Director of Information Security

Drury Hotels Company, LLC

$125K — $150K *
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • 10+ years of cybersecurity experience with leadership focus.
  • Expertise in security frameworks like NIST and PCI DSS.
  • Experience in identity and access management and related monitoring.
  • Strong skills in vendor risk management and assessments.
  • Proven track record in negotiating contracts and managing vendor relationships.
  • Demonstrated ability to convey complex security concepts effectively.
  • Analytical skills with a risk-based approach to investment prioritization.

Responsibilities

  • Lead and direct the cybersecurity program and team.
  • Develop and evolve the security roadmap and operating plan.
  • Monitor industry threats and cybersecurity trends.
  • Oversee daily security operations and incident response activities.
  • Manage governance, risk, compliance, and related operational controls.
  • Facilitate metrics and report on program efficiencies and effectiveness.
  • Direct security awareness training and measure its impact.

Benefits

  • On-site work environment located in St. Louis, Missouri.
  • Opportunity for professional development and team coaching.
  • Mentorship for growth in cybersecurity leadership roles.
  • Access to a collaborative team and a supportive corporate culture.
Full Job Description
This position is on-site in St. Louis, Missouri.

Candidates must be authorized to work in the United States and not require current or future employment visa sponsorship. Drury Hotels does not sponsor employment visas for this position.

Property Location:

13075 Manchester Rd - St. Louis, Missouri 63131

Summary:

Leads the company’s cybersecurity program, overseeing governance, risk, compliance, and day-to-day security operations. Responsible for information security across internal systems, cloud solution providers, vendor/third-party solutions, identity and access management, and application development.

Establishes security architecture, strategic roadmaps, and operational standards to strengthen the company’s overall security posture. Evaluates and implements technologies and processes to improve efficiency, effectiveness, and strengthen overall security posture. Oversees capabilities that enable the organization to identify, protect, detect, respond to, and recover from cyber threats and vulnerabilities.

Defines security requirements using risk assessments, threat modeling, testing, and analysis of existing systems. Ensures operational security activities (including endpoint security and patch management) are performed timely and efficiently. Oversees compliance related activities including PCI compliance and NIST alignment.

Responsibilities and Duties:

  • Provide leadership and direction for the cybersecurity program, managing a team that includes security operations and security compliance (GRC) leadership.

  • Develop, maintain, and evolve a security roadmap and annual operating plan that balances operational needs, compliance requirements, and risk reduction.

  • Stay current on industry threats, alerts, technology trends, and best practices related to cybersecurity.

  • Oversee day-to-day security operations through the Supervisor of IT Security Operations, including monitoring/SOC, endpoint security (EDR), identity, vulnerability management, and timely remediation of alerts.

  • Oversee governance, risk, and compliance through the Manager of Compliance and Security, including policy/standards management (e.g., NIST), risk assessments, audit support, and compliance obligations (e.g., PCI DSS). In a lean team environment, this role may also support operational security controls such as email security, Active Directory/Group Policy (GPOs), and network access controls (ACLs).

  • Facilitates a metrics and reporting framework to measure the efficiency and effectiveness of the program, facilitates appropriate resource allocation, and increases the maturity of the cybersecurity, and reviews it with stakeholders at the executive and board levels.

  • Directs the cybersecurity awareness training program for all team members and establishes metrics to measure the effectiveness of this security training program.

  • Establish and enforce security standards and “security by design” practices across technology platforms, application development, and vendor solutions.

  • Partner with IT operations to define, test, and oversee disaster recovery and business continuity security requirements and resilience controls.

  • Oversee third-party security partners and vendor security posture, including due diligence, contractual security requirements, and ongoing third-party risk management.

  • Hire, develop, coach, and evaluate team members; establish clear goals and metrics; and ensure appropriate training and professional development.

Basic Qualifications:

  • Strong analytical, problem-solving, and decision-making skills.

  • Ability to learn and apply new technologies and security concepts quickly.

  • Ability to communicate complex security topics to technical and non-technical stakeholders at an appropriate level of detail.

  • Strong collaboration skills; ability to work effectively with coworkers, leaders, and external partners/vendors.

  • Ability to work independently, prioritize competing demands, and lead through influence in a team environment.

  • Ability to evaluate security tools and vendors, negotiate contracts, and manage vendor relationships.

  • Demonstrated experience leading teams and influencing across IT and the business.

  • Working knowledge of incident response concepts and operational security practices (e.g., endpoint security, vulnerability management, patching).

  • Ability to apply a risk-based approach to prioritize security investments and activities.

  • Effective verbal and written communication skills.

  • Demonstrated experience and success in senior leadership roles in risk management, cybersecurity, and IT or OT security

  • Experience with contract and vendor negotiations

Required Qualifications:

  • 10+ years of experience in cybersecurity, including leadership/management experience.

  • Production/enterprise experience operating and improving security controls (e.g., EDR, vulnerability management, email security, network security).

  • Experience with security frameworks and compliance requirements (e.g., NIST, PCI DSS) and translating them into actionable controls.

  • Experience with identity and access management (IAM), privileged access, and related monitoring practices.

  • Experience with third-party/vendor risk management and security assessments.

Preferred Qualifications:

  • Experience leading large teams, including managing managers.

  • Strong knowledge of network and security fundamentals and how they apply to enterprise environments.

  • Experience with security budgeting, KPI/metrics reporting, and multi-year roadmap development.

  • Experience with Microsoft administrative controls and governance.

  • Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified Information Systems Auditor (CISA), Certified in Risk and Information Systems Control (CRISC) or other similar credentials

Rise. Shine. Work Happy. Apply Now

Similar Jobs

More Jobs at Drury Hotels Company, LLC

More Information Technology Jobs

Find similar Director of Information Security jobs: