Global Information Security Strategist Associate Director at EY | Alpharetta, GA, US | Rezi

Global Information Security Strategist Associate Director at EY

Global Information Security Strategist Associate Director

EY · Alpharetta, GA, US

1 weeks ago

Global Information Security Strategist Associate Director

EY · Alpharetta, GA, US

10 days ago
Resume preview

Impress employers and recruiters.
Choose from hundreds of resume examples.

Target Resume Now

About the Role

The Global Information Security Strategist is a senior role responsible for shaping and implementing the long-term information security strategy of the firm. This individual will work closely with the Global Lead for Information Security Strategy and Research to ensure that security initiatives not only protect the firm’s assets and reputation but also enable business objectives. The strategist will combine deep knowledge of emerging technologies and threats with strong business acumen to drive security programs that align with the company’s global strategy and operational needs. This role involves high-level collaboration, strategic planning, and leadership to keep the Information Security program a step ahead of evolving business demands and cyber risks.

Responsibilities

  • Define and drive the development of long-term information security program strategies that support the firm’s business objectives.
  • Ensure security goals, processes, and resources are aligned with overall corporate strategy and priorities, with clear targets for success.
  • Collaborate with senior business and technology leaders to understand short- and long-range business plans.
  • Recommend security strategies and solutions that anticipate future changes in services, technologies, and client requirements.
  • Work across global business and technology teams to build awareness on security initiatives.
  • Rationalize and present recommendations to stakeholders and champion the security strategy across the organization.
  • Drive organization-wide adoption of strategic security initiatives, resulting in consistent risk reduction and improved security posture.
  • Analyze the Information Security program’s operational effectiveness, processes, and stakeholder feedback.
  • Identify areas for improvement and optimize processes to increase program effectiveness and agility.
  • Monitor and evaluate emerging security technologies, industry trends, and evolving threat landscapes.
  • Determine how these developments could impact the firm and its security posture.
  • Use these insights to proactively adapt and evolve the security strategy.
  • Identify strategic opportunities for innovation within the security program.
  • Plan and propose research initiatives or pilot projects to explore new security solutions, architectures, or processes.
  • Develop business cases for new investments or approaches.
  • Partner with teams in Information Security, Enterprise Technology, and Client Technology to address security and business needs from the outset of new capability conception and adoption.
  • Support and guide senior executive decision-making.
  • Prepare and present high-level analyses, strategic plans, and roadmaps to executive leadership.
  • Provide clear recommendations for the adoption of new capabilities or approaches, backing them with data-driven insights and projections.
  • Serve as a subject matter expert in information security.
  • Maintain a deep understanding of the firm’s technology portfolio, security architecture, and business operations.
  • Educate business units on the Information Security program’s strategic direction.
  • Build and maintain strong relationships with both internal and external partners to stay informed about potential strategic shifts.
  • Leverage these relationships to inform the firm’s security strategy and ensure preparedness for industry changes.

Requirements

  • Minimum 10+ years of experience in roles involving strategy development, organizational change, or business process improvement, with a strong track record of driving business impact.
  • At least 10 years of experience in Information Security or Information Technology domains, demonstrating increasing responsibility and breadth of scope.
  • Exceptional program leadership and stakeholder management skills.
  • Proven ability to lead cross-functional initiatives in a global organization, aligning diverse teams through influence and relationship-building.
  • Strong business acumen with the ability to understand the company’s business model and industry.
  • Capable of translating business needs into security program requirements and articulating the value of security initiatives in business terms.
  • Excellent communication and presentation skills.
  • Able to effectively convey complex concepts and strategies to both technical teams and non-technical executive audiences.
  • Advanced English writing skills are required for clear documentation and strategic plan writing.
  • Broad and deep knowledge of information security domains and technologies – including cybersecurity architecture, risk management, identity and access management (IAM), incident response, and emerging threat mitigation techniques.
  • Able to dive into technical details and also abstract them into high-level insights for decision-makers.
  • Demonstrated track record of delivering results in complex, matrixed environments.
  • Able to manage multiple high-priority initiatives simultaneously, meet deadlines, and drive projects to completion.
  • Experience in driving adoption of new processes or capabilities across an organization is essential.

Skills

  • Information Security Strategy
  • Cybersecurity Architecture
  • Risk Management
  • Identity and Access Management (IAM)
  • Incident Response
  • Emerging Threat Mitigation
  • Strategic Planning
  • Stakeholder Management
  • Business Acumen
  • Communication
  • Presentation
  • Technical Depth
  • Results Orientation
  • Organizational Change
  • Business Process Improvement
  • Global/Enterprise Experience
  • Industry Knowledge (Professional Services)
  • Information Security Frameworks (ISO 27001/27002, NIST CSF, CSA, CIS Controls)
  • Product Security Lifecycle
  • Secure Development Lifecycle (SDLC)

Location

  • US

Work Type

  • Hybrid

Experience Level

  • Senior
  • 10+ years

Education Level

  • Bachelor's degree
  • Master's degree

Salary/Compensations

  • $152,700 to $294,000 (US)
  • $183,300 to $334,100 (New York City Metro Area, Washington State and California excluding Sacramento)

Benefits

  • Medical coverage
  • Dental coverage
  • Pension plans
  • 401(k) plans
  • Flexible vacation policy
  • Paid time off
  • Designated EY Paid Holidays
  • Winter/Summer breaks
  • Personal/Family Care leave
  • Other leaves of absence

About the Company

  • EY is building a better working world by creating new value for clients, people, society and the planet, while building trust in capital markets.
  • Enabled by data, AI and advanced technology, EY teams help clients shape the future with confidence and develop answers for the most pressing issues of today and tomorrow.
  • EY teams work across a full spectrum of services in assurance, consulting, tax, strategy and transactions.
  • Fueled by sector insights, a globally connected, multi-disciplinary network and diverse ecosystem partners, EY teams can provide services in more than 150 countries and territories.

Equal Opportunity

  • EY provides equal employment opportunities to applicants and employees without regard to race, color, religion, age, sex, sexual orientation, gender identity/expression, pregnancy, genetic information, national origin, protected veteran status, disability status, or any other legally protected basis, including arrest and conviction records, in accordance with applicable law.
  • EY is committed to providing reasonable accommodation to qualified individuals with disabilities including veterans with disabilities.