Director, Cybersecurity (Global/Emerging Market Experience Required - DC Area)
Winrock InternationalAbout the role
Position Title: Director, Cybersecurity
Department: Information, Communication and Technology (ICT)
Location and Working Hours: US, Washington DC Metro (DMV) area
Reports to: VP of ICT
Position Summary:
The Director, Cybersecurity will provide cybersecurity leadership and guide the development and implementation of the organization’s cybersecurity roadmap. This is a hands-on role that involves setting security goals, establishing policies, managing cybersecurity activities, and ensuring alignment with organizational objectives. The Director will work closely with senior management, the Risk & Compliance team, and the ICT team to secure systems and data. The Director will supervise and coordinate with the Sr. Analyst, Cybersecurity to create a resilient cybersecurity posture and act as a backup for critical operational tasks.
This position may be based within the contiguous United States, but will require the candidate to work on East Coast time. Candidates in the Washington DC (DMV) area are strongly preferred.
Key Responsibilities:
Strategic Leadership
- Define and communicate long-term security goals, objectives, and strategies aligned with organizational priorities and the evolving threat landscape.
- Assess security posture to identify critical gaps and develop a cybersecurity maturity roadmap to guide improvement efforts.
- Oversee cybersecurity projects, directing the Sr. Analyst, Cybersecurity to align initiatives with strategic objectives and the security roadmap.
Policy and Procedure Development
- Develop, implement, and maintain the organization’s cybersecurity strategy and policy framework, ensuring alignment with regulatory requirements and industry standards.
- Ensure consistent application of cybersecurity policies across all environments, holding teams accountable for compliance and implementation.
Security Program Management
- Oversee cybersecurity architecture reviews and configuration enhancements to strengthen network security.
- Manage the Security Awareness Program, collaborating with the Sr. Analyst, Cybersecurity to deliver targeted training and awareness initiatives.
- Lead disaster recovery and business continuity planning with ICT, including regular testing and maintenance to ensure readiness.
Risk Management
- Oversee security assessments, audits, and risk management activities, prioritizing risks based on organizational impact.
- Manage annual vulnerability and penetration testing, collaborating with ICT to address findings.
- Prepare for audits by facilitating necessary documentation and meetings, serving as the primary cybersecurity contact for external auditors.
Data Protection and Privacy
- Develop, implement, and enforce data protection policies that ensure confidentiality, integrity, and availability of sensitive information.
- Collaborate with Risk, Compliance, and Legal teams to align cybersecurity policies with data privacy regulations (e.g., GDPR, CCPA, HIPAA).
- Lead data protection impact assessments, implement access controls, and establish response processes for potential data breaches.
- Promote data privacy awareness and lead organization-wide training on data protection policies and best practices.
Compliance and Regulatory Alignment
- Collaborate with Risk & Compliance to determine regulatory requirements, creating strategic plans for implementing necessary controls.
- Define roles and responsibilities within ICT, Cybersecurity, and Risk & Compliance teams, clarifying accountability for compliance efforts
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s