Associate Director - Security Strategy & Analytics (Hybrid)
AbbVie
August 26, 2026
Remote friendly (Mettawa, IL)
United States
$141,500 - $268,500 USD yearly
IT
Responsibilities:
- Lead the metrics and reporting team (hiring, performance management, talent development, portfolio/processes/ways of working).
- Partner with security domain leaders to develop cross-functional reporting on security posture, operational health, and program value.
- Collaborate with ISRM leadership and portfolio management to define ISRM’s strategic direction (priorities, target state, multi-year roadmap) grounded in threat/risk insights, key metrics, business priorities, and delivery realities.
- Own ISRM’s strategic narrative via strategy documentation and executive communications/presentations.
- Translate strategic priorities into annual planning inputs (LRP and capital planning), ensuring investment rationale ties to execution roadmaps.
- Own and mature ISRM’s data lake and reporting platforms for consistent, accurate, timely decision support.
- Own and mature the semi-annual cyber business review process with periodic cybersecurity performance reporting.
- Track security maturity progress against frameworks such as NIST CSF and reflect results in priorities, roadmap inputs, and remediation planning.
Qualifications:
Required:
- Bachelor’s and 9 years; OR Master’s and 8 years; OR PhD and 4 years in relevant technical security roles (e.g., security architecture, security engineering, cyber defense).
- 4+ years leadership experience managing senior individual contributors in technical/analytical functions.
- Demonstrated experience in information security strategy, security program leadership, or security transformation in a large organization.
- Strong experience building complex cross-functional executive reporting.
- Exceptional executive communication and written communication (roadmaps, decision papers, governance narratives).
- Strong knowledge of corporate security domains (security architecture, AppSec, security operations, GRC, TPRM) and ability to build trust.
- Experience with NIST CSF (translating findings into priorities and remediation plans).
Preferred:
- 6+ years relevant technical security roles.
- Experience in security strategy, chief-of-staff, transformation, or metrics leadership.
- Hands-on software development/data engineering/security engineering.
- Experience with globally distributed teams.
- Experience developing multi-year security roadmaps, service strategies, operating model materials, or investment cases.
- Lead the metrics and reporting team (hiring, performance management, talent development, portfolio/processes/ways of working).
- Partner with security domain leaders to develop cross-functional reporting on security posture, operational health, and program value.
- Collaborate with ISRM leadership and portfolio management to define ISRM’s strategic direction (priorities, target state, multi-year roadmap) grounded in threat/risk insights, key metrics, business priorities, and delivery realities.
- Own ISRM’s strategic narrative via strategy documentation and executive communications/presentations.
- Translate strategic priorities into annual planning inputs (LRP and capital planning), ensuring investment rationale ties to execution roadmaps.
- Own and mature ISRM’s data lake and reporting platforms for consistent, accurate, timely decision support.
- Own and mature the semi-annual cyber business review process with periodic cybersecurity performance reporting.
- Track security maturity progress against frameworks such as NIST CSF and reflect results in priorities, roadmap inputs, and remediation planning.
Qualifications:
Required:
- Bachelor’s and 9 years; OR Master’s and 8 years; OR PhD and 4 years in relevant technical security roles (e.g., security architecture, security engineering, cyber defense).
- 4+ years leadership experience managing senior individual contributors in technical/analytical functions.
- Demonstrated experience in information security strategy, security program leadership, or security transformation in a large organization.
- Strong experience building complex cross-functional executive reporting.
- Exceptional executive communication and written communication (roadmaps, decision papers, governance narratives).
- Strong knowledge of corporate security domains (security architecture, AppSec, security operations, GRC, TPRM) and ability to build trust.
- Experience with NIST CSF (translating findings into priorities and remediation plans).
Preferred:
- 6+ years relevant technical security roles.
- Experience in security strategy, chief-of-staff, transformation, or metrics leadership.
- Hands-on software development/data engineering/security engineering.
- Experience with globally distributed teams.
- Experience developing multi-year security roadmaps, service strategies, operating model materials, or investment cases.