This is a "hybrid" role. The selected candidate will work in Arlington, VA (Tuesdays-Thursdays) on a weekly basis. The Director of Information Security Risk Management serves as the functional lead for NACD's enterprise information security program, operating with the scope and accountability of a Chief Information Security Officer within the organization. Reporting to the CIO, the Director owns the execution and ongoing maturation of NACD's security governance, risk management, compliance, and operations functions — including full ownership of the information security budget. NACD's information security program is in its early stages of development. Many foundational capabilities are newly established, and several critical programs have yet to be built. This is a builder role. The Director will assess the current state of the program, prioritize investments, and systematically stand up the people, processes, and technologies required to mature NACD's security posture. This requires someone equally comfortable designing programs from the ground up as they are operating and improving what already exists. The Director identifies, evaluates, and reports on legal, regulatory, and cybersecurity risk to information assets while supporting NACD's business objectives — partnering with the CIO, Legal/Privacy, senior leadership, and business units to define acceptable risk levels and ensure systems are maintained in a secure, functional, and compliant state.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Director