Epicareer Might not Working Properly
Learn More

Head of Security

Salary undisclosed

Apply on


Original
Simplified

Job Title: Director, Information Security

Reporting to: Senior Director, Information Services

Location; Frisco, TX

On-site

Salary: $160,000-$180,000

Stelvio are seeking a highly skilled and experienced individual to lead both physical and information security efforts as the Director of Information Security. In this role, you will oversee the protection of the organization’s personnel, physical assets, systems, and data from both physical and cyber threats.

The ideal candidate will possess a strong technical background in cybersecurity management, physical security, and risk management. You will be responsible for developing and implementing comprehensive security strategies to ensure the safety of our organization's assets and information.

Qualifications:

  • Bachelor’s or master’s degree in computer science, Information Security, Security Management, or a related field. Advanced degree preferred.
  • 8+ years of experience in security leadership, with a blend of physical security and information security management.
  • Strong technical background in cybersecurity, including knowledge of security technologies, tools, and methodologies.
  • Proven experience developing and implementing comprehensive security strategies for both physical assets and information systems.
  • Strong leadership, communication, and interpersonal skills, with the ability to collaborate effectively across all levels of the organization.
  • Deep knowledge of security regulations, standards, and frameworks (e.g., GDPR, HIPAA, PCI DSS, ISO 27001, and NIST).
  • Experience in incident response and recovery for both physical security breaches and cyber threats.
  • Relevant certifications such as CISSP, CISM, CISA, GIAC, or PSP are highly desirable.
  • Strong analytical and problem-solving skills, with the ability to prioritize security initiatives based on business impact.

Key Responsibilities:

Strategic Security Leadership:

Develop and implement an overarching security strategy, integrating both physical and information security to protect organizational assets from internal and external threats.

Align security initiatives with business goals and objectives, providing a clear vision for the future security posture of the organization.

Stay current with emerging threats and trends in both physical and cybersecurity, ensuring proactive risk management and threat mitigation.

Information Security:

Lead the design, implementation, and maintenance of robust security controls, policies, and technical safeguards to protect the organization’s data and networks from cyber threats.

Conduct regular risk assessments, security audits, and penetration tests to identify vulnerabilities and implement remediation plans.

Oversee incident detection, response, and recovery efforts for cybersecurity breaches, minimizing damage and ensuring business continuity.

Ensure compliance with relevant information security regulations and frameworks, such as GDPR, HIPAA, PCI DSS, ISO 27001, and NIST Cybersecurity Framework.

Develop and deliver information security awareness and training programs to employees.

Physical Security:

Oversee the physical security of facilities, data centers, and other key assets, including the installation and management of security systems (e.g., surveillance cameras, access controls).

Implement and maintain physical security protocols to safeguard against unauthorized access, theft, and other physical threats.

Collaborate with local law enforcement and emergency services to maintain security and respond to incidents.

Risk Management:

Conduct comprehensive risk assessments to identify and prioritize security vulnerabilities across both physical and digital domains.

Develop risk mitigation strategies, including contingency plans for various security scenarios (e.g., cyberattacks, natural disasters, physical breaches).

Lead crisis management efforts, ensuring timely and effective responses to security-related incidents.

Team Leadership & Development:

  • Lead a high-performing team of security professionals, providing mentorship, guidance, and support for both physical and cybersecurity staff.
  • Foster a culture of continuous learning, innovation, and accountability within the security team.
  • Ensure the team is equipped with the necessary skills and tools to execute security initiatives effectively.

Compliance & Reporting:

  • Ensure compliance with relevant laws, regulations, and standards related to both physical and information security.
  • Serve as the primary point of contact for internal and external stakeholders, including executives, customers, partners, auditors and regulatory authorities on all security matters.
  • Regularly report to senior leadership on security risks, incidents, and mitigation efforts.

Stakeholder Engagement & Collaboration:

  • Work closely with IT, compliance, and other business units to ensure security initiatives align with overall organizational goals.
  • Establish clear communication with key stakeholders, ensuring transparency and accountability in security operations.

Financial & Resource Management:

  • Manage the budget for both physical and information security operations, ensuring the efficient allocation of resources.
  • Work with leadership to forecast security needs, both physical and digital, ensuring scalability as the organization grows

Working Conditions:

  • May require travel to various facilities or client sites as necessary.
  • Must be available to respond to security incidents 24/7.
  • Role may involve high-pressure situations, requiring quick decision-making during critical incidents.

If this role is of interest, please directly apply and I will be in touch.