Director, IT Cybersecurity
American Bureau of ShippingAbout the role
The Director of IT Cybersecurity is responsible for managing the overall cybersecurity program. This includes but is not limited to the delivery of cybersecurity projects, the creation of and management of the ongoing cybersecurity program, and the development of the ABS cybersecurity architecture team, architectures, roadmaps, standards, and guidelines. The IT Director of Cybersecurity works closely with Security Risk and Compliance and drives collaboration across Legal, Ethics & Compliance, Facilities, Facilities, and other organizations. This role spans the organization and inludes ABS Bureau, ABS Group Consulting, and ABS Wavesight.
What You Will DO:
- Creates and leads the ABS Security Program, aligning it to not only National Institute of Standards and Technology (NIST) 800-171, Defense Federal Acquisition Regulation Supplement (DFARS) 252.204-7012, 7019, Federal Acquisition Regulation (FAR) 52.204, Cybersecurity Maturity Model Certification (CMMC), and other similar regulations, legal, geo-political factors, etc.
- Develops the ABS Cybersecurity Architecture team, aligning with Enterprise Architecture and our federated development organizations to ensure that all infrastructure, operations, and application teams follow all secure systems development lifecycle processes and have clear architectural standards, best practices, and guidelines for secure systems development.
- Ensures a clean, consistent architectural engagement point as part of the secure systems development lifecycle process and drives the creation of that process and its ongoing improvement in collaboration with the Director of Infrastructure Operations and the Vice President of IT (over Enterprise Architecture, Application Development, and Business Relationship Management).
- Leverages the governance process to interpret the complex legal, regulatory, business, and compliance landscape to identify new policies needed or changes to existing policies and work with security risk and compliance to develop such policies realigning them to the new understanding.
- Leverages the newly created policies and the interpretation of the complex legal, regulatory, business, and compliance to generate, update, or modify architecture standards, guidelines and principles not only for cybersecurity architectures, but also to ensure alignment across enterprise architecture.
- Works with security risk and compliance to drive the creation of a security risk score for the enterprise, aligning the highest risks to the organization to the costs necessary to remediate them.
- Drives the creation and maintenance of a cybersecurity technology and capability roadmap that drives risk mitigation and cost efficiency through the proper use of available and up-and-coming technologies.
- Drives the creation of a Third-Party Risk Management approach for ABS in alignment with the existing ABS procurement process or collaborate in modifying the existing procurement process to better facilitate it.
- Leads and manages teams of contractors and employees including managers of people where necessary.
- Participates in or drives participation in Architecture Review Boards or Technology Review Boards.
What You Will Need:
Education & Experience
- Preferred, Master’s in Cybersecurity or Master’s in Business Administration (with a focus in technology or technology security) or equivalent experience
- Preferred, one or more of the major cybersecurity certifications such as, but not limited to Global Information Assurance Certification (GAIC), Certified Information Systems Security Professional (CISSP), Certified Information Security Auditor (CISA), Certified in Risk and Information Systems Control (CRISC), etc.
- Minimum 10 years of experience (preferred).
Knowledge, Skills, and Abilities
- Must have a clear understanding of cybersecurity risk management
- Must have executive leadership skills and the ability to work with and through the C-suite to accomplish complex organizational goals, develop buy-in, create new processes, and drive consensus on potentially challenging legal, regulatory, and compliance requirements coming from the business.
- Must have a keen cybersecurity architecture mindset and understand how to lead a team of architects to develop standards, guidelines, best practices, and roadmaps.
- Must also know how to build new processes and policies across organizations and successfully navigate complex organizational challenges. Demonstrates organizational agility and political savvy.
- Ability to learn the ABS Health, Safety, Quality, and Environmental Management System.
Reporting Relationships:
Reports to a senior level member of management and will have direct reports.
We set oApply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s