Global Leader in News Content Distribution
Cybersecurity Director
Location
United States
Posted
3 days ago
Salary
$230K - $245K / year
Seniority
Lead
Job Description
Cybersecurity Director
Business Wire
• Develop and maintain cybersecurity and GRC strategy and long-term roadmap, with the goal of enhancing overall strategy in alignment with business objectives. • Make continuous improvements to our security strategies to protect critical assets and data. • Provide strategic decision-making and problem-solving to navigate complex security and regulatory landscapes. • Manage a comprehensive Governance, Risk, and Compliance program in support of corporate audits, client assessments, and regulatory standards such as PCI DSS, SOC 2, and ISO 27001; ensure that our company meets all internal and external audit requirements. • Conduct regular risk assessments and periodic penetration testing and vulnerability assessments to identify and mitigate potential threats to the organization's infrastructure, applications, and data. • Manage the timely creation and dissemination of security-related communications including security awareness and training announcements, security compliance policies and processes, security alerts, and event messaging. • Provide oversight in maintaining a successful collaborative relationship with our external cyber defense partner, including evaluation of service delivery performance and in alignment with BW’s cybersecurity priorities. • Provide strategic leadership during cybersecurity incidents, coordinating with IT, Legal, HR, Privacy, Communications, and other stakeholders, and act as executive-level point-of-contact. • Offer senior-level guidance in developing and improving cybersecurity governance programs, policies, standards, and secure architecture guidelines. • Oversee enterprise cybersecurity risk assessments and ensure corrective actions are prioritized and implemented effectively; provide direction for privacy and data protection initiatives. • Provide leadership, guidance, and mentorship to cybersecurity and GRC team members, drive strong performance across all initiatives and support individual and team development. • Act as a trusted advisor to senior leadership on cybersecurity risk, architecture decisions, and strategic measures. • Use metrics to evaluate and track effectiveness of security, governance, and compliance initiatives. • Leverage exceptional communication skills to translate technical requirements into actionable business solutions.
Job Requirements
- Bachelor's or Master's degree in Computer Science, Information Security, or a related field.
- 10+ years of relevant industry experience in Information Security, with 5+ years of managerial and strategic leadership experience.
- Knowledge of data protection, privacy regulations, and cybersecurity governance frameworks.
- Expertise in cloud security, including AWS and Azure, as well as cybersecurity architecture, application security, identity management, and Zero Trust.
- Experience in data encryption, access controls, code reviews, and secure coding practices.
- Expertise in building and implementing GRC frameworks and risk management processes.
- Familiarity with regulatory compliance requirements, including PCI DSS, SOC 2, and ISO 27001.
- Certified Information Systems Security Professional (CISSP) or equivalent certification is a plus.
- Strong leadership and team-building skills.
- Excellent written and verbal communication skills with external and internal stakeholders and executives, and the ability to simplify complex cybersecurity topics.
- Ability to deliver constructive & encouraging feedback.
- Proactive, organized, analytical, detail-oriented, and persistent.
- Experience managing and overseeing external security service providers or technology partners.
Benefits
- Ability to work remotely
- Excellent health benefits that begin on your first day of employment
- $100 monthly fitness allotment, a tuition reimbursement program, and enhanced mental health resources
- 401(k) plan with generous company match, and annual profit sharing contribution (subject to company performance)
- PTO, Floating Holidays, Wellness Day Off, Birthday Day Off, and more!
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Senior IT Security Engineer
The Hanover Insurance GroupFor more than 170 years, The Hanover has been committed to delivering on our promises and being there when it matters the most. We live our values every day, demonstrating we CARE through our values, Sustainability initiatives and inclusive corporate culture.
Role Description We are seeking a highly experienced and skilled Senior IT Security Engineer to join our IT Security organization in our Worcester, MA office or remote work arrangement. The Senior IT Security Engineer (SIEM & IDS/IPS Administrator) is responsible for the end‑to‑end administration, maintenance, and optimization of the organization’s on‑premise Security Information and Event Management (SIEM) platform and Intrusion Detection/Prevention Systems (IDS/IPS). This role ensures that these critical security technologies remain highly available, strategically aligned with enterprise security objectives, governed according to policy, and operating at peak effectiveness. The engineer will work closely with cybersecurity, infrastructure, and governance teams to ensure that threat detection, alerting, and response capabilities are robust, reliable, and continuously improving. This is a full time, exempt position. Responsibilities - SIEM Administration & Engineering - Manage, maintain, and optimize the on‑premise SIEM platform, including log ingestion, parsing, correlation rules, dashboards, and alerting. - Ensure SIEM availability, performance, and scalability to support enterprise security monitoring needs. - Develop and tune detection rules, correlation logic, and use cases aligned with threat intelligence and organizational risk. - Oversee log source onboarding, configuration, and validation across servers, applications, network devices, and security tools. - Conduct regular SIEM health checks, capacity planning, and lifecycle management. - IDS/IPS Administration & Engineering - Administer and maintain on‑premise IDS/IPS platforms, ensuring accurate detection and prevention of malicious activity. - Tune signatures, policies, and rulesets to reduce false positives while maintaining strong detection coverage. - Monitor IDS/IPS performance, availability, and event trends to identify anomalies or operational issues. - Coordinate with network and security teams to implement policy updates, rule changes, and architectural improvements. - Operational Excellence & Governance - Ensure both SIEM and IDS/IPS solutions are aligned with security governance frameworks, compliance requirements, and organizational policies. - Maintain documentation for system configurations, processes, runbooks, and governance controls. - Support audit activities by providing evidence, reports, and system configuration details. - Participate in incident response activities by providing SIEM/IDS/IPS insights, event analysis, and technical expertise. - Strategic Alignment & Continuous Improvement - Evaluate emerging threats and recommend enhancements to detection logic and monitoring capabilities. - Collaborate with architecture and leadership teams to align SIEM and IDS/IPS strategies with long‑term security objectives. - Identify opportunities to automate processes, improve detection fidelity, and enhance operational efficiency. Qualifications - Minimum 5 years of hands‑on experience administering, managing, and maintaining an on‑premise SIEM security solution and an on‑premise IDS/IPS security solution. - Demonstrated experience ensuring high availability, governance alignment, and operational effectiveness of security monitoring technologies. - Strong understanding of SIEM architecture, log ingestion pipelines, correlation logic, and event normalization. - Expertise with IDS/IPS technologies, signature tuning, network traffic analysis, and threat detection methodologies. - Proficiency with security log formats (syslog, JSON, CEF, LEEF, etc.). - Familiarity with network protocols, firewall rules, and enterprise network architecture. - Experience with Linux/Windows server administration as it relates to security tooling. - Ability to analyze security events, identify patterns, and support incident response. - Strong analytical and problem‑solving abilities. - Excellent communication skills for cross‑team collaboration. - Ability to work independently in a remote environment while managing multiple priorities. - Detail‑oriented mindset with a commitment to governance, documentation, and operational discipline. Preferred Qualifications - Industry certifications such as: - GIAC (GCIA, GCDA, GCED, GMON) - CompTIA Security+ / CySA+ - CISSP or equivalent - Experience with automation (Python, PowerShell, or similar). - Familiarity with threat intelligence platforms and frameworks (MITRE ATT&CK, NIST CSF). Benefits - Medical, dental, vision, life, and disability insurance - 401K with a company match - Tuition reimbursement - PTO - Company paid holidays - Flexible work arrangements - Cultural Awareness Day in support of IDE - On-site medical/wellness center (Worcester only) EEO Statement The Hanover values diversity in the workplace and among our customers. The company provides equal opportunity for employment and promotion to all qualified employees and applicants on the basis of experience, training, education, and ability to do the available work without regard to race, religion, color, age, sex/gender, sexual orientation, national origin, gender identity, disability, marital status, veteran status, genetic information, ancestry or any other status protected by law. Furthermore, The Hanover Insurance Group is committed to providing an equal opportunity workplace that is free of discrimination and harassment based on national origin, race, color, religion, gender, ancestry, age, sexual orientation, gender identity, disability, marital status, veteran status, genetic information or any other status protected by law. As an equal opportunity employer, Hanover does not discriminate against qualified individuals with disabilities. Individuals with disabilities who wish to request a reasonable accommodation to participate in the job application or interview process, or to perform essential job functions, should contact us at: HRServices@hanover.com and include the link of the job posting in which you are interested.
SVP, Chief Information Security Officer
Finance of AmericaEmpowering 55+ customers with modern reverse mortgage options to fund the next chapter in life. NMLS #2285
• Provides top-level strategic executive leadership oversight • Acts as a key advisor for the enterprise’s systems security and data integrity • Participates in the formulation of general management policy • Develops and monitors short- and long-term security standards and best practices • Provides final approval for strategic information systems security plans • Drives technology risk and change management priorities • Monitors the execution of strategic plans for disaster recovery and business continuity • Analyzes and resolves escalated IT security related issues • Directs the development and production of reporting tools, key performance metrics, and policies • Proactively addresses and resolves conflict and helps others navigate ambiguity
Azure Solutions, Security Architect
Ascend TechnologiesInnovation & Technology Enabling Business Growth
• Design and lead enterprise Azure solutions across compute, networking, identity, storage, logging, and monitoring. • Architect secure Azure landing zones and hybrid cloud environments aligned with Microsoft best practices and organizational standards. • Lead cloud migration and modernization initiatives from on-premises or legacy platforms to Azure. • Design and implement Infrastructure as Code (IaC) using ARM, Bicep, and/or Terraform. • Design and support CI/CD pipelines to enable automated, repeatable, and compliant infrastructure deployments. • Embed security-by-design and Zero Trust principles into all Azure architectures. • Design and implement Azure-native security controls, including Azure Policy, Microsoft Defender for Cloud, Microsoft Sentinel, identity protection, and conditional access. • Perform cloud security posture reviews and environment readiness assessments. • Serve as a senior advisor for cloud security and compliance initiatives aligned to ISO 27001, SOC 1/2, GDPR, TISAX, and similar regulatory frameworks. • Lead the interpretation, design, implementation, and operationalization of security and compliance controls within Azure environments. • Conduct compliance and risk gap assessments and translate regulatory requirements into Azure-native technical and operational controls. • Support audit readiness activities, including evidence preparation, control validation, and remediation planning. • Act as a trusted advisor to engineering teams, business leaders, and executive stakeholders.
• Support and continuously improve the ISMS, including compliance activities, audit preparation, evidence collection, risk tracking, and remediation follow-up. • Translate security and compliance requirements into practical technical controls and verify their effectiveness. • Implement and operate core security controls in the Microsoft / Entra environment, including MFA, Conditional Access, role-based access, privileged access practices, access reviews, endpoint security, and hardening. • Coordinate operational security activities such as Cyber Defence Center investigations, vulnerability and patch management, incident response, backup/restore security, ransomware resilience, and restore-test evidence. • Integrate security into IT operations, change/release processes, and service management, and report the security posture using relevant KPIs such as MFA coverage, device compliance, patch status, critical risks, and restore-test success.



