Vice President of Information Security - Governance/Risk/Compliance (Remote)
UPSAbout the role
Before you apply to a job, select your language preference from the options available at the top right of this page.
Explore your next opportunity at a Fortune Global 500 organization. Envision innovative possibilities, experience our rewarding culture, and work with talented teams that help you become better every day. We know what it takes to lead UPS into tomorrow—people with a unique combination of skill + passion. If you have the qualities and drive to lead yourself or teams, there are roles ready to cultivate your skills and take you to the next level.
Job Description:
The Vice President of Information Security will lead the global Governance, Risk, and Compliance (GRC) function, driving strategic oversight and operational excellence across cybersecurity policy, regulatory compliance, risk management, and assurance. This role will serve as a key advisor to the Chief Information Security Officer (CISO), business and technology leadership, helping to ensure the organization’s cyber risk posture aligns with business objectives and global regulatory expectations. This role requires a leader with expertise in cybersecurity governance, security risk management, regulatory compliance, and third-party risk. You will lead a global team of professionals and collaborate with executive stakeholders to embed security into the organization’s culture, operations, and strategic initiatives.
RESPONSIBILITIES
Strategy and Leadership
- Articulate program strategy and mobilizes the workforce to collaboratively achieve appropriate cybersecurity objectives through internal and external relationships.
- Champion technology and funding recommendations to senior management to help ensure appropriate controls and capabilities are in place to meet business objectives
- Represent the company in external regulatory and industry forums, supporting compliance and thought leadership
Cybersecurity Governance
- Facilitate corporate cybersecurity governance forums and executive steering committees to align cybersecurity risk management strategy with enterprise risk appetite
- Communicate verbally and in writing to senior leadership team with various levels of technical knowledge, educates them about cybersecurity risk management topics, and shares insights and recommendations that inform risk management strategies.
- Define and enforce enterprise-wide cybersecurity policies, standards, and procedures, ensuring they are current, enforceable, and adopted across business units.
Risk Management
- Conduct security risk assessments to evaluate asset protection and control effectiveness.
- Apply risk models to assess threats, vulnerabilities, and business impact.
- Maintain a risk register and drive remediation through corrective action plans.
- Partner with stakeholders to ensure risk mitigation and achieve regulatory compliance.
Mergers and Acquisitions
- Conduct security due diligence on target companies to identify risks and integration challenges.
- Assess cybersecurity posture, compliance status, and data protection practices of acquisition targets.
- Advise on risk mitigation strategies and contractual security requirements during deal negotiations.
- Support post-acquisition integration by aligning security controls, policies, and infrastructure.
Regulatory Compliance
- Stay updated on regulatory changes and industry standards (e.g., ISO, NIST, PCI-DSS EU Regulations)
- Ensure compliance with global cybersecurity and data protection regulations, including but not limited to PCI-DSS, EU NIS2, and other industry-specific regulatory and standards
- Oversee external cybersecurity audits, regulatory assessments, and certification processes (e.g., ISO 27001, SOC 2).
- Partner with legal, privacy, and internal audit teams to manage regulatory inquiries, audits, and responses.
Security Training and Awareness
- Lead the design and execution of a security awareness program aligned with regulatory and organizational needs.
- Create engaging, role-specific training content and phishing simulations.
- Track and report on training effectiveness and compliance metrics.
- Partner with stakeholders to embed security culture across the organization.
Third-Party and Supply Chain Cyber Risk
- Lead the third-party cyber risk management program, including due diligence, onboarding assessments, contract reviews, and continuous monitoring.
- Develop and maintain a scalable framework for evaluating and managing risks associated with vendors, partners, and supply chain entities.
- Collaborate with procurement, legal, and bus
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s