Director, Data & Applications Security
Job Description
Lead enterprise data protection and secure application initiatives with a focus on governance, risk, and compliant operating models.
Responsibilities
- Partner regularly with the CISO and align with Data Services and Infrastructure leadership to support strategic alignment, business satisfaction, and continuous improvement in cybersecurity services
- Create and implement enterprise-wide data classification, taxonomy, and governance policies to standardize data protection and compliance
- Own the enterprise data loss prevention strategy: develop, manage, monitor, and deploy DLP tools and capabilities
- Identify, measure, and reduce security risks across application, database, network, host, artificial intelligence, and cloud environments with an emphasis on data and application security
- Evaluate current data security effectiveness, determine gaps, and produce a security strategy with an execution roadmap
- Collaborate with IT and OT leaders to manage vulnerabilities in systems that support data and application functions
- Manage security vendor relationships and evaluate effectiveness of products and services for data and application protection
- Support internal and external cybersecurity audits covering systems and service providers to ensure regulatory and policy compliance
- Set direction and manage support for software and hardware asset management standards, capabilities, and reporting
- Drive employee experience through leadership, employee development, and coaching
Requirements
- Bachelor’s degree from an accredited four-year college or university plus 10+ years of relevant experience in Data & Applications Security (or equivalent education and experience)
- 5+ years demonstrated experience in team management and development
- CISSP, CISM, or equivalent certification is required
- Experience in multinational organizations with complex, integrated IT and OT environments
- Proven knowledge of data classification strategies and high-risk data handling, including data masking, tokenization, encryption, and cryptographic controls
- Knowledge and experience implementing, managing, and assessing AI risk and AI governance frameworks
- Deep understanding of Secure Software Development Lifecycle (SSDLC), code review methodologies, and static and dynamic code analysis
- Strong background in risk management and in developing and implementing cybersecurity strategy and supporting technologies/tools
- Working knowledge of SABSA and TOGAF, plus NIST and ISO 27000, with familiarity with OWASP Top 10, SANS 25, MITRE ATT&CK, and CWEs
- Excellent written and verbal communication skills, with the ability to engage and negotiate across all organizational levels
- Respects others, thrives in fast-paced environments, and builds strong team-oriented relationships
Technologies
- Cloud Access Security Broker (CASB)
- Secure Software Development Lifecycle (SSDLC)
- CISSP, CISM
- SABSA, TOGAF
- NIST, ISO 27000
- OWASP Top 10, SANS 25
- MITRE ATT&CK
- CWEs
Location & Compensation
- Location: Smithfield, VA (onsite)
- Salary: USD 160,000 - 202,500 per year
Benefits
- Relocation package available
Preferred
- MS IT or MBA preferred
Similar Jobs
A
T