Jobs and Careers
VI

Director, Cyber Governance

Vistra
Royal Lane Office, United States, United Statesfull_timeVerifiedPosted 30 Jan 2025

About the role

If you have what it takes to become part of the Vistra family and would like to start a promising career with a global leader, take a look at the exciting employment opportunities that are currently available and apply online.

Job Summary

The Director of Cyber Governance will lead the development and implementation of the cybersecurity governance framework, ensuring alignment with corporate policies, industry standards, and regulatory requirements. This role will act as the strategic liaison between cybersecurity, compliance, and various business units to integrate governance practices that foster risk management, adherence to policies, and the achievement of business objectives. This role will also oversee the governance of managed security services, ensuring that third-party security providers adhere to the organization's policies, standards, and risk management practices.

Job Description

Key Accountabilities

  • Lead the creation and maintenance of the cybersecurity governance framework, ensuring alignment with corporate goals, compliance obligations, and industry best practices.
  • Oversee the development of metrics and reporting structures to measure adherence to cybersecurity policies and the effectiveness of governance initiatives.
  • Collaborate with various business units to promote the integration of cybersecurity governance into business operations and strategic planning.
  • Coordinate cross-functional committees and working groups focused on governance-related initiatives, such as policy reviews and compliance assessments.
  • Provide leadership in risk assessment processes and ensure that governance frameworks are maintained to support effective risk management.
  • Educate and train staff on cybersecurity governance principles and their role in upholding policy compliance and risk mitigation.
  • Develop and drive strategies for continuous improvement of governance practices, ensuring they evolve with emerging risks, technologies, and business needs.
  • Advise senior management and stakeholders on key governance risks and recommended mitigation strategies.
  • Drive the alignment of cybersecurity governance with the organization's broader enterprise risk management (ERM) framework.
  • Oversee the governance and performance of managed security services, ensuring third-party vendors comply with the organization’s policies and security standards.

Education, Experience, & Skill Requirements

  • Experience gained through college degree programs or certifications in Information Systems, Business, or Computer Science
  • Strong understanding of cybersecurity frameworks (e.g., NIST, ISO 27001), regulatory requirements, and industry best practices.
  • 15+ years of working in an IT environment
  • 8-10 years of technology team management experience 
  • Excellent interpersonal, communication and teaming skills.
  • Ability to navigate technology environment and work effectively with multiple teams.
  • Demonstrated ability to be trustworthy and dependable 
  • Ability to learn quickly, be self motivated to improve knowledge and tackle new challenges.
  • Ability to prioritize requests to deliver highest-impacting items first.
  • Deliver business value of technology solutions. 
  • Proven ability to develop team members.

Key Metrics

  • Team member engagement across technology department
  • Tools adoption and usage, where appropriate
  • Implement improvements that result in reduced operating or capital expense
  • Implement automation that results in increased operational efficiency and decreased operational cost.
  • Team member retention / development.

  • Ability to design and implement governance models that integrate seamlessly with business objectives.
  • Demonstrated leadership in building and managing cybersecurity governance programs and cross-functional initiatives.
  • Strong analytical skills to assess complex regulatory and compliance requirements and their impact on the organization.
  • Aptitude for fostering a culture of cybersecurity awareness and adherence to governance standards.
  • Excellent problem-solving, project management, and strategic planning skills.
  • Ability to influence and partner with stakeholders at various levels of the organization to align govern

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Vistra

View company profile →