- Company Name
- Eleven Recruiting
- Job Title
- Director of Information Security
- Job Description
-
**Job Title:** Director of Information Security
**Role Summary:** Lead the enterprise information security function for a global investment firm, steering a strategy that ensures compliance with regulatory mandates (SEC, FINRA, GDPR, etc.), protects sensitive data, and mitigates cyber risk across all technology assets. Oversee security governance, incident response, vendor risk management, and team development while reporting to executive leadership.
**Expectations:**
- Deliver a comprehensive, risk‑based security program aligned with business goals.
- Maintain up‑to‑date policies, procedures, and controls that satisfy legal, regulatory, and industry standards.
- Foster a culture of security awareness and continuous improvement across the organization.
**Key Responsibilities:**
- Develop, update, and enforce security policies, procedures, and standards per SEC, FINRA, GDPR, and other regulations.
- Lead and manage the security team, including mentoring, resource allocation, and performance management.
- Design and implement security architecture: network defenses, endpoint protection, data loss prevention, threat intelligence, and monitoring.
- Conduct regular risk assessments, vulnerability scans, penetration tests, and audits of security controls.
- Coordinate incident response: investigation, containment, mitigation, and post‑incident analysis.
- Manage vendor risk program, including third‑party security due diligence and contract oversight.
- Collaborate with IT, legal, and compliance to ensure secure adoption of new technologies and alignment with data privacy obligations.
- Prepare and manage security budget, forecast resource needs, and report on program status to executives and the cybersecurity committee.
- Maintain security documentation: Information Security Program, Incident Response Plan, policies, procedures, and presentations.
- Oversee patch management, security hardening, and configuration controls for Windows and third‑party software.
- Conduct security awareness training, phishing simulations, and onboarding/offboarding security processes.
- Provide daily monitoring of alerts, maintain incident logs, and ensure timely reporting of significant events.
**Required Skills:**
- Strategic leadership and program management in information security.
- Deep knowledge of regulatory requirements (SEC, FINRA, GDPR) and risk assessment frameworks.
- Expertise in network security, endpoint protection, IAM, DLP, threat intelligence, and SIEM.
- Incident response and crisis management capability.
- Vendor risk management and third‑party security assessment experience.
- Strong communication skills for presenting technical findings to executives and committees.
- Ability to mentor, motivate, and develop a cross‑functional security team.
**Required Education & Certifications:**
- Bachelor’s or Master’s degree in Information Security, Computer Science, Information Systems, or related discipline.
- Minimum of 10 years’ experience in information security or IT risk management, with at least 5 years in a leadership role.
- Professional certifications: CISSP, CISM, CISA, or equivalent.
Santa monica, United states
On site
Senior
05-11-2025