Jobs and Careers
AB

Director of Governance and Strategy

ABM Industries
United Statesfull_timeVerifiedPosted 3 Jun 2024

About the role

Reporting to the chief information security officer (CISO), the information security Governance and Strategy Director is a highly visible member of the information security team. This role will also be responsible for the Information Security Governance (reporting, metrics, policy, training and awareness and resiliency program. The director develops, plans, executes and tests the availability and recovery of business processes. This is an advanced role that requires a broad understanding of both technical solutions and business functions. The director supports continuous changes to the business to ensure critical processes are identified and prioritized according to business needs. The manager acts a liaison to business stakeholders to understand their strategy and execution outlook. 

The director is expected to be an excellent communicator who exuberates confidence but is humble and capable of interfacing with all levels of management and personnel. Additionally, and ideally, the director is a strong practitioner background and can readily collaborate with technical department leads and their direct reports. On a daily basis, the director ensures the CISO is fully briefed and prepared for business and technical meetings, financial reporting, personnel management, operational stability, project status updates, strategic relationships, as well as incident(s) status and any breaking news related to cybersecurity. 

Essential Functions:

  • Provide the CISO executive support with strategic planning and daily initiatives.
  • Act as a key point of contact with senior management, information security management and business unit stakeholders for cybersecurity-related communications. 
  • Assist with program roadmaps and communications disseminated throughout the organization. 
  • Work in tandem with the CISO, information security management and other technology leaders on financial planning and analysis, and additional fiduciary responsibilities.
  • Monitor all information security projects and procurement from inception to successful completion, fully understanding the purpose of projects, technologies and their value-add to the organization.
  • Adhere to strategic risk management vision and decisions that scale globally to secure by design without slowing company innovation and execution.
  • Promote a strong security culture within the security department, but also organization-wide across management and employees.
  • Maintain adequate knowledge on best practice recommendations based on the evolving threat landscape to protect the business. 
  • Work with information security management to help define key performance indicators (KPIs) and metrics that align with business initiatives and deliver to non-technical individuals.
  • Support security governance process across the business in conjunction with an information security steering committee and advisory board. 
  • Help prepare and refine board-level and senior management presentations and company-wide information security communications. 
  • Facilitate, attend and document meetings and action items, in tandem or in lieu of the CISO. 
  • Maintain open lines of communications with business units to understand their plans and how information security can securely enable them to execute their vision and business obligations. 
  • Participate in new business or M&A activity requiring information security input.
  • Under the purview of the CISO, report regularly to senior management and boards to keep them abreast of the threat landscape and the tactical controls and strategic plans required to achieve success. 
  • Require and aid in scheduling and management, independent verification and validation testing of the company networks and sensitive programs through internal team resources and independent consulting engagements.
  • Confirm third-party audit reviews of internal departments and report results to management and security oversight committees. 
  • Be highly involved with IT security programs to confirm the company’s systems are fully compliant with all applicable regulatory requirements and privacy laws.
  • Recognize the varying strengths, skills and needs of the team and possess/adapt leadership skills to obtain the best possible results from individuals. 
  • Work with a team to consistently learn and share advanced skills and practices that promote team excellence.
  • Build relationships with business leaders, technical teams, governance and third parties to incorporate availability and recovery needs. 
  • Serve as a primary point of contact and subject matter expert for new and existing BC planning and recovery objectives.
  • Maintain templates that align with strategies around business applications, impact assessment, key dependencies, and recovery objectives and expectation

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

ABM Industries

View company profile →