Director of Information Security & Compliance

DBM GLOBAL INCPhoenix, AZ
Onsite

About The Position

The Director Information Security & Compliance is responsible for establishing and maintaining the information security program to ensure that information assets and associated technology, applications, systems, infrastructure and processes are adequately protected. This position is responsible for identifying, evaluating and reporting on legal and regulatory, IT, and cybersecurity risk to information assets, while supporting and advancing business objectives. This position is responsible for maintaining IT General Controls for Sarbanes Oxley (SOX) compliance. The successful candidate will be able to collaborate and influence all areas of the business to reduce risk and increase the effectiveness of our information security program.

Requirements

  • 5-10 Years experience in an information security or cybersecurity role
  • BS in Computer Science or related field, or equivalent experience
  • Must have a current CISSP certification. If the candidate does not have this certification, they will need to obtain it.
  • Frequent use and knowledge of MS Windows 7 and/or MS Windows 10, MS Word, MS Excel, MS PowerPoint, and MS Outlook.

Responsibilities

  • Facilitate an information security governance structure through the implementation of a hierarchical governance program, including the formation of an information security steering committee or advisory board.
  • Provide regular reporting on the current status of the information security program to enterprise risk teams and senior business leaders as part of a strategic enterprise risk management program, thus supporting business outcomes.
  • Work with the vendors to ensure that information security requirements are included in contracts by liaising with business leaders throughout the organization
  • Create and manage a targeted information security awareness training program for all employees, contractors and approved system users, and establish metrics to measure the effectiveness of this security training program for the different audiences.
  • Understand and interact with related disciplines through committees to ensure the consistent application of policies and standards across all technology projects, systems and services, including privacy, risk management, compliance and business continuity management.
  • Provide clear risk mitigating directives for projects with components in IT, including the mandatory application of controls.
  • Work with internal and external audit firms to ensure compliance with Sarbanes Oxley and other compliance requirements.
  • Ensure IT General Controls are effective and operating successfully.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service