- Company Name
- Lovesac
- Job Title
- Director, Cybersecurity
- Job Description
-
Job Title: Director, Cybersecurity
Role Summary: Lead the vision, strategy, and execution of the organization’s cybersecurity program, safeguarding IT systems, infrastructure, and data against cyber threats. Drive a security‑centric culture, align initiatives with business goals, and report directly to executive leadership and the Board.
Expactations: 10+ years in cybersecurity, 5+ years in senior leadership roles; proven track record of building and scaling security programs. Strong business acumen, ability to influence stakeholders at all levels, and experience managing cross‑functional incident response and business continuity.
Key Responsibilities:
- Develop and execute a comprehensive cybersecurity strategy aligned with business objectives and regulatory requirements.
- Communicate vision, motivate teams, and lead a high‑performing cybersecurity staff.
- Provide executive updates on posture, risks, and mitigation.
- Oversee risk assessments, incident response, vulnerability management, and third‑party/vendor risk programs.
- Ensure compliance with GDPR, CCPA, SOX, PCI DSS, NIST CSF, and internal policies.
- Manage cybersecurity systems, architecture, network, endpoint, identity, and cloud security; drive zero‑trust and secure SDLC integration.
- Conduct horizon scanning, threat intelligence, and emerging technology evaluation.
- Collaborate with IT, business units, and executives on digital transformation initiatives.
- Lead incident response, crisis management, and business continuity planning.
- Set performance objectives, manage budgets, vendor relationships, and program maturity models.
Required Skills:
- Strategic leadership and program management.
- Deep knowledge of threat assessment, incident response, vulnerability management, and risk frameworks.
- Expertise in regulatory compliance (GDPR, CCPA, SOX, PCI DSS, NIST CSF).
- Proficiency in security architecture, cloud security, zero‑trust, network, endpoint, and identity management.
- Strong communication, stakeholder engagement, and executive reporting.
- Experience with vendor risk management, supply chain security.
Required Education & Certifications:
- Bachelor’s degree in Computer Science, Information Systems, Cybersecurity, or related field (Master’s preferred).
- Professional certifications: CISSP, CISM, CISA, CEH, CCSP, or equivalent.