Director of Security and Compliance at Swinerton | Arvada, CO, US | Rezi

Director of Security and Compliance at Swinerton

Director of Security and Compliance

Swinerton · Arvada, CO, US

Yesterday

Director of Security and Compliance

Swinerton · Arvada, CO, US

a day ago
Resume preview

Impress employers and recruiters.
Choose from hundreds of resume examples.

Target Resume Now

About the Role

The Director of Security and Compliance leads the design and oversight of cybersecurity, compliance, and privacy programs that safeguard the organization’s digital assets and data while ensuring adherence to regulatory requirements, contractual obligations, and internal policies.

Responsibilities

  • Sets the mission, vision, and strategy for technology risk management including cybersecurity, compliance and privacy organization.
  • Implements appropriate risk management and mitigation efforts while ensuring the success of business and IT initiatives.
  • Ensures alignment with business objectives and product priorities.
  • Demonstrates exceptional communication and presentation skills, effectively conveying complex technical and compliance concepts to critical stakeholders, including senior managers and the executive leadership team.
  • Builds successful stakeholder relationships with other IT, enterprise risk managers and key business stakeholders.
  • Develops a clear understanding of business needs, acts as a trusted advisor, and ensures cost-effective delivery of security services.
  • Directs enterprise-wide security architecture and operations across IT and OT environments.
  • Ensures secure design, deployment, and ongoing protection of infrastructure, applications, and data systems.
  • Ensures compliance with all relevant cybersecurity, compliance and privacy regulations.
  • Conducts compliance assessments and provides regular status reports to risk management teams and senior business leaders.
  • Leads cross-functional Privacy Team to develop and implement a comprehensive enterprise-wide data and personnel privacy program.
  • Maintains current policies, facilitates publication and communication, and ensures all employees receive required privacy training.
  • Develops and controls the annual department budget to ensure it's consistent with overall strategic objectives.
  • Fosters an enterprise security culture by embedding compliance and risk management practices into daily business operations.
  • Leads organization-wide training and awareness initiatives.
  • Conducts comprehensive enterprise risk assessments and develops strategies that strengthen business continuity, disaster recovery, and incident response capabilities.
  • Builds, trains, and coordinates cross-functional incident response teams.
  • Ensures digital and paper archiving systems are complying with corporate data retention policies.
  • Collaborates with Product Managers to ensure they understand policies and their products and services are aligned.
  • Builds and leads a high performing team.
  • Works collaboratively with direct reports to support their career progression, nurture their development and help them realize their potential.
  • Has a documented succession plan for critical functions.
  • Develops and actively participates in peer network groups.
  • Stays up on trends and shares lessons learned.
  • Leads vendor management and negotiations with security service providers.
  • Establishes strong vendor relationships ensuring vendors understand and share our focus on security and are capable of meeting requirements.

Requirements

  • Bachelor’s or Master’s degree in business administration or technology related field
  • 15 or more years of experience in IT Operations, cybersecurity or business/industry
  • 7 or more years of leadership responsibilities, including strategy, budgeting, and staffing
  • 3 or more years of leadership responsibilities of an auditable compliance program (ex: NIST 800-171, CMMC, ISO 2700x, SOC 2, NERC-CIP, etc.)
  • Exceptional leadership skills, with the ability to develop and communicate a vision that inspires and motivates staff and aligns with the IT and business strategy
  • Effective influencing and negotiation skills and the ability to build consensus in complex environments where resources required for success may not be in direct control of this role
  • Demonstrates collaboration skills across multiple teams including business operating groups, corporate departments and other IT teams
  • Excellent analytical, strategic conceptual thinking, strategic planning, and execution skills
  • Strong business acumen, including industry, domain-specific knowledge of the enterprise and its business units
  • Developing staff including coaching, mentoring and performance management
  • Deep understanding of current and emerging security technologies and practices, and how other enterprises are employing them
  • Strong awareness of current and changing regulatory landscape
  • Maintain awareness of emerging threats and incorporate appropriate mitigation measures
  • Demonstrated ability to develop and execute a strategic staffing plan that ensures the right people are in the right roles at the right time, and employees are highly engaged and satisfied
  • Third-party management, working closely with sourcing and vendor managers

Skills

  • Cybersecurity
  • Compliance
  • Privacy
  • Risk Management
  • Communication
  • Presentation Skills
  • Stakeholder Management
  • Relationship Management
  • Security Architecture
  • Security Operations
  • Regulatory Compliance
  • Reporting
  • Data Management
  • Personnel Privacy
  • Budget Management
  • Financial Management
  • Security Culture
  • Awareness Training
  • Business Continuity
  • Disaster Recovery
  • Incident Response
  • Data Retention
  • Archiving
  • Team Leadership
  • Staff Development
  • Vendor Management
  • Third-Party Management
  • NIST 800-CSF
  • NIST 800-53
  • Cloud Architecture
  • Network Architecture
  • Identity and Access Management
  • Business Continuity
  • Disaster Discovery
  • Data Management
  • Data Classification
  • Privacy
  • Artificial Intelligence
  • Microsoft
  • AWS
  • Google
  • Cisco

Experience Level

  • 15 or more years of experience in IT Operations, cybersecurity or business/industry
  • 7 or more years of leadership responsibilities
  • 3 or more years of leadership responsibilities of an auditable compliance program

Education Level

  • Bachelor’s or Master’s degree in business administration or technology related field

Salary/Compensations

  • $200,000.00 - $225,000.00 Annual Salary

Benefits

  • Medical
  • Dental
  • Vision
  • 401(k) with company matching
  • Employee Stock Ownership Program (ESOP)
  • Individual stock ownership
  • Paid vacation
  • Paid sick leave
  • Paid holidays
  • Bereavement leave
  • Employee assistance program
  • Pre-tax flexible spending accounts
  • Basic term life insurance and AD&D
  • Business travel accident insurance
  • Short and long term disability
  • Financial wellness coaching
  • Educational assistance
  • Care.com membership
  • ClassPass fitness membership
  • DashPass delivery membership
  • Additional term life insurance
  • Long term care insurance
  • Critical illness and accidental injury insurance
  • Pet insurance
  • Legal plan
  • Identity theft protection
  • Other voluntary benefit options