Director, Information Security
Location: Spartanburg, SC, United States
Description
Director, Information Security (DIS)
JOB DESCRIPTION
Summary/Objective
The Director of Information Security will report to the CISO, and be responsible for establishing information security operations standards and policies. The DIS will recommend Information Security investments which mitigate cyber and insider risks, strengthen defenses, and reduce vulnerabilities for development, internal and client facing systems and products. In this role, the DIS must be able to not only define a strategic vision, but must also be able to implement and execute against it. The DIS is responsible for design, implementation, and maintenance of controls and procedures to ensure the integrity and security for all computer-based systems and networks across all technical platforms. In addition, the DIS will oversee the Access Management onboarding and offboarding functions. The DIS will be responsible for Security Operations Center (SOC) functions including, but not limited to system monitoring, vulnerability analysis, and incident response. The DIS will work closely with other business groups and stakeholders, including Legal, Compliance, Audit and Risk ensuring the protection of information and assets including data, systems, databases, networks, and other resources.
Essential Functions
Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.
- Develop, implement and monitor a strategic, comprehensive enterprise information security operations program.
- Leverage information security experts and technology to support a secure infrastructure, secure applications, and overall data security.
- Ensure compliance with organizational security policies and standards; proactively work with business units to implement practices that meet defined policies and standards for information security.
- Create content to be included in company security awareness training programs.
- Provide subject matter expertise to executive management on a broad range of information security standards, best practices, and compliance requirements.
- Work with developers and architects to ensure security is built into the development cycle.
- Coordinate the performance of internal and external network and systems vulnerability assessments and penetration tests.
- Coordinate organizational efforts in response to security events.
- Coordinate use of external resources involved in the information security program including negotiating.
- Develop business-relevant metrics to measure the efficiency and effectiveness of security operations, facilitate appropriate resource allocation, and increase the maturity of security operations.
- Provide oversight and accountability of the day-to-day security operations and/or other administrative areas.
- Develop and maintain the security function of maintaining security access to corporate communication and computing systems including all onboarding and off boarding functions
- Oversee on-going security monitoring of organization information.
- Assess information security risk as well as conduct functionality and gap analyses to determine the extent to which key business areas and infrastructure comply with statutory and regulatory requirements.
Qualifications
- 7+ years of experience in the information security field and 5+ years of leadership in an information security role
- 5+ years managing a security operation in premise-based, cloud, and hybrid infrastructures
- 5+ years managing identity and privileged access management systems
- BA/BS required, MS in Information Security or other relevant post-graduate degree a plus
- Experience with Financial industry compliance regulations
- CISSP or CISM, CEH, CHFI certifications preferred
- NIST, PCI-DSS, and SOC2 compliance experience required
- Experience in developing an entrepreneurial organization is significant advantage
- Proven experience with current information security technologies
- Demonstrated understanding of technological developments in the areas of information security
- Ability to drive execution of aggressive goals through effective planning, prioritization, resource management and follow through
- Proven track record of building influential relationships with internal customers; ability to influence across departmental lines without direct authority
- Ability to think strategically and identify and understand business needs and translate into strategic direction, plans and solutions
- Experience working with business process reengineering and IT solutioning; experience working on project teams bringing together both business & technology. Capable of explaining technical concepts to a non-technical audience
- Superior verbal and written communication skills, including ability to tailor communications based on audience
- Experience leading people with demonstrated ability to attract, develop, motivate and retain talent
- Proficiency in interpreting financial results and business data to identify opportunities and risks
Supervisory Responsibility
Supervisory Experience Required.
Work Environment and Physical Demands
This job operates in a professional office environment. This role routinely uses standard office equipment such as computers, phones, photocopiers, filing cabinets and fax machines.
Position Type/Expected Hours of Work
This is a full-time position. Days of work are Monday through Friday. The daily schedule may vary from 8 am to 5 pm or 9 am to 6 pm. Hours may vary or exceed 40 in any given week depending on the needs of the business.
Travel
This position requires up to 25% travel.
EEO Statement
ACA provides equal employment opportunities (EEO) to all applicants for employment without regard to race, color, religion, gender, sexual orientation, gender identity or expression, national origin, age, disability, genetic information, marital status, amnesty, or status as a covered veteran in accordance with applicable federal, state and local laws. ACA complies with applicable state and local laws governing non-discrimination in employment in every location in which the company has facilities.
Please note this job description is not designed to cover or contain a comprehensive listing of activities, duties or responsibilities that are required of the employee for this job. Duties, responsibilities and activities may change at any time with or without notice.
Interested in working for American Credit Acceptance?
Take the first step by joining our Talent Network today!