Director, Information Security
CotyAbout the role
Director, Informtaion Security
New York, NY (hybrid)
COTY is looking for smart leaders who are tenacious, passionate, and fearlessly kind.
Job Description
The Global Director of Information Security and Risk Management is responsible for establishing and maintaining corporate wide information security and risk management programs to ensure that information assets are adequately protected. This position will lead the global Information Security program and is responsible for identifying, evaluating, and reporting on security risks as well as owning and driving the enterprise-wide Cybersecurity program. This position requires a visionary leader with strong skills in technology, security, and risk management. The director will proactively work with Coty Information Technology teams and business units to implement practices that meet defined policies and standards for information security.
The Global Director of Information Security and Risk Management serves as the process owner of all ongoing activities related to the integrity and confidentiality of customers, business partners, employees and business information, as well as compliance with the organization's information security policies. A key element of this role is working with executive management to determine acceptable levels of risk for the organization. He or she must be highly knowledgeable about the business environment and must ensure that information system controls are maintained in a fully functional, secure mode.
The ideal candidate is an integrator of people and processes, a thought leader, a problem solver, an effective consultant and should possess solid domain competency in the field of information security by having 8 to 10 years of direct experience in this significant leadership role.
Responsibilities Include, but are not limited to:
- Develop, implement, and monitor strategic, comprehensive enterprise information security and risk management programs to ensure the integrity, confidentiality and availability of information owned, controlled, or processed by Coty.
- Manage the enterprise's security organization, consisting of direct reports and indirect reports (such as individuals in risk management roles), including hiring, training, staff development, performance management and annual compensation review.
- Develop, communicate, and ensure compliance with Coty's information security policies and standards.
- Develop and manage information security budgets and monitor them for variances.
- Work directly with the business units to facilitate risk analysis and risk management processes, identify acceptable levels of risk, and establish roles and responsibilities with regard to information classification, protection and security issue resolution
- Provide subject matter expertise to executive management on a broad range of information security standards and best practices, such as ISO 27001/2, the NIST Cybersecurity Framework, or the CIS Top 20.
- Provide strategic and tactical security guidance for all IT projects, including the evaluation and recommendation of technical controls during Architectural Review Boards.
- Liaise with the IT Business Facing Team to ensure alignment between the security and enterprise solution designers, thus coordinating the strategic planning implicit in projects.
- Lead information security and risk management projects with staff from the IT organization and business unit teams.
- Lead the organization through testing and execution of effective incident response procedures.
- Ensure that security programs are in compliance with applicable laws, regulations, and policies to minimize or eliminate risk and audit findings, specifically SOX, PCI-DSS, and GDPR.
- Liaise between the information security team and corporate compliance, audit, legal and HR management teams as required.
- Create and facilitate an effective information security risk assessment process, including reporting and oversight of remediation efforts to address negative findings.
- Manage security incidents and events to protect corporate Coty's information assets, including intellectual property, fixed assets, and the company's reputation.
- Coordinate the use of external resources involved in the information security program, including, but not limited to, interviewing, negotiating contracts and fees, and managing external resources.
- Develop business-relevant metrics to measure the efficiency and effectiveness of the security and risk management programs, facilitate appropriate resource allocation and increase the maturity of these programs.
- Facilitate business alignment and communications by forming an information security and/or risk management steering
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s