Job Summary
We are seeking a Director of Information Security to lead and manage all aspects of our on-site cybersecurity, risk management, and SOX compliance operations. This role is central in formulating and implementing policies and procedures to protect the organization from internal and external threats, with a significant focus on ensuring SOX compliance. The Director will develop and manage Information Security and Disaster Recovery programs, emphasizing innovative strategies to maintain compliance and strengthen the company’s security posture.
Essential Duties & Responsibilities
- Lead the development and implementation of a comprehensive Information Security improvement plan, with a primary focus on achieving and maintaining SOX compliance.
- Act as the primary point of contact for SOX IT audit activities, coordinating with internal and external auditors to address any compliance gaps or deficiencies.
- Build and maintain strong relationships with stakeholders across the organization, supporting risk remediation and compliance initiatives.
- Oversee IT audit processes and compliance efforts, ensuring alignment with SOX requirements, and implement gap remediation strategies for critical systems.
- Collaborate with senior management and departmental partners to assess and support SOX compliance and broader risk mitigation needs, providing strategic guidance and quality control.
- Evaluate past security and SOX compliance assessments, drive corrective actions, and develop a strategic roadmap to support continuous improvement.
- Develop metrics to measure the effectiveness of security and compliance programs, ensuring adherence to SOX requirements, internal policies, and best practices across all business units.
- Keep current with regulatory compliance standards and emerging security trends, incorporating these into the organization’s frameworks with minimal business disruption.
- Implement and manage Disaster Recovery (DR) and Business Continuity Planning (BCP) improvements to enhance system resiliency for critical applications.
- Partner with the Chief Information Officer (CIO) to oversee vendor relationships, manage contracts, negotiate terms, and ensure SLA adherence.
Minimum Qualifications
- Bachelor’s degree in a technical or business-related field; an advanced degree (MBA) is a plus.
- Relevant security certifications, such as CISSP, CISM, or CISA, demonstrating active knowledge of security frameworks and SOX compliance.
- 15+ years of progressively responsible experience in Information Security, including 8+ years in leadership roles, ideally within a multi-location, public company environment with a focus on SOX compliance.
- Proven experience managing Security Operations functions (e.g., AV/Malware, SIEM, DLP, patch management) and achieving SLA targets.
- Strong experience with SOX compliance processes and IT audit management, including gap remediation and process improvement for compliance.
- Background in incident response and crisis management across multiple business units.
- Excellent risk evaluation and risk management skills, with demonstrated ability to manage the security and compliance lifecycle across an enterprise.
- Strong verbal and written communication skills, with experience reporting security and compliance metrics at the executive level.
- Ability to travel up to 20%.
- This position requires full-time, on-site presence in Phoenix, AZ, with no remote work options available.