Jobs and Careers
OV

Director, Information Security & Compliance

Overhead Door Corporation
Lewisville, United Statesfull_timeVerifiedPosted 14 Aug 2026

About the role

The Director of Information Security and Compliance provides strategic and operational leadership for Information Security and IT Risk Compliance efforts. The role manages and coordinates core aspects of security administration, identity and access management, audit response, and vulnerability assessments within the boundaries of acceptable risk. The director will conduct audits/assessments for IT Compliance, IT Security and Data Privacy.  New implementations and operational maintenance of existing business-critical applications will be examined.  The role extends to any part of the business that has risk associated with information assets.  The Director of Enterprise Security and Compliance reports directly to the Chief Information Officer.
 

Overall Responsibilities:

  • Serve as advisor to executive leadership on information security risks, IT compliance issues, and industry trends that will require prioritization, funding, and/or implementation support.
  • Oversee all information security related technologies and third-party vendor relationships.
  • Partner with Infrastructure, Operations and development teams to drive adoption and implementation of information security policies, procedures, standards, and incident handling processes.
  • Serve as liaison with leadership, legal, and internal audit, to analyze new requirements, standards, and capabilities and to determine feasibility and timing of implementation of new programs and capabilities. 
  • Conduct assessments/audits to confirm operational effectiveness of IT general controls and identify risk.
  • Manage development and assignment of access roles for all users across ERP platforms.
  • Provide risk metrics to management regarding audit performance and findings.
  • Assist control owners with root cause analysis and track risk management action plan progress.
  • Guide efforts to create common control framework and uniform compliance reporting standard.     

Specific Responsibilities:                                    

  • Planning and reviewing annual review of compliance requirements influencing operations and initiatives in information security, privacy, and IT risk management.
  • Performing examination of security controls to determine design and operational effectiveness.
  • Coordinate, plan, manage and maintain activities related to application security for multiple ERP systems and related applications, including but not limited to user profile assignments, system access permissions and user account maintenance.
  • Evaluate information security related technologies and implement the solutions.
  • Planning and reviewing annually the risks influencing the effectiveness of information security, privacy, and information security risk management.
  • Studying risk assessments conducted by business owners and support functions to incorporate relevant tests in assessment plans.
  • Conducting IT controls management testing of controls independent of the audit schedule to save time during audits.
  • Communicating with different levels of IT and business leaders on drivers of the information security risk assessment agenda.
  • Preparing the communications schedule with all stakeholders — CIO, CFO, Internal Audit, etc.
  • Identifying and tracking assessment/audit performance metrics.
  • Implementing and supervising the issue tracking and resolution process.
  • Reviewing IT audit risk assessments conducted by internal audit team members.
  • Planning third-party audits in consultation with IT, Internal Audit, business process owners and vendor management.
  • Reviewing third-party attestation and audit reports and providing feedback to business leaders and risk owners.
  • Collaborating with the internal audit team, their agents, and external auditors.
  • Monitoring Information Security assessment best practices in the industry to determine opportunities for improvement, including tools and processes.
  • Assisting business and support functions in evaluating tools and technology that support the enterprise's risk management approach.
  • Providing recommendations to business and IT leaders on practices followed in the industry to mitigate risks.
Qualifications:
  • Bachelor’s Degree in Business, Accounting, Information Technology, or other quantitative discipline.
  • 10+ years of broad privacy and data protection, compliance or legal experience
  • 5+ years of audit/assessment experience with PCI or SOX
  • 3+ years leading a team of auditors or compliance analysts
  • Sound understanding of security principles including logical access controls, change control, least privilege, segregation of duties, computer operations, network security, vulnerability management, an

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Overhead Door Corporation

View company profile →