What are the responsibilities and job description for the Director of Cybersecurity position at American Bath Group?
Director, Cybersecurity
American Bath Group | Irving, TX
Onsite 4 days/week | Travel up to 25%
Reports to: Vice President, IT
American Bath Group is seeking a Director, Cybersecurity to lead the build-out and continuous maturation of our enterprise cybersecurity program across a private equity-backed, multi-brand manufacturing and distribution environment.
This is a hands-on leadership role in an actively maturing program. The Director will own the cybersecurity vision, maturity roadmap, controls reporting, security governance, core tooling deployment, incident response readiness, and cybersecurity capability stand-up for newly acquired businesses. This leader will serve as ABG’s internal cybersecurity authority while partnering closely with the Director of Infrastructure and external security advisory partners.
The Opportunity
This role is designed for a builder. ABG is continuing to mature cybersecurity across corporate systems, acquired businesses, and plant-floor environments. The right leader will bring structure, urgency, technical depth, and practical execution to a cybersecurity function that must support business growth, manufacturing continuity, and ongoing M&A activity.
This is not a policy-only or presentation-oriented cybersecurity role. The successful candidate must be able to set direction independently, evaluate and deploy core security capabilities, build governance, translate risk to business leaders, and execute directly when needed.
The Mandate
The Director, Cybersecurity will build, operationalize, and mature ABG’s enterprise cybersecurity program by strengthening governance, deploying core security tooling, improving identity and access discipline, advancing vulnerability and exposure management, operationalizing incident response and business continuity, and creating a scalable cybersecurity model for future acquisitions.
Core Areas of Ownership
Enterprise cybersecurity program leadership
Own the cybersecurity vision, strategy, maturity roadmap, controls reporting, budget input, vendor selection, and operating cadence.
Governance and compliance maturation
Build and enforce practical security policies, user provisioning discipline, periodic access reviews, data classification and handling standards, email policies, security awareness training, and third-party/vendor risk management.
Security tooling deployment
Lead selection, implementation, and ongoing operation of core capabilities including Managed Detection & Response (MDR), Cloud Access Security Broker (CASB), Privileged Access Management (PAM), vulnerability and exposure management, endpoint security, email security, cloud security, and identity/access security.
Identity and access security
Strengthen MFA, PAM, SSO, Active Directory governance, multi-domain identity environments, user access requests, and recurring user access reviews.
Incident response, business continuity, and disaster recovery
Own cross-functional incident response plans, incident-specific playbooks, Business Impact Analyses, tabletop exercises, and defined RPOs/RTOs across business units.
M&A cybersecurity and integration
Lead cybersecurity due diligence, integration planning, capability stand-up, and transition from seller-provided TSA services to a stable standalone security state for acquired businesses.
Manufacturing and OT/ICS security
Extend practical monitoring, segmentation, and risk management into operational technology and plant-floor environments in partnership with operations and infrastructure leadership.
Infrastructure partnership
Serve as the cybersecurity standard-setter across M365 tenant hardening, cloud security posture, network, endpoint, and identity decisions in support of the Director of Infrastructure.
Leadership communication
Report cybersecurity posture, risk, progress, and investment tradeoffs clearly and credibly to executive leadership, the Audit Committee, and the Board.
Team leadership
Build, lead, mentor, and develop cybersecurity talent as the internal function scales.
Success in Year One
By the end of Year One, the successful leader will have helped move ABG toward a more structured, governable, and repeatable enterprise cybersecurity model. Key outcomes include:
- A clear cybersecurity maturity roadmap is in place, governed, and connected to business risk and investment decisions.
- MDR is implemented and operationalized for 24/7 monitoring and detection.
- CASB and cloud security controls are evaluated, deployed, and matured.
- PAM tooling and operating processes are deployed for privileged users and applications.
- User provisioning, access requests, access reviews, SSO, MFA, and Active Directory governance are measurably stronger.
- Vulnerability and exposure management includes risk-based prioritization, remediation SLAs, penetration testing cadence, and exposure reduction discipline.
- Email security controls, including MFA enforcement and DMARC/DKIM progression, are improved.
- Incident response, business continuity, disaster recovery, tabletop exercises, BIAs, RPOs, and RTOs are active operating routines.
- Cybersecurity diligence, onboarding, integration, and TSA separation are repeatable for acquired businesses.
- Practical monitoring, segmentation, and risk management are extended into OT/ICS and plant-floor environments.
Why This Role Is Challenging
This role requires a leader who can build structure while operating inside real-world constraints. ABG is not looking for someone who only delegates, writes policy, or presents abstract frameworks. The business needs a cybersecurity leader who can move from roadmap to implementation, from executive risk conversations to vendor decisions, and from governance into practical operating rhythms.
The environment spans multiple business units, brands, corporate systems, acquired environments, and manufacturing sites. Cybersecurity must protect the enterprise while supporting manufacturing continuity and business growth.
Leadership Profile
The right candidate will be:
- A hands-on cybersecurity builder who can set direction and execute directly when needed.
- A pragmatic risk translator who communicates cybersecurity tradeoffs in business terms.
- An operational security leader who turns tools, controls, policies, and plans into working routines.
- A manufacturing-aware security partner who understands plant-floor realities.
- An M&A-ready integrator who can assess, stand up, and integrate cybersecurity capability quickly.
- An influence-based collaborator who can work across infrastructure, IT leadership, operations, advisors, vendors, executives, and the Board.
- A team developer who can mentor analysts and managers as the function scales.
Required Experience
- 10 years of progressive cybersecurity experience, including security leadership or program ownership responsibility.
- Experience owning or building an enterprise cybersecurity program, including strategy, maturity roadmap, governance, budget input, and vendor selection.
- Hands-on experience deploying and operating capabilities such as MDR, CASB, vulnerability/exposure management, endpoint security, email security, cloud security, MFA, PAM, SSO, and Active Directory security.
- Experience leading incident response and building IR, business continuity, disaster recovery plans, playbooks, and tabletop exercises.
- Experience securing manufacturing or industrial environments, including OT/ICS security and plant-floor network segmentation.
- Working knowledge of cybersecurity frameworks and risk management practices such as NIST CSF, CIS Controls, or ISO 27001.
- Ability to mentor and elevate technical staff, influence without direct authority, and operate as a trusted peer across IT leadership.
- Bachelor’s degree in information systems, Computer Science, Cybersecurity, a related field, or equivalent professional experience.
Preferred Experience
- Experience in private equity-backed or M&A-active environments.
- Experience with post-acquisition cybersecurity integration and separation from seller-provided TSA services.
- Relevant certifications such as CISSP, CISM, or equivalent.
- Advanced degree in a relevant field.
- Steady career progression with demonstrated promotion and tenure.
Why the Right Candidate Will Be Excited
This is a rare opportunity to own the build-out of an enterprise cybersecurity function with direct visibility, meaningful business relevance, and executive sponsorship. The right candidate will be energized by creating durable capability rather than simply inheriting a mature program.
This leader will shape tool selection, governance discipline, operating routines, cybersecurity standards, M&A integration practices, and plant-floor security maturity across a complex and growing enterprise.
Why This Role Matters
Cybersecurity maturity is central to ABG’s ability to operate, acquire, integrate, and scale. This leader will help convert cybersecurity from a set of projects and risks into an enterprise capability that protects the business, supports growth, and gives leadership better visibility into operational and investment tradeoffs.