Purpose of the Role: The Director of Cybersecurity executes the security program strategy defined by the VP of Digital Innovation & Cybersecurity, and owns the day-to-day health and continuous evolution of the company’s security environment — from risk identification through mitigation. This role is the operating arm of the security strategy: it maintains the risk register, owns threat modeling and security architecture, runs the security review cadence for new initiatives, leads incident response, and drives the program’s evolution as the threat environment changes and the cost to exploit decreases. The Director partners with the Senior Director of IT Operations on the operational execution of security controls (SIEM, vulnerability management, IAM, endpoint hygiene), with the Director of Solutions Delivery on secure development and AI safety, and with the Director of Digital Innovation on building security into solution design from the start. The ideal candidate brings strong security depth, current familiarity with the AI-era threat landscape, and the program leadership skills to evolve the security posture continuously rather than annually.
Functional Accountabilities
- Risk Management & Threat Modeling
- Maintain the enterprise security risk register — identification, assessment, and tracking of mitigation — across infrastructure, applications, data, manufacturing operations, and third-party dependencies.
- Own the threat modeling practice for the company, ensuring new initiatives, new platforms, and significant architecture changes go through appropriate threat assessment before release.
- Continuously evolve the threat model to account for changes in adversary capabilities, the decreasing cost to exploit, and the AI-era threat landscape.
- Security Architecture & Engineering
- Own the security architecture for the enterprise — identity and access, network segmentation, data protection, application security, and the security layer for AI and agentic systems.
- Partner with the Director of Solutions Delivery on secure development practices, with particular attention to the guardrails and circuit breakers required for agentic systems.
- Maintain security standards, reference architectures, and design patterns that the rest of the organization can use without requiring direct involvement from the security team for routine decisions.
- Incident Response & Continuous Posture
- Lead enterprise incident response — detection through resolution and post-incident review — in tight partnership with the Senior Director of IT Operations on operational execution.
- Drive the shift from an annual security posture to a continuous one: continuous control validation, continuous risk assessment, and continuous improvement of the program’s response capability.
- Maintain the incident response plan, run regular tabletop exercises, and ensure both the security team and broader leadership are practiced and ready.
- Governance, Compliance, and Third-Party Risk
- Maintain alignment with the NIST Cybersecurity Framework and ensure compliance with applicable regulatory, contractual, and customer security requirements.
- Own third-party risk management — security review of vendors, contractual security commitments, and ongoing monitoring of critical third-party dependencies.
- Maintain the security policy framework and ensure policies are practical, current, and actually followed across the organization.
- Security Operations Partnership
- Partner with the Senior Director of IT Operations and the Security Operations team on the day-to-day operational execution of security controls — SIEM, vulnerability management, IAM, endpoint, and patch cadence.
- Own the definition of operational security objectives and the review of operational performance against them, while the execution of those controls lives within IT Operations.
- Awareness, Culture, and Program Evolution
- Lead the security awareness program for the broader workforce, with particular attention to the AI-era phishing, social engineering, and data-handling risks that traditional training misses.
- Continuously evolve the security program itself — tooling, staffing, practices — to keep pace with a threat environment that no longer waits for an annual review cycle.
Leadership Accountabilities
- Function Leadership — Provides clear direction and priorities for the security team. Owns the operating cadence for the security program (risk review, threat modeling, incident response readiness, control validation).
- Cross-Functional Partnership — Maintains tight partnership with the Senior Director of IT Operations on operational execution, with the Director of Solutions Delivery on secure development and AI safety, and with the Director of Digital Innovation on security-by-design in new solutions.
- Team Development — Develops the security team, with particular attention to skills required for the AI-era threat landscape. Builds the bench in a tight talent market.
- Program Evolution — Treats the security program as a continuously evolving capability rather than a fixed standard. Drives measurable improvement in detection time, response time, and risk reduction.
- Communication & Influence — Communicates security risk clearly to non-security audiences, including BU leadership and the broader Leadership Team. Builds the credibility required for security-by-design to be the default rather than a constraint.
Core Responsibilities: General
- Lives our Values — Consistently demonstrating behaviors aligned with our Rehrig Pacific Company values and models servant leadership.
- Ensures Accountability — Drives accountability and ensures the successful execution of function key accountabilities. Proactively establishes milestones, manages dependencies, and ensures completion.
- Balances Stakeholders / Plans & Aligns — Anticipates and balances the needs of multiple stakeholders across the business. Builds and maintains healthy cross-functional relationships.
- Develops Talent — Develops people to meet both their career goals and the organization’s goals. Networks with external resources and harvests top external talent to Grow the Family. Works with team members individually as needed while promoting a healthy team environment.
- A Culture of Innovation & Belonging — Contributes to the development of our Culture of Innovation & Belonging at Rehrig Pacific, through Personnel Development (Creativity + Commitment + Courage) and Organizational Development (Diversity, Belonging, Leadership).
Qualifications:
- Bachelor’s Degree in Computer Science, Information Security, or a related field. A Master’s Degree would be a plus.
- Professional certifications such as CISSP, CISM, CISA, or comparable strongly preferred; cloud security credentials (AWS Security Specialty or equivalent) preferred.
- A minimum of 10 years of cybersecurity experience, with at least 4 years in a leadership role running a security program or major security function.
- Hands-on, current familiarity with the AI-era threat landscape, including the security implications of LLMs, agentic systems, and AI-augmented adversaries.
- Demonstrated experience evolving a security program from periodic to continuous posture, including the tooling, staffing, and practice changes that requires.
- Working understanding of the NIST Cybersecurity Framework and applicable regulatory requirements for manufacturing or distribution operations.
- Experience leading incident response, including the cross-functional coordination required during a material incident.
- Strong organizational and leadership skills, with proven success in collaborative environments and outstanding communication and interpersonal abilities.
- Ability to travel approximately 15–25% of the time.