Sr. Director, Cyber Security

Upbound Group•Plano, TX
•Onsite

About The Position

At Upbound Group, we are committed to elevating financial opportunity for all through innovative, inclusive, and technology-driven financial solutions that address the evolving needs and aspirations of consumers. The Company’s customer-facing operating units include industry-leading brands such as Rent-A-Center, Acima and Brigit that facilitate consumer transactions across a wide range of store-based and digital retail channels, including over 2,400 company-branded retail units across the United States, Mexico, New York and Puerto Rico. Upbound Group, Inc. is headquartered in Plano, Texas. You'll lead cyber defense for Upbound: security operations, incident response, threat hunting, detection engineering, and exposure management. You also own the governance that keeps defense risk-driven: the vulnerability management standard and its SLAs, risk acceptance and exceptions, the security program's oversight of AI risk, and the measures we report to the CISO and the board committee. You own how fast we detect, contain, recover, and close exposures, and you leverage AI to scale the team and increase the pace of everything it does. If we bring the right talent, this role is a deputy for the CISO and part of succession.

Requirements

  • More than fifteen years in cybersecurity, with ten or more spanning security governance, security operations, and exposure management.
  • More than eight years of people management.
  • You've led response through major incidents, including incident command and briefing executives.
  • You've owned a vulnerability management program at scale: the standard, the SLAs, the exception process, and the evidence auditors and assessors asked for.
  • You've run risk governance for a security program: a risk register, risk acceptance, and reporting to executives and a board committee, without slowing the business down.
  • You've built or rebuilt detection engineering and managed an outsourced detection and response partner.
  • You've put AI and automation to work in security operations and can show what it changed, and you're comfortable governing AI risk as the business adopts it.
  • Comfortable with PCI DSS and the regulatory environment of consumer finance.
  • Retail or consumer finance.

Nice To Haves

  • CISSP, CISM, GCIH, GCFA, or similar, preferred.

Responsibilities

  • Own the security operations center and the managed monitoring partner's service levels.
  • Run incident response end-to-end, from incident command to executive updates, with playbooks so every incident runs to a script.
  • Own detection engineering and threat hunting: detections as code, mapped to the attacker techniques that matter to us and measured for coverage, and hunting as a standing practice.
  • Own exposure management end-to-end through the Principal, Exposure Management: the asset and exposure inventory, prioritization by risk, closure SLAs, and verified fixes with the platform and application owners.
  • Own vulnerability management governance: the standard, the SLAs by risk tier, risk acceptance and exceptions, and the evidence for PCI DSS, audits, and regulators.
  • Manage AI governance for the security program: risk assessment of new AI use, the approval and exception path, and the program's reporting into the company's AI governance forum, with the Head of AI Security setting the technical standards.
  • Run the defense risk register: turn findings from incidents, audits, assessments, and penetration tests into one risk-driven backlog with owners and dates, hold them, and report the measures to the CISO and the board committee: time to detect, time to contain, time to recover, exposures closed within SLA, and risk accepted.
  • Leverage AI to scale and increase the pace of defense: AI-assisted triage and investigation, agentic response with approval gates, and automation of the routine work so the team hunts and engineers.
  • Hire, develop, and lead the team and direct the contract engineers who augment it.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service