Director, Information Security Risk Management (CISO)
Job Location:
Arlington, TX - USA
Monthly Salary:
$ 223000 - 233000
Posted:
19 July 2026 (23 days ago)
Application Deadline:
16 October 2026
Vacancies:
1 Vacancy
Job Summary
This is a hybrid role. The selected candidate will work in
Arlington VA (Tuesdays-Thursdays) on a weekly basis.
SUMMARY
The Director of Information Security Risk Management serves as the functional lead for NACDs enterprise information security program operating with the scope and accountability of a Chief Information Security Officer within the organization. Reporting to the CIO the Director owns the execution and ongoing maturation of NACDs security governance risk management compliance and operations functions including full ownership of the information security budget.
NACDs information security program is in its early stages of development. Many foundational capabilities are newly established and several critical programs have yet to be built. This is a builder role. The Director will assess the current state of the program prioritize investments and systematically stand up the people processes and technologies required to mature NACDs security posture. This requires someone equally comfortable designing programs from the ground up as they are operating and improving what already exists.
The Director identifies evaluates and reports on legal regulatory and cybersecurity risk to information assets while supporting NACDs business objectives partnering with the CIO Legal/Privacy senior leadership and business units to define acceptable risk levels and ensure systems are maintained in a secure functional and compliant state.
SUPERVISORY RESPONSIBILITIES
This position carries direct people management accountability. The Director manages a team of full-time employees and/or contractors supporting the information security risk and compliance function. Responsibilities include recruiting hiring onboarding performance management professional development and annual reviews. The Director also manages contractor relationships including scope oversight performance expectations and vendor coordination in partnership with the vendor management office.
ESSENTIAL DUTIES AND RESPONSIBILITIES
Establish Governance and Build Knowledge
- Leads the information security governance structure including formation of a steering committee or advisory board development and approval of security policies and regular reporting to senior leadership and the board of directors on program status and risk posture.
- Directs a targeted security awareness training program for all employees contractors and system users; establishes metrics to measure effectiveness and ensures consistent application of policies and standards across all technology projects and services.
- Provides risk-mitigating directives for IT-related projects embeds cyber judgment across decentralized decision-making and works with the vendor management office to ensure security requirements are reflected in contracts and third-party engagements.
Lead the Information Security Function
- Leads the information security function across NACD defining the operating model and approach in consultation with stakeholders and aligned to the organizations risk management strategy.
- Manages a team of employees and contractors with full accountability for hiring onboarding performance management professional development and contractor scope and quality oversight.
Define and Manage the Information Security Budget
- Owns the Information Security Risk Management budget end-to-end including annual planning forecasting and in-year management across staffing tools services and new program investments and develops business cases to justify security expenditures aligned to risk priorities.
- Partners with the CIO and finance leadership to ensure the budget reflects the resource requirements of a maturing program monitors variances throughout the year and recommends adjustments as program needs evolve.
Execute the Strategy
- Develops and monitors a comprehensive information security program ensuring confidentiality integrity availability privacy and recoverability of NACDs information assets; assesses program gaps and leads a prioritized phased buildout of capabilities needed to reach target maturity.
- Facilitates risk assessment and risk management processes with business units empowering them to own risk decisions within their appetite; identifies shadow IT services and establishes controls or risk mitigation with clear ownership.
Develop and Maintain Security Frameworks
- Develops and maintains a risk-based information security management framework anchored to the NIST Cybersecurity Framework including building frameworks policies standards and guidelines for programs not yet established and oversees their approval and publication.
- Creates a unified control framework integrating global laws standards and regulations; establishes a metrics and reporting framework to measure maturity and effectiveness presenting results to executive and board stakeholders.
Build the Network and Communicate the Security Vision
- Builds and sustains internal networks across legal HR compliance audit physical security and line-of-business leaders and cultivates external relationships with industry peers vendors law enforcement and advisory bodies to stay ahead of emerging threats and trends.
- Partners with the enterprise architecture team to integrate security requirements into reference architectures (security by design) and provides input into the information security section of NACDs code of conduct.
Operate the Security Function
- Leads a risk-based third-party risk management program; ensures all NACD data is processed and stored in compliance with applicable laws and regulations; collaborates with the data privacy officer to integrate privacy requirements into security operations.
- Oversees security risk and regulatory assessment processes embeds security into project delivery manages technology dependencies and vendor contracts and ensures incident response plans and disaster recovery policies are in place and executable.
- Manages and contains information security incidents to protect NACDs IT assets intellectual property regulated data and reputation; monitors the external threat environment and advises leadership on emerging risks and appropriate courses of action.
- Other duties as assigned.
EDUCATION/QUALIFICATIONS
Demonstrated experience in senior leadership roles spanning information security cybersecurity risk management and IT or OT security including direct management of employees and/or contractors ownership of a security budget and proven success building or significantly maturing an information security program from an early stage. Bachelors degree in business administration or a technology-related field required; advanced degree preferred. One or more of the following certifications strongly desired: CISSP CISM CISA or CRISC. Deep knowledge of HIPAA and applicable data privacy frameworks; working knowledge of ISO/IEC 27001 ITIL COBIT NIST 800-53 and the NIST Cybersecurity Framework. Excellent communication skills with the ability to translate complex risk concepts for technical and nontechnical audiences at all levels. Demonstrated ability to influence without authority manage multiple priorities and operate effectively in a fast-paced evolving environment.
This position description summarizes the main duties of the job. It neither prescribes nor restricts the exact tasks that may be required to carry out these duties. This document should not be construed in any way to represent a contract of employment. Management reserves the right to review and revise this document at any time.
The salary/hourly range for this position is $223000 - $233000 plus potential bonus. Compensation is based on several factors including but not limited to education work experience certifications etc.
Required Experience:
Director
About Company
Welcome to the NACD website, the most trusted resource for corporate directors. Find custom research, governance resources, and the most diligent assessment of modern governance.