About the Role
The Cybersecurity Director will provide strategic leadership for Business Wire's cybersecurity function, overseeing security architecture, infrastructure, risk decisions, and a comprehensive Governance, Risk, and Compliance (GRC) program. This role ensures a robust information security program for existing and new client solutions, managing cloud security, application security, identity and access, Zero Trust, vulnerability management, data protection, privacy, and emerging technology risks like AI. It also involves establishing a security governance framework, ensuring compliance, fostering a security-first culture, and integrating risk management into business operations.
Responsibilities
- Develop and maintain cybersecurity and GRC strategy and long-term roadmap.
- Make continuous improvements to security strategies to protect critical assets and data.
- Provide strategic decision-making and problem-solving for complex security and regulatory landscapes.
- Manage a comprehensive GRC program supporting corporate audits, client assessments, and regulatory standards (PCI DSS, SOC 2, ISO 27001).
- Conduct regular risk assessments, penetration testing, and vulnerability assessments.
- Manage the creation and dissemination of security-related communications.
- Oversee the relationship with the external cyber defense partner.
- Provide strategic leadership during cybersecurity incidents.
- Offer senior-level guidance in developing cybersecurity governance programs, policies, standards, and secure architecture guidelines.
- Oversee enterprise cybersecurity risk assessments and direct privacy and data protection initiatives.
- Provide leadership, guidance, and mentorship to cybersecurity and GRC team members.
- Act as a trusted advisor to senior leadership on cybersecurity risk, architecture decisions, and strategic measures.
- Use metrics to evaluate and track the effectiveness of security, governance, and compliance initiatives.
- Translate technical requirements into actionable business solutions.
Requirements
- Ability to work in the San Francisco office an average of twice a week.
- Bachelor's or Master's degree in Computer Science, Information Security, or a related field.
- 10+ years of relevant industry experience in Information Security.
- 5+ years of managerial and strategic leadership experience.
- Knowledge of data protection, privacy regulations, and cybersecurity governance frameworks.
- Expertise in cloud security (AWS and Azure), cybersecurity architecture, application security, identity management, and Zero Trust.
- Experience in data encryption, access controls, code reviews, and secure coding practices.
- Expertise in building and implementing GRC frameworks and risk management processes.
- Familiarity with regulatory compliance requirements (PCI DSS, SOC 2, ISO 27001).
- Certified Information Systems Security Professional (CISSP) or equivalent certification is a plus.
- Strong leadership and team-building skills.
- Excellent written and verbal communication skills with external and internal stakeholders and executives.
- Ability to simplify complex cybersecurity topics.
- Ability to deliver constructive & encouraging feedback.
- Proactive, organized, analytical, detail-oriented, and persistent.
- Experience managing and overseeing external security service providers or technology partners.
- Business Wire will not sponsor a new applicant for employment authorization for this position.
Skills
- Cloud security
- AWS
- Azure
- Cybersecurity architecture
- Application security
- Identity management
- Zero Trust
- Data encryption
- Access controls
- Code reviews
- Secure coding practices
- GRC frameworks
- Risk management processes
- PCI DSS
- SOC 2
- ISO 27001
- Leadership
- Team-building
- Written communication
- Verbal communication
- Risk assessment
- Penetration testing
- Vulnerability assessment
- Data protection
- Privacy regulations
- AI risk management
Location
- San Francisco
Work Type
- Remote
- Onsite
Experience Level
- 10+ years of relevant industry experience in Information Security
- 5+ years of managerial and strategic leadership experience
Education Level
- Bachelor's or Master's degree in Computer Science, Information Security, or a related field
Salary/Compensations
- $230K to $245K/year
Benefits
- Ability to work remotely
- Excellent health benefits that begin on your first day of employment
- $100 monthly fitness allotment
- Tuition reimbursement program
- Enhanced mental health resources
- 401(k) plan with generous company match
- Annual profit sharing contribution (subject to company performance)
- PTO
- Floating Holidays
- Wellness Day Off
- Birthday Day Off
About the Company
- Business Wire, a Berkshire Hathaway company, is the global market leader in press release distribution and regulatory disclosure.
- Organizations, large and small, depend on us to accurately publicize market-moving news and multimedia, and generate social engagements that develop interactions with their target audiences.
Equal Opportunity
- Business Wire is proud to be an equal opportunity workplace.
- We are committed to equal employment opportunity regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender identity or Veteran status.
- Pursuant to the San Francisco Fair Chance Ordinance and other similar state laws and local ordinances, and its internal policy, Business Wire will also consider for employment qualified applicants with arrest and conviction records.
