Corporate Director, CyberSecurity
TriMark USAAbout the role
TriMark USA is the country’s largest provider of design services, equipment, and supplies to the foodservice industry. We proudly serve our customers by providing design services, commercial equipment, and foodservice supplies across a wide range of industries and business sectors. Headquartered in Massachusetts, with a history dating back to 1896, we have locations across the country that offer foodservice operators an unparalleled level of service by combining our unique design capabilities and our expert market knowledge with the purchasing strength, delivery, installation, and after-sales service capabilities of a national company. Our employees are focused on creating customized solutions for our clients to ensure they achieve their culinary goals while upholding our I.C.A.R.E. values: Integrity, Customer Service, Accountability, Respect, and Excellence. For more information, please visit: www.trimarkusa.com
Why you’ll love it here!
+ Benefits include Medical, Dental, Vision, Tuition Reimbursement, Pet, and Legal Insurance
+ 401k
+ Community Service Day
+ Spotlight Awards
+ National Sales Excellence Awards
+ CFSP Prep Certification Program
POSITION SUMMARY:
• The Director of CyberSecurity reports to the Chief Intelligence Officer
• Located in Mansfield, MA
• Full-Time
• Hybrid
POSITION OVERVIEW: TriMark USA is seeking an accomplished Director of Cybersecurity to lead the company’s enterprise security function across its national footprint. This is a senior leadership role responsible for owning and evolving the cybersecurity strategy, managing security operations, and protecting a complex, distributed environment spanning cloud, on-premises, and hybrid infrastructure. The ideal candidate brings a track record of translating technical risk into business decisions, has operated at scale, and can credibly engage both the boardroom and the SOC. This role reports to the CIO and carries direct budget ownership, executive-level reporting responsibilities, and cross-functional authority over security posture across the organization. The Director is expected to present to the executive team and, on a defined cadence, to the board or audit committee.
ESSENTIAL FUNCTIONS & RESPONSIBILITIES:
Security Strategy & Architecture:
• Own and continuously evolve a risk-based cybersecurity strategy aligned to business objectives, regulatory obligations, and the current threat landscape.
• Lead the design and implementation of a Zero Trust Architecture (ZTA) across identity, network, data, and endpoint domains, incorporating least-privilege access, continuous verification, and micro-segmentation.
• Direct cloud security posture across multi-cloud and hybrid environments, ensuring alignment with shared responsibility models and CNAPP/CSPM controls.
• Drive AI security governance — both leveraging AI-powered tooling for defense and establishing policy and controls around the organization’s use of AI/GenAI platforms, working alongside the AI steering committee.
• Assess and advance post-quantum cryptography readiness as part of long-range strategic planning. Security Operations & Engineering
• Oversee the full security operations function including a modern detection and response stack: SIEM, SOAR, XDR, and threat intelligence platforms.
• Drive an automation-first approach to Managed Detection and Response (MDR) — whether through internal capability, MSSP partnership, or a hybrid model — with a focus on reducing mean time to detect (MTTD) and mean time to respond (MTTR).
• Direct vulnerability management, penetration testing, threat hunting, and red team/purple team exercises with ongoing risk reporting.
• Champion Identity and Access Management (IAM) including phishing-resistant MFA, Privileged Access Management (PAM), and continuous access auditing as a foundational security control.
• Integrate DevSecOps practices into the software development lifecycle, embedding SAST, DAST, and SCA tooling across engineering and application teams, including externally facing platforms.
• Own and mature an insider threat program encompassing behavioral analytics, access monitoring, and policy enforcement across a geographically distributed workforce. Data Security & Classification
• Define and enforce a data classification framework across structured and unstructured data, including customer PII, payment data, supplier contracts, and internal operational data.
• Own and operate data loss prevention (DLP) controls across endpoints, email, cloud storage, and collaboration platforms.
• Ensure sensitive data handling policies are operationally enforced and regularly tested, not merely documented.
M&A Security Due Diligence & Integration
• Own cybersecurity due diligence for M&A targets: assess security posture, identify material risk, and deliver findings t
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s