Director of Information Security

9/11 Memorial & MuseumNew York, NY
2d$130,000 - $140,000

About The Position

The Director of Information Security leads the organization’s information security program, ensuring the confidentiality, integrity, and availability of systems and data while enabling secure business operations and technology innovation.

Requirements

  • Strong analytical skills and attention to detail.
  • Technical expertise across network security, application security, identity and access management, cloud security and cryptography.
  • Excellent communication skills; able to convey complex security topics to technical and non-technical audiences.
  • Proven leadership skills, including team building and vendor management.
  • Ability to operate calmly under pressure and in crisis situations.
  • 5+ years cybersecurity experience including hands-on and leadership responsibilities.
  • Bachelor’s in Cybersecurity, Computer Science, Information Technology or a related discipline.
  • Industry certifications such as CISSP, CISM, CRISC, CEH or equivalent.
  • Deep familiarity with security frameworks such as NIST CSF, ISO 27001, COBIT and risk management methodologies.
  • Demonstrated experience responding to incidents, managing security operations centers and conducting forensics.
  • Experience managing MSSPs or SOC providers, securing cloud-based and SaaS environments

Responsibilities

  • Develop Information Security program & team, maintain and enforce a comprehensive information security strategy aligned with business goals.
  • Develop and execute the enterprise information security strategy and multi-year security roadmap
  • Oversee risk and vulnerability assessments, penetration tests and security audits; prioritize mitigation activities.
  • Ensure compliance with relevant legal, regulatory and contractual security requirements (PCI-DSS, GDPR, SOC2).
  • Lead security operations, incident response, vulnerability management, and threat detection activities
  • Own identity and access management strategy, controls, and lifecycle processes
  • Establish and oversee security governance, risk management, and compliance programs
  • Manage third-party and vendor security risk, including security requirements in procurement
  • Partner with IT, Data, and Engineering teams to embed security into systems and workflows
  • Define and report security KPIs, risk metrics, and security posture to executive leadership
  • Lead and develop internal security staff and manage managed security service providers
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service