Director of Security and Compliance

Swinerton Inc

Spokane, WA

JOB DETAILS
SALARY
$200,000–$255,000 Per Year
SKILLS
Accidental Death and Dismemberment (AD&D), Amazon Web Services (AWS), Analysis Skills, Budgeting, Business Administration, Business Operations, Business Skills, CISA - Certified Information Systems Auditor, CISM - Certified Information Security Manager, CISSP - Certified Information Systems Security Professional, Coaching, Communication Skills, Computer Security, Consensus Building Skills, Contract Requirements, Cross-Functional, Customer Relations, Disaster Recovery, Emerging Technology, Enterprise Protection, Fitness, ISO (International Organization for Standardization), Incident Response, Information Technology & Information Systems, Insurance, Internet Security, Leadership, Maintain Compliance, Management Strategy, Mentoring, Microsoft Product Family, Needs Assessment, Negotiation Skills, Operations, Performance Metrics, Privacy Controls, Privacy Regulations, Protective Services, Publications, Recruiting Strategy, Regulations, Regulatory Compliance, Regulatory Requirements, Risk, Risk Analysis, Risk Management, Security Architecture, Service Delivery, Staff Motivation, Status Reports, Strategic Planning, Succession Planning, Team Lead/Manager, Team Player, Technical Leadership, U.S. National Institute of Standards and Technology (NIST), Vendor/Supplier Management, Vendor/Supplier Relations, Vendor/Supplier Sourcing, Warehousing
LOCATION
Spokane, WA
POSTED
30+ days ago

Compensation Range:$200,000.00 - $255,000.00 Annual SalaryJob Description Summary:Architect cybersecurity, compliance and privacy programs that protect the organization's digital assets and data and ensure compliance with regulatory requirements, contractual commitments and policies.Job Description:POSITION RESPONSIBILITIES AND DUTIESSets the mission, vision, and strategy for technology risk management including cybersecurity, compliance and privacy organization.  Implementing appropriate risk management and mitigation efforts while ensuring the success of business and IT initiatives, ensuring alignment with business objectives and product priorities.Build successful stakeholder relationships with other IT , enterprise risk managers and key business stakeholders by developing a clear understanding of business needs, acting as a trusted advisor, and ensuring cost-effective delivery of security  services to meet those needs.Direct enterprise-wide security architecture and operations across IT and OT environments, ensuring secure design, deployment, and ongoing protection of infrastructure, applications, and data systems.Ensure compliance with all relevant cybersecurity, compliance and privacy regulations.  As part of a strategic enterprise risk management program, conduct compliance assessments and provide regular status reports to risk management teams and senior business leaders  including relevant metrics, key performance and risk indicators.Lead cross-functional Privacy Team to develop and implement a comprehensive enterprise-wide data and personnel privacy program. Maintain current policies, facilitate publication and communication, and ensure all employees receive required privacy training.Develop and control the annual department budget to ensure that it''s consistent with the overall strategic objectives of IT and the enterprise and is within plan.Foster an enterprise security culture by embedding compliance and risk management practices into daily business operations. Lead organization-wide training and awareness initiatives that enable informed cybersecurity decision-making across all functions and levels.Conduct comprehensive enterprise risk assessments and develop strategies that strengthen business continuity, disaster recovery, and incident response capabilities. Build, train, and coordinate cross-functional incident response teams across security, IT, business partners, and executive leadership to ensure effective crisis response and business protection.Ensure digital and paper archiving (warehouse) systems are complying with corporate data retention policies.  Collaborate with Product Managers to ensure they understand policies and their products and services are aligned.Build and lead a high performing team. Work collaboratively with direct reports to support their career progression, nurture their development and to help them realize their potential. Have a documented succession plan for critical functions.Develop and actively participate in peer network groups.  Stay up on trends and share lessons learned.Lead vendor management and negotiations with security service providers. Establish strong vendor relationships ensuring vendors understand and share our focus on security and are capable of meeting requirements.Complete other responsibilities as assigned.MINIMUM SKILLS AND EXPERIENCEBachelor's or Master's degree in business administration or technology related field15 or more years of experience in IT Operations, cybersecurity or business/industry7 or more years of leadership responsibilities, including strategy, budgeting, and staffing3 or more years of leadership responsibilities of an auditable compliance program (ex: NIST 800-171, CMMC, ISO 2700x, SOC 2, NERC-CIP, etc.)Certification Preferred - Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified Information Systems Auditor (CISA), Certified in Risk and Information Systems Control (CRISC) or other similar credentialsExceptional leadership skills, with the ability to develop and communicate a vision that inspires and motivates staff and aligns with the IT and business strategyEffective influencing and negotiation skills and the ability to build consensus in complex environments where resources required for success may not be in direct control of this roleDemonstrate collaboration skills across multiple teams including business operating groups, corporate departments and other IT teamsExcellent analytical, strategic conceptual thinking, strategic planning, and execution skillsStrong business acumen, including industry, domain-specific knowledge of the enterprise and its business unitsDeveloping staff including coaching, mentoring and performance managementDeep understanding of current and emerging security technologies and practices, and how other enterprises are employing themStrong awareness of current and changing regulatory landscapeMaintain awareness of emerging threats and incorporate appropriate mitigation measuresDemonstrated ability to develop and execute a strategic staffing plan that ensures the right people are in the right roles at the right time, and employees are highly engaged and satisfiedThird-party management, working closely with sourcing and vendor managersExperience with Specific Technology Areas and Vendors:Security servicesNIST 800-53NIST 800-171/CMMCCloud & Network architectureIdentity and access managementBusiness continuity & disaster discoveryData management, classification and privacyArtificial  IntelligenceKey vendors: Microsoft, AWS, Google, CiscoSUMMARY OF BENEFITS:This role is eligible for the following benefits:  medical, dental, vision, 401(k) with company matching, Employee Stock Ownership Program (ESOP), individual stock ownership, paid vacation, paid sick leave, paid holidays, bereavement leave, employee assistance program, pre-tax flexible spending accounts, basic term life insurance and AD&D, business travel accident insurance, short and long term disability, financial wellness coaching, educational assistance, Care.com membership, ClassPass fitness membership, and DashPass delivery membership.  Voluntary benefits include additional term life insurance, long term care insurance, critical illness and accidental injury insurance, pet insurance, legal plan, identity theft protection, and other voluntary benefit options.Anticipated Job Application Deadline:12/19/2025

About the Company

S

Swinerton Inc