drjobs Sr. Director, IT Security

Sr. Director, IT Security

Employer Active

1 Vacancy
drjobs

Job Alert

You will be updated with latest job alerts via email
Valid email field required
Send jobs
Send me jobs like this
drjobs

Job Alert

You will be updated with latest job alerts via email

Valid email field required
Send jobs
Job Location drjobs

Atlanta, GA - USA

Monthly Salary drjobs

Not Disclosed

drjobs

Salary Not Disclosed

Vacancy

1 Vacancy

Job Description

Serving the needs of all families with young childrenCarters Inc. is the largest North American apparel retailer exclusively for babies and young children encompassing Carters OshKosh Bgosh Skip*Hop and Little Planet brands. Meaningful work constant learning genuine people and a community guided by core values that promote inclusion and innovation is in everything we do. There are many reasons to build your career at Carters.

HOW YOULL MAKE AN IMPACT
This role
is responsible for establishing maintaining and overseeing the enterprise-wide vision strategy architecture policies and programs to ensure information assets are protected while maintaining an understanding and managing the risks and challenges facing the company and the retail industry. This role will ensure information technology (IT) systems networks and internal and external computing environments are secure and security and business continuity risk/reward decisions are balanced and comply with regulatory and legislative requirements.He/She will create an information privacy and security-conscious culture across the position will develop and implement information security initiatives; security frameworks; conduct and oversee security operations for the ongoing protection of the Carters global environment; monitor and audit compliance with regulatory and internal standards; and lead investigations related to policy violations security breaches and computer crimes.

Directs and manages the activities and personnel of the Information Security Services Team including focus on the following capabilities:

IT Policies Risk & Compliance 25%

  • Oversees the development implementation and maintenance of global security policy enterprise security standards guidelines and procedures for appropriate risk mitigation and to support regulatory or industry compliance (e.g. SOX PCI HIIPA)

  • Serves as an expert advisor to executive leadership Board or Directors and Audit Committee in the development implementation and maintenance of a strong information privacy and security program and infrastructureincluding network access and monitoring policies

  • Develops policies and procedures to ensure physical safety of employees and visitors; Creates workplace violence awareness and prevention programs as in partnership with Facilities Management or corporate/enterprise Risk Management teams

  • Collaborates with Legal Counsel Internal Audit on compliance security and privacy practices processes procedures and protocols; Monitors and reports statuses and actively participates in audits or reviews as

  • Maintains relationships with local state and federal law enforcement and other related government agencies in support of security program and roadmap with partnership and direction from Legal Counsel

  • Must be able to interact effectively with applications teams peers and management staff to create application security processes and protocols

  • Must be able to develop manage and maintain the proposed capital and operating budget for IT Security Risk and Compliance department. Will conduct ongoing budget control through budget review and approval processes and monitor departmental performance

  • Be engaged with and understanding of business environment projects considerations and constraints in implementing all policies and associated technologies

Security Operations Management 35%

  • Be responsible for 24/7 security monitoring and threat detection/prevention for the organization

  • Develop and report on security operations dashboards metrics and KPIs relevant to understanding improving Carters security capabilities and defense levels

  • Foster and manage relationship with 3rd party MSSP/SOC provider to establish a true partnership with Carters organization

Security Engineering 40%

  • Accountable to develop implement integrate and maintain the security strategy and roadmap including security tools and technologies.

  • Provide leadership and management oversight for security tool deployment and implementation including applicable hardware software firewalls intrusion detection systems security event management systems anti-virus and malware solutions cryptography systems access control systems or any other device or solution for enterprise cyber and systems protection and monitoring.

  • Develops emergency procedures and incident response protocols; acts as the control point during significant privacy and security incidents

  • Understands potential threats vulnerabilities and control techniques. Monitors network of vendors and employees to ensure the safeguarding of information assets

  • Investigates security breaches communicates to appropriate executive management and local information privacy and security leadership and pursues associated legal protocols in relation to any security investigation incident or security breach

  • Conducts periodic penetration testing and security audits; establishes risk assessment criteria and methodology

  • Builds and sustains strong relationships with Carters functional and technical teams and serves as a trusted advisor on security related matters for the organization

  • Serves on the chair of the Information Governance and Privacy Committee; serves on the Compliance Committee and Risk Management Committee representing Information Systems as directed by their supervisor

Supervisory/ Budgetary/ External Communication Responsibility

  • Manages a multi-functional team of 7 10 to include security engineering security operations and IT risk and compliance

  • Manages a Managed Security Services Provider (or co-managed security provider) to augment teams ability to monitor and manage IT security events and manage security operations

  • Manages a significant operational and capital budget for the security

  • Required to communicate accordingly to Board Members Audit Committee Members on general security updates. Required to brief internal and external groups (auditors law enforcement etc.) in the event of security incidents or breach.

Secondary Functions

  • Understands and supports the Companys goals and objectives and makes certain that his/her actions and decisions are consistent with them.

  • Keeps his/her supervisor informed of all matters of importance and particularly those instances where deviations from planned results are likely to occur.

  • Performs other responsibilities and duties as assigned by his/her supervisor.

Wed Love to hear from you if: (Requirements section)

Must have:

  • Proven experience in planning security strategy and IT security projects for a multi-billion organization

  • Must have strong knowledge of industry best practices laws frameworks and compliance standards related to data privacy and protection

  • Requires success experience in at least three of the following domains: application security; security technologies and products; security engineering; security analysis and investigations; risk assessment and management; disaster recovery; IT SOX auditing

  • In-depth knowledge of platform operating systems including Windows Linux and Unix

  • Experience with Wide Area Network/Local Area Network/Wireless Network TCP/IP and related protocols

  • Strong knowledge of Intrusion Detections and Prevention techniques

  • Deep knowledge and understanding of SOX PCI and other compliance standards

  • Proven experience leading committees or sub-committees related to security compliance privacy or risk in the organization

  • Understands DR planning and execution and is able to influence IT infrastructure IT application and business owners on DR planning and practices.

  • Must have very strong written and verbal skills and executive presence to interact effectively with all levels of leadership board members IT staff vendors auditors third-party business application providers and other parties impacting the companys security state

  • Experience with Managed Service providers in relation to providing security services including establishing protocol measuring provider metrics understanding contractual agreements and general day-to-day monitoring and operational expectations

  • Ability to effectively prioritize and execute tasks in a high-pressure environment

Preferred skills and experience:

  • Prior successful experience as the Information Security leader in a multi-billion organization highly desirable

  • Bachelor Degree and 10 years IT experience with at least 5 of those years of leadership in area of information security preferably in the retail industry

  • At least 3 years of direct hands-on experience or direct management of firewall administration intrusion detection systems data encryption software security information and event management systems and working knowledge of switches and routers

  • A Certified Information System Security Professional (CISSP) or equivalent certification from a recognized professional organization such as International Informational Systems Security Certification Consortium ISC)2 Global Assurance Certification (GIAC) or Information Systems Audit and Control Association (ISACA)

  • Prior work experience with MSSP vendor relationship

OUR Team Members:

Carters is committed to creating a diverse environment and is proud to be an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race color religion gender gender identity sexual orientation national origin genetics disability age veteran status or any other status protected by federal state or local law.


Required Experience:

Director

Employment Type

Full-Time

Report This Job
Disclaimer: Drjobpro.com is only a platform that connects job seekers and employers. Applicants are advised to conduct their own independent research into the credentials of the prospective employer.We always make certain that our clients do not endorse any request for money payments, thus we advise against sharing any personal or bank-related information with any third party. If you suspect fraud or malpractice, please contact us via contact us page.