Director, Information Security Risk Management (CISO)

NACD

Arlington, Texas

JOB DETAILS
SKILLS
Budgeting, Business Administration, Business Case, CISA - Certified Information Systems Auditor, CISM - Certified Information Security Manager, CISSP - Certified Information Systems Security Professional, Communication Skills, Computer Security, Control Objectives for Information and related Technology (COBIT), Disaster Recovery, Enterprise Architecture, Enterprise Protection, Establish Priorities, Finance, Forecasting, ISO (International Organization for Standardization), ITIL (IT Infrastructure Library), Incident Response, Information Assets, Information Technology & Information Systems, Information/Data Security (InfoSec), Intellectual Property (IP), International Electro-Technical Commission (IEC), Internet Security, Law Enforcement, Leadership, Legal, Legal Reports, Management Strategy, Metrics, Multitasking, Onboarding, People Management, Performance Analysis, Performance Management, Physical Security, Policy Development, Privacy Controls, Program Evaluation, Project/Program Management, Public/Media/Press/Analyst Relations, Publications, Regulations, Regulatory Compliance, Relationship Management, Risk, Risk Analysis, Risk Management, Security Analysis, Security Architecture, Security Auditing, Security Design, Security Monitoring, Team Lead/Manager, Technical Leadership, Technical Support, Training Program, Trend Analysis, U.S. National Institute of Standards and Technology (NIST), Vendor/Supplier Management
LOCATION
Arlington, Texas
POSTED
4 days ago
This is a "hybrid" role.  The selected candidate will work in
Arlington, VA (Tuesdays-Thursdays) on a weekly basis.
 
SUMMARY
The Director of Information Security Risk Management serves as the functional lead for NACD's enterprise information security program, operating with the scope and accountability of a Chief Information Security Officer within the organization. Reporting to the CIO, the Director owns the execution and ongoing maturation of NACD's security governance, risk management, compliance, and operations functions — including full ownership of the information security budget.
NACD's information security program is in its early stages of development. Many foundational capabilities are newly established, and several critical programs have yet to be built. This is a builder role. The Director will assess the current state of the program, prioritize investments, and systematically stand up the people, processes, and technologies required to mature NACD's security posture. This requires someone equally comfortable designing programs from the ground up as they are operating and improving what already exists.
 
The Director identifies, evaluates, and reports on legal, regulatory, and cybersecurity risk to information assets while supporting NACD's business objectives — partnering with the CIO, Legal/Privacy, senior leadership, and business units to define acceptable risk levels and ensure systems are maintained in a secure, functional, and compliant state.
 
SUPERVISORY RESPONSIBILITIES
This position carries direct people management accountability. The Director manages a team of full-time employees and/or contractors supporting the information security risk and compliance function. Responsibilities include recruiting, hiring, onboarding, performance management, professional development, and annual reviews. The Director also manages contractor relationships — including scope oversight, performance expectations, and vendor coordination — in partnership with the vendor management office.
 
ESSENTIAL DUTIES AND RESPONSIBILITIES
Establish Governance and Build Knowledge
  • Leads the information security governance structure, including formation of a steering committee or advisory board, development and approval of security policies, and regular reporting to senior leadership and the board of directors on program status and risk posture.
  • Directs a targeted security awareness training program for all employees, contractors, and system users; establishes metrics to measure effectiveness and ensures consistent application of policies and standards across all technology projects and services.
  • Provides risk-mitigating directives for IT-related projects, embeds cyber judgment across decentralized decision-making, and works with the vendor management office to ensure security requirements are reflected in contracts and third-party engagements.
Lead the Information Security Function
  • Leads the information security function across NACD, defining the operating model and approach in consultation with stakeholders and aligned to the organization's risk management strategy.
  • Manages a team of employees and contractors, with full accountability for hiring, onboarding, performance management, professional development, and contractor scope and quality oversight.
Define and Manage the Information Security Budget
  • Owns the Information Security Risk Management budget end-to-end — including annual planning, forecasting, and in-year management across staffing, tools, services, and new program investments — and develops business cases to justify security expenditures aligned to risk priorities.
  • Partners with the CIO and finance leadership to ensure the budget reflects the resource requirements of a maturing program, monitors variances throughout the year, and recommends adjustments as program needs evolve.
Execute the Strategy
  • Develops and monitors a comprehensive information security program ensuring confidentiality, integrity, availability, privacy, and recoverability of NACD's information assets; assesses program gaps and leads a prioritized, phased buildout of capabilities needed to reach target maturity.
  • Facilitates risk assessment and risk management processes with business units, empowering them to own risk decisions within their appetite; identifies shadow IT services and establishes controls or risk mitigation with clear ownership.
Develop and Maintain Security Frameworks
  • Develops and maintains a risk-based information security management framework anchored to the NIST Cybersecurity Framework — including building frameworks, policies, standards, and guidelines for programs not yet established — and oversees their approval and publication.
  • Creates a unified control framework integrating global laws, standards, and regulations; establishes a metrics and reporting framework to measure maturity and effectiveness, presenting results to executive and board stakeholders.
Build the Network and Communicate the Security Vision
  • Builds and sustains internal networks across legal, HR, compliance, audit, physical security, and line-of-business leaders, and cultivates external relationships with industry peers, vendors, law enforcement, and advisory bodies to stay ahead of emerging threats and trends.
  • Partners with the enterprise architecture team to integrate security requirements into reference architectures (security by design), and provides input into the information security section of NACD's code of conduct.
Operate the Security Function
  • Leads a risk-based third-party risk management program; ensures all NACD data is processed and stored in compliance with applicable laws and regulations; collaborates with the data privacy officer to integrate privacy requirements into security operations.
  • Oversees security risk and regulatory assessment processes, embeds security into project delivery, manages technology dependencies and vendor contracts, and ensures incident response plans and disaster recovery policies are in place and executable.
  • Manages and contains information security incidents to protect NACD's IT assets, intellectual property, regulated data, and reputation; monitors the external threat environment and advises leadership on emerging risks and appropriate courses of action.
  • Other duties as assigned.
EDUCATION/QUALIFICATIONS
Demonstrated experience in senior leadership roles spanning information security, cybersecurity risk management, and IT or OT security — including direct management of employees and/or contractors, ownership of a security budget, and proven success building or significantly maturing an information security program from an early stage. Bachelor's degree in business administration or a technology-related field required; advanced degree preferred. One or more of the following certifications strongly desired: CISSP, CISM, CISA, or CRISC. Deep knowledge of HIPAA and applicable data privacy frameworks; working knowledge of ISO/IEC 27001, ITIL, COBIT, NIST 800-53, and the NIST Cybersecurity Framework. Excellent communication skills with the ability to translate complex risk concepts for technical and nontechnical audiences at all levels. Demonstrated ability to influence without authority, manage multiple priorities, and operate effectively in a fast-paced, evolving environment.
 
This position description summarizes the main duties of the job. It neither prescribes nor restricts the exact tasks that may be required to carry out these duties. This document should not be construed in any way to represent a contract of employment. Management reserves the right to review and revise this document at any time.
 
The salary/hourly range for this position is $223,000 - $233,000 plus potential bonus. Compensation is based on several factors including but not limited to education, work experience, certifications, etc.

 

About the Company

N

NACD