Summary of Position:
Senior Director, Cybersecurity (Chief Information Security Officer) responsible for building and scaling enterprise cybersecurity capabilities protecting people, data, technology assets, intellectual property, and business operations. Reporting to the CIO; defines and executes the cybersecurity strategy and roadmap with enterprise stakeholders.
Position Responsibilities
- Define and execute enterprise cybersecurity strategy, roadmap, priorities, and operating model.
- Establish governance, policies, standards, and control frameworks; prioritize maturity initiatives by risk and regulatory/commercial needs.
- Serve as primary cybersecurity advisor to CIO/Board/business leadership; translate risks into actionable recommendations.
- Own target-state security architecture and technology roadmap across cloud, infrastructure, identity, endpoint, network, application, SaaS, and data.
- Lead security engineering; embed secure-by-design and risk-based principles; integrate security into solution design and operations.
- Own security operations (vulnerability management, incident response, monitoring, identity security, cyber resilience); mature detection/response/recovery.
- Lead incident response, executive communications, and post-incident reviews; support BCDR and cyber resilience planning.
- Lead enterprise governance, risk, and compliance; maintain NIST alignment; develop metrics (KPIs/KRIs) and executive reporting.
- Support SOX IT General Controls, user access governance, change management controls, and third-party risk management.
- Lead data protection for sensitive/regulated data; support privacy-by-design and least privilege; partner on privacy obligations and vendor risk.
- Serve as cybersecurity lead for audits/inspections; ensure controls for GxP systems, CSV, and data integrity; remediate findings.
- Define/lead cybersecurity vendor & managed service operating model; set SLAs/metrics; manage third-party performance.
- Deliver executive strategy/risk/roadmap updates; influence enterprise decisions; enable business growth with risk discipline.
- Lead and develop cybersecurity team and security-focused resources; build practical, business-aligned security culture.
Candidate Requirements
- Bachelorβs degree in Information Security, Computer Science, Engineering, Information Technology, or related field.
- 12+ years progressive cybersecurity experience with increasing leadership responsibilities.
- Leadership across cybersecurity architecture, engineering, and operational security; building/maturing enterprise cybersecurity programs.
- Experience leading cybersecurity initiatives in regulated environments.
- Strong knowledge of NIST CSF, cybersecurity governance, risk management, and security control implementation.
- Experience with audits/compliance, risk assessments, and remediation.
- Experience with data protection, access governance, third-party risk, and controls for cloud/SaaS/endpoint/enterprise applications.
- Experience managing cybersecurity vendors, MSSPs, and outsourced security services.
- Strong executive communication and stakeholder management.
- CISSP required.
Preferred Qualifications
- Experience in biotechnology/pharmaceutical/life sciences/healthcare/medical devices.
- Experience supporting GxP-regulated systems (CSV, Quality Management Systems, inspection readiness).
- Experience supporting SOX and IT General Controls.
- Familiarity with cloud security, IAM, vulnerability management, data protection, security operations, and cyber resilience.
- Experience partnering with Legal/Privacy on privacy-by-design, data classification, access control, and vendor risk.
- Experience supporting commercial-stage growth/scale/geographic expansion/regulatory complexity.
- CISM, CRISC, CCSP, GIAC, CISA, or ISO 27001 preferred.