Summary
The Group Director, Cyber Risk & Security Engineering will lead cyber risk, security engineering, and governance for a complex enterprise. This role partners across technology, legal, operations, retail, and global teams to strengthen security, support regulatory compliance, and build a culture of cyber resilience.
Responsibilities
- Identify, assess, and prioritize cyber risks to support remediation, acceptance, or transfer decisions.
- Lead the implementation and integration of security controls across digital and physical environments.
- Develop security awareness programs and promote secure practices across corporate, retail, and operations teams.
- Advance identity and access governance, continuous monitoring, and remediation of information security program gaps.
Requirements
- At least 10 years of cybersecurity engineering experience, including hands-on leadership in security solutions, risk assessments, and awareness programs.
- Experience securing cloud-native and hybrid environments, networks, endpoints, software development, DevSecOps, and infrastructure-as-code.
- Expertise with SIEM, EDR, PAM, firewalls, encryption, identity and access management, and data loss prevention.
- Knowledge of frameworks such as NIST 800-53, ISO 27001, and CIS; PCI DSS experience is preferred.
- Bachelor's degree in computer science, information technology, or equivalent; CISSP, CISM, or CISA certification preferred.
- Ability to work onsite three days per week at the New York, NY and Piscataway, NJ offices.