Director of Information Security

Exponent•Phoenix, AZ
•Onsite

About The Position

Exponent is currently seeking a Director of Information Security residing in Phoenix, AZ. In this role, you will work as part of the Information Technology Team reporting to the Vice President of Information Technology. You will be responsible for strategy, governance, and executive advisory, including developing and executing the multiyear security and privacy strategy, roadmap, operating model, and investment priorities. You will translate cyber, privacy, operational, and regulatory risk into clear business, financial, client, and reputational impact for executive leadership, the board, and governance bodies. You will serve as the accountable manager for ISO/IEC 27001, 42001, and ISO/IEC 27701, chairing required governance forums, maintaining policies, objectives, risk treatment, management review, evidence, and continual improvement. You will coordinate with Legal on applicable contractual, legal, and privacy obligations. You will direct enterprise risk assessment, risk acceptance, control design, and secure architecture across identity, cloud, network, endpoint, applications, data, and AI, embedding security and privacy requirements into projects, acquisitions, vendors, and technology change. You will provide executive oversight for incident response, threat detection, vulnerability management, access governance, penetration testing, digital forensics, and incident coordination, ensuring escalation, communications, law-enforcement, and external-response decisions are documented and exercised. You will act as Data Protection Officer and privacy escalation authority, overseeing privacy risk assessment, data protection requirements, information classification, data handling, transfer and disclosure decisions, and alignment with global privacy obligations. You will own the security assurance model for client questionnaires, contractual commitments, audits, and restricted-information requirements, and direct third-party security risk management, supporting business development by clearly articulating Exponent’s security and privacy posture. You will establish business-relevant metrics covering risk, incidents, vulnerabilities, audit findings, control effectiveness, awareness, third parties, and program maturity, and sponsor internal and external audits, driving remediation and reporting trends and investment outcomes. You will lead, develop, and retain the security and privacy team, defining accountability, succession, on-call coverage, and service expectations, and own budget planning, vendor and contract portfolio, resource allocation, and delivery through internal teams and managed service partners. Leadership Outcomes include maintaining a defensible, audit-ready security and privacy program aligned to Exponent’s business objectives and client commitments, reducing material cyber and privacy risk through prioritized treatment plans, clear ownership, measurable controls, and timely escalation, enabling consulting, litigation, and corporate operations to adopt technology, cloud, and AI securely without unnecessary friction, providing executives with concise, decision-oriented reporting on risk posture, incidents, investment needs, and program maturity, and building a resilient operating model with documented authority, repeatable processes, qualified backups, and effective external partners.

Requirements

  • Progressive leadership experience directing enterprise information security, privacy, cyber risk or related programs in a distributed, regulated or client-trust-dependent environment.
  • Experience building, transforming and/or directing an information security program.
  • Demonstrated ownership of security strategy, governance, budget, vendors, metrics and multiyear transformation roadmaps.
  • Proven experience managing a compliance program.
  • Practical leadership of ISO/IEC 27001 programs and audits.
  • Experience directing incident response, vulnerability management, identity and access governance, third-party risk, security architecture, MDR/MSSP services and audit remediation.
  • Experience responding to a business impacting incident.
  • Ability to advise executives, clients, auditors, counsel and technical leaders, including during incidents, regulatory scrutiny and high-impact decisions.
  • Working knowledge of modern Microsoft security and identity capabilities, cloud platforms, endpoint and network security, data protection, Purview, AI security and secure software practices.
  • Bachelor’s degree in information technology, cybersecurity, risk management or a related field, or equivalent relevant experience.
  • Relevant certification such as CISSP required or expected.

Nice To Haves

  • Working knowledge of privacy management and ISO/IEC 27701.
  • CISM, CRISC, PMP, ISO 27001 Lead Implementer/Lead Auditor, or privacy credentials are valued.

Responsibilities

  • Develop and execute the multiyear security and privacy strategy, roadmap, operating model and investment priorities.
  • Translate cyber, privacy, operational and regulatory risk into clear business, financial, client and reputational impact for executive leadership, board and governance bodies.
  • Serve as accountable manager for ISO/IEC 27001, 42001 and ISO/IEC 27701. Chair required governance forums; maintain policies, objectives, risk treatment, management review, evidence and continual improvement.
  • Coordinate with Legal on applicable contractual, legal and privacy obligations.
  • Direct enterprise risk assessment, risk acceptance, control design and secure architecture across identity, cloud, network, endpoint, applications, data and AI.
  • Embed security and privacy requirements into projects, acquisitions, vendors and technology change.
  • Provide executive oversight for incident response, threat detection, vulnerability management, access governance, penetration testing, digital forensics and incident coordination.
  • Ensure escalation, communications, law-enforcement and external-response decisions are documented and exercised.
  • Act as Data Protection Officer and privacy escalation authority.
  • Oversee privacy risk assessment, data protection requirements, information classification, data handling, transfer and disclosure decisions, and alignment with global privacy obligations.
  • Own the security assurance model for client questionnaires, contractual commitments, audits and restricted-information requirements.
  • Direct third-party security risk management and support business development by clearly articulating Exponent’s security and privacy posture.
  • Establish business-relevant metrics covering risk, incidents, vulnerabilities, audit findings, control effectiveness, awareness, third parties and program maturity.
  • Sponsor internal and external audits, drive remediation, and report trends and investment outcomes.
  • Lead, develop and retain the security and privacy team; define accountability, succession, on-call coverage and service expectations.
  • Own budget planning, vendor and contract portfolio, resource allocation, and delivery through internal teams and managed service partners.

Benefits

  • Competitive benefits
  • Compensation and recognition programs
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service