- Location: Parsippany, NJ
- Type: Contract To Hire On-Site
- Job #9496
The Director, Cybersecurity reports to the Chief Information Officer with a dotted line to the Chief Compliance Officer. This role is pivotal in leading the cybersecurity program, strategy, governance, risk management, compliance, security operations, and resiliency efforts to protect critical information assets and support regulatory requirements.
Primary Responsibilities and Duties:
- Own and strengthen the overall Cybersecurity Strategy, multi-year roadmap, annual priorities, budget, and measurable program outcomes.
- Lead delivery of cybersecurity roadmap initiatives through collaboration with internal IT teams and managed service partners.
- Oversee incident response planning, investigations, forensic coordination, tabletop exercises, lessons learned reviews, and ransomware preparedness.
- Conduct cybersecurity risk assessments, maintain the cybersecurity risk register, evaluate inherent and residual risk, and coordinate risk acceptance with business and technology owners.
- Provide executive-level reporting on cybersecurity KPIs, KRIs, incidents, vulnerabilities, control effectiveness, remediation status, and emerging risks.
- Manage endpoint, network, cloud, identity and access security programs including privileged access management, MFA, Conditional Access, access reviews, service accounts, segregation of duties, and joiner-mover-leaver controls.
- Oversee SIEM, security monitoring, MDR/SOC services, logging health, threat detection, and response activities.
- Govern managed security providers and cybersecurity vendors, including MDR/SOC, penetration testing, forensic, and other security service providers.
- Lead vulnerability management, remediation tracking, validation, reporting, and process improvement activities.
- Perform security architecture and risk reviews for applications, cloud services, infrastructure changes, vendors, APIs, and strategic technology initiatives.
- Strengthen data protection through data classification, encryption, DLP, secure file transfer, email security, and protection of regulated and client information.
- Establish secure configuration standards and validate that cybersecurity controls are properly designed, implemented, and operating effectively.
- Oversee cybersecurity awareness, phishing simulations, and role-based security training programs.
- Support internal and external audits, including PCI, HIPAA, SOC1/2, and client assessments.
Qualifications:
Minimum Education and/or Experience Requirements:
- Bachelor’s degree in cybersecurity, information technology, or a related discipline, or an equivalent combination of education, professional certifications, and relevant experience; minimum 5 years of cybersecurity or information security experience, including at least five years in a leadership role.
- Strong understanding of cybersecurity frameworks, standards, and best practices including NIST.
- Experience with incident response, penetration testing, vulnerability management, SIEM/log analysis, network security, endpoint security, Active Directory, Windows/Linux security, email security, and DLP.
- Experience with Microsoft 365 security, Azure and AWS cloud security, application security, APIs, DevSecOps, vendor management, budgeting, and executive communication.
Required Knowledge, Skills and Abilities:
- Strong knowledge of cybersecurity technologies, processes, governance, risk management, and security operations.
- Working knowledge of Microsoft 365 security, security and compliance capabilities, cloud security controls, and audit logging.
- Knowledge of identity and access management, application security, SOC1/2, PCI, HIPAA, privacy regulations, and modern threat landscapes.
- Strong analytical, communication, leadership, and stakeholder management skills.
- Security certifications such as CISSP, CISM, or CISA preferred.
Estimated Compensation: $170,000 - $180,000 Per Year
Pattie Tsivouras