Jobs and Careers
SW

Director of Security and Compliance

Swinerton
United Statesfull_timeVerifiedPosted 10 Apr 2026
💰 $225,000/yr($200,000/yr$225,000/yr)

About the role

Compensation Range:

$200,000.00 - $225,000.00 Annual Salary

Job Description Summary:

The Director of Security and Compliance leads the design and oversight of cybersecurity, compliance, and privacy programs that safeguard the organization’s digital assets and data while ensuring adherence to regulatory requirements, contractual obligations, and internal policies. This position reports to the VP of IT Operations / Chief Information Security Officer.

Job Description:

Position Responsibilities and Duties:

Risk Management:

  • Set the mission, vision, and strategy for technology risk management including cybersecurity, compliance and privacy organization.  Implementing appropriate risk management and mitigation efforts while ensuring the success of business and IT initiatives, ensuring alignment with business objectives and product priorities.

Communication & Executive Engagement:

  • Demonstrate exceptional communication and presentation skills, effectively conveying complex technical and compliance concepts to critical stakeholders, including senior managers and the executive leadership team, to support informed decision‑making.

Stakeholder & Relationship Management:

  • Build successful stakeholder relationships with other IT , enterprise risk managers and key business stakeholders by developing a clear understanding of business needs, acting as a trusted advisor, and ensuring cost-effective delivery of security  services to meet those needs.

Security Architecture & Operations:

  • Direct enterprise-wide security architecture and operations across IT and OT environments, ensuring secure design, deployment, and ongoing protection of infrastructure, applications, and data systems.

Regulatory Compliance & Reporting:

  • Ensure compliance with all relevant cybersecurity, compliance and privacy regulations.  As part of a strategic enterprise risk management program, conduct compliance assessments and provide regular status reports to risk management teams and senior business leaders  including relevant metrics, key performance and risk indicators.

Privacy Program Leadership:

  • Lead cross-functional Privacy Team to develop and implement a comprehensive enterprise-wide data and personnel privacy program. Maintain current policies, facilitate publication and communication, and ensure all employees receive required privacy training.

Budget & Financial Management:

  • Develop and control the annual department budget to ensure that it's consistent with the overall strategic objectives of IT and the enterprise and is within plan.

Security Culture & Awareness:

  • Foster an enterprise security culture by embedding compliance and risk management practices into daily business operations.
  • Lead organization-wide training and awareness initiatives that enable informed cybersecurity decision-making across all functions and levels.

Risk Assessment, Business Continuity & Incident Response:

  • Conduct comprehensive enterprise risk assessments and develop strategies that strengthen business continuity, disaster recovery, and incident response capabilities.
  • Build, train, and coordinate cross-functional incident response teams across security, IT, business partners, and executive leadership to ensure effective crisis response and business protection.

Data Retention & Archiving Compliance:

  • Ensure digital and paper archiving (warehouse) systems are complying with corporate data retention policies. 
  • Collaborate with Product Managers to ensure they understand policies and their products and services are aligned.

Team Leadership & Development:

  • Build and lead a high performing team.
  • Work collaboratively with direct reports to support their career progression, nurture their development and to help them realize their potential.
  • Have a documented succession plan for critical functions.
  • Develop and actively participate in peer network groups.  Stay up on trends and share lessons learned.

Vendor & Third-Party Management:

  • Lead vendor management and negotiations with security service providers.
  • Establish strong vendor relationships ensuring vendors understand and share our focus on security and are capable of meeting requirements.

Minimum Skills and Experience:

  • Bachelor’s or Master’s degree in business administration or technology related field
  • 15 or more years of experience in IT Operations, cybersecurity or business/industry

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Swinerton

View company profile →