Jobs and Careers
GA

Director, Information Security Compliance and Governance

Gap Inc.
San Francisco, United Statesfull_timeVerifiedPosted 3 Jun 2024

About the role

About the Role

In this pivotal role, you will spearhead the development of a forward-looking 24-36 month security strategy and lead the charge in implementing robust security enhancements. Your mandate will also encompass driving Information Security Compliance and Governance, including conducting comprehensive IT Security Risk Assessments to fortify GapTech for both internal and external audits. Additionally, you will be entrusted with the crucial task of ensuring unwavering compliance with Sarbanes-Oxley (SOX), overseeing Third Party Risk Audits, and managing Findings and Risk Management with authority and precision.

What You'll Do

You will lead strategic collaboration, align security with business objectives, manage data security and compliance, oversee budget control, ensure regulatory compliance, advocate for security investments, manage relationships with partners, and influence the strategy for the team.

  • Collaborate with the CISO and senior leadership to define the overall security vision and roadmap.
  • Align security initiatives with business objectives and risk tolerance.
  • Build and lead a Data security strategy and technology direction. 
  • Budget management and control, work with Procurement to ensure budget control.
  • Prepare and present reports on security posture and trends.
  • Ensure compliance with industry standards (such as ISO 27001 and NIST) and regulatory requirements.
  • Advocate for security investments and resource allocation.
  • Test and validate controls for continued regulatory compliance.
  • Build and manage relationship with the current MSP  
  • Manage the team and MSP partner to review and collect evidence for control testing performance; remediate findings from various IT audits through completion.
  • Build cross functional partnerships and collaboration with boarder teams.
  • Influence strategy for area/team
     

Who You Are

  • Ability to assess complex situations and analyze data to make judgments and recommend solutions. 
  • Effective communication skills and experience translating complex information and presenting to leadership.
  • Strong strategic understanding of Information Security and ability to articulate clearly and to all levels of leadership. 
  • Leverage knowledge of laws directives, guidance and PCI regulations governing data and computer assets, to ensure we maintain our compliance.
  • Competence and experience with Information Security Compliance and Governance methodologies, procedures, tools and practices
  • Sound knowledge of concepts and procedures specific to own subject area and an understanding of the procedures in other relevant security areas.
  • Experience in preparing reports and leading a team of exempt level employees
  • Manage the outsource partners to ensure that all key metrics and projects are met. 
     

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Gap Inc.

View company profile →