What are the responsibilities and job description for the Cybersecurity Director position at The Emery Company?
Cybersecurity Director
POSITION SUMMARY:
The Cybersecurity Director is responsible for managing the Cybersecurity Program designed to advise the organization on its management of Cybersecurity risk by supporting risk-based management decisions; developing, deploying, monitoring, tuning, evaluating, reporting on and maintaining systems and procedures; and identifying and mitigating threats to the corporate network, corporate assets, and corporate users to ensure the security of company systems and information assets.
This team member is responsible for leading both technical implementation of systems, and communication of security requirements to management and security leadership. Additionally, this team member will be responsible, as necessary, with leading investigations into security threats, working with internal and external groups to ensure the Cybersecurity program is operating effectively and efficiently, and developing strong partnerships across the enterprise to ensure information assets are protected at the appropriate level.
As our Cybersecurity Director, you will be responsible for managing cybersecurity processes, defining risk areas, reviewing third party partner compliance, and coordinating incident response across all businesses and locations. Oversight of secure development practices across the organizations software and product development lifecycles.
The Cybersecurity Director is responsible for: ensuring that all systems are effectively and efficiently monitored by assigned staff; investigating and triaging notable events according to severity level; providing tier one (1) and two (2) support to enterprise customers; and maintaining cybersecurity controls and processes that help manage overall risk at an acceptable level. The role ensures that cybersecurity best practices are followed in the environment and that our company is able to aggressively respond to any attempts to compromise our infrastructure, information, or operations. The Cybersecurity Director directly interacts with our Information Technology and Production security teams on addressing issues identified by vulnerability scans or penetration test among other sources. The Cybersecurity Director partners closely with the Information Technology and our supporting vendors.
PRIMARY RESPONSIBILITIES INCLUDE:
- Manage a “first-line of defense” team with eyes-on-glass for a number of alerts associated with Phishing, Data Loss Prevention, Policy Violations, User-Behavior Analytics, and Network and Host-based anomalies.
- Mentor, Train and Develop staff members in triage and investigation methodologies.
- Support Incident Response in coordination with HR, Legal, Privacy and Corporate Security initiatives and investigations.
- Lead the integration of secure coding practices into the SDLC, collaborating with development teams to implement security controls without hindering innovation.
- Oversee application security testing (e.g., static / dynamic code analysis, penetration testing) and ensure remediation of vulnerabilities.
- Identify opportunities for enhanced data enrichment, alert creation & tuning, or automation, based on the teams need.
- Partner with our Governance, Architecture, and Engineering and Operations organizations to develop process enhancements and Tabletop Exercises to further our maturity.
- Monitor internal and external policy and contractual cybersecurity compliance of third parties.
- Review cybersecurity risks associated with new technology solutions, including contractual implications in coordination with the Legal function.
- Continuously monitor current state of cybersecurity utilizing outside resources, primary research, and third-party partners to ensure we are aware of the latest issues and solutions.
- Provides oversight of project and program implementation including all activities, outputs, and outcomes related to project management and administration, including reporting, budget development and monitoring, financial transactions, execution of project plans, and project performance
- Ensure effective monitoring, measuring, reviewing and updating project process, adjusting project plans and implementing remedial plans and informing all relevant parties.
- Manage the ISO 27001 process which may include defining controls, policies and procedures to ensure compliance. Conducts or oversees regular audits of the ISO 27001 controls.
- Design policies, processes, practices, guidelines, standards, and baselines that are mapped directly to business risks to measure for effectiveness and adherence.
- Liaise with business units, leadership, and law enforcement as needed.
- appreciates and enjoys coaching junior team members on cybersecurity best practices (Mentor associates)
- Manage vendor relationships and negotiate service agreements to optimize cybersecurity investments
- Advise Leadership on emerging security trends, and prepare communications on the same
REQUIRED QUALIFICATIONS:
- Minimum of 7-10 years of experience in one or more of the following domains: Cybersecurity, Information Security, Network Engineering or Operations, Information Technology, Application Development, Access Control, Security Governance, Risk Management, Software Development Security, Cryptography, Security Architecture and Design, Operational Security, Business Continuity & Disaster Recovery, Legal Regulations, Investigations and Compliance, Physical (Environmental) Security, IT or Security Audit, IT or Security Compliance required
- 10 years of experience in large and complex business environments with a successful track record working directly with senior level management preferred
- Bachelor’s degree in Information Technology or related functional areas: Supply Chain, Finance, Engineering.
PREFERRED QUALIFICATIONS:
- Local and wide area networking concepts, principles and protocols
- Advanced knowledge in Infrastructure design and management
- Working knowledge of management processes such as personnel administration, planning and budgeting
- Advanced understanding of IT Service Management (ITSM) best practices and processes
- Strong understanding of application layer protocols including HTTP, SSH, SSL and DNS
- Practical experience and knowledge of the latest Cybersecurity legislations, regulations, advisories, alerts, vulnerabilities and Cybersecurity frameworks
- Experience with cybersecurity in a multi-site, global organization.
- Strong interpersonal, verbal, and written communication skills to effectively communicate with all levels throughout the organization and external vendors, strong customer service orientation, excellent problem-solving skills and the ability to drive for results.
- Ability to effectively negotiate with vendors on upgrades and acquisitions
- Advanced information security standards/frameworks (ie, NIST Cybersecurity Framework, ISO 27001) skills
- Advanced experience with Network and VLAN segmentation
- Management of all certification processes related to Cybersecurity including but not limited to ISO 270
Pay: $160,000.00 - $180,000.00 per year
Benefits:
- Dental insurance
- Health insurance
- Paid time off
- Vision insurance
Education:
- Bachelor's (Required)
Experience:
- IT Service Management : 9 years (Required)
- Security Architecture and Design: 9 years (Required)
- Operational Security: 9 years (Required)
- Cybersecurity Management: 7 years (Required)
Work Location: Hybrid remote in Atlanta, GA 30309
Salary : $160,000 - $180,000