Exponent

Director of Information Security

Exponent • $150K — $180K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 7+ years in enterprise information security or related fields
  • Proven leadership in developing security strategies and governance
  • Experience managing compliance programs and enterprise risk
  • Strong background with ISO/IEC 27001 and privacy management
  • Hands-on experience in incident response and vulnerability management
  • Ability to communicate effectively with executive leadership
  • Bachelor's degree in relevant field or equivalent experience
  • CISSP certification required; other certifications valued

Responsibilities

  • Develop and implement multiyear security and privacy strategy
  • Chair governance forums and maintain compliance policies
  • Direct enterprise risk assessments and secure architecture design
  • Oversee incident response, threat detection, and vulnerability management
  • Act as Data Protection Officer and oversee privacy risk assessments
  • Manage third-party security assurances and client audits
  • Establish metrics for program effectiveness and sponsor audits

Benefits

  • Support for health and well-being programs
  • Commitment to diversity, equity, and inclusion
  • Opportunities for professional development
  • Collaborative and inclusive work environment
  • Flexible working arrangements promoting employee engagement
Full Job Description
Our Opportunity

We are currently seeking a Director of Information Security residing in Phoenix, AZ. In this role you will work as part of the Information Technology Team reporting to the Vice President of Information Technology

You will be responsible for

ACCOUNTABILITY

EXPECTED SCOPE

Strategy, governance and executive advisory

Develop and execute the multiyear security and privacy strategy, roadmap, operating model and investment priorities. Translate cyber, privacy, operational and regulatory risk into clear business, financial, client and reputational impact for executive leadership, board and governance bodies

ISMS, PIMS and regulatory assurance

Serve as accountable manager for ISO/IEC 27001, 42001 and ISO/IEC 27701. Chair required governance forums; maintain policies, objectives, risk treatment, management review, evidence and continual improvement. Coordinate with Legal on applicable contractual, legal and privacy obligations.

Security risk and architecture

Direct enterprise risk assessment, risk acceptance, control design and secure architecture across identity, cloud, network, endpoint, applications, data and AI. Embed security and privacy requirements into projects, acquisitions, vendors and technology change.

Security operations and resilience

Provide executive oversight for incident response, threat detection, vulnerability management, access governance, penetration testing, digital forensics and incident coordination. Ensure escalation, communications, law-enforcement and external-response decisions are documented and exercised.

Privacy and data protection

Act as Data Protection Officer and privacy escalation authority. Oversee privacy risk assessment, data protection requirements, information classification, data handling, transfer and disclosure decisions, and alignment with global privacy obligations.

Client, third-party and market assurance

Own the security assurance model for client questionnaires, contractual commitments, audits and restricted-information requirements. Direct third-party security risk management and support business development by clearly articulating Exponent’s security and privacy posture.

Metrics, audit and continuous improvement

Establish business-relevant metrics covering risk, incidents, vulnerabilities, audit findings, control effectiveness, awareness, third parties and program maturity. Sponsor internal and external audits, drive remediation, and report trends and investment outcomes.

Leadership, budget and operating maturity

Lead, develop and retain the security and privacy team; define accountability, succession, on-call coverage and service expectations. Own budget planning, vendor and contract portfolio, resource allocation, and delivery through internal teams and managed service partners.

Leadership Outcomes
  • Maintain a defensible, audit-ready security and privacy program aligned to Exponent’s business objectives and client commitments.
  • Reduce material cyber and privacy risk through prioritized treatment plans, clear ownership, measurable controls and timely escalation.
  • Enable consulting, litigation and corporate operations to adopt technology, cloud and AI securely without unnecessary friction.
  • Provide executives with concise, decision-oriented reporting on risk posture, incidents, investment needs and program maturity.
  • Build a resilient operating model with documented authority, repeatable processes, qualified backups and effective external partners.
You will have the following skills and qualifications
  • Progressive leadership experience directing enterprise information security, privacy, cyber risk or related programs in a distributed, regulated or client-trust-dependent environment. This experience must include building, transforming and or directing an information security program.
  • Demonstrated ownership of security strategy, governance, budget, vendors, metrics and multiyear transformation roadmaps.
  • Proven experience managing a compliance program.
  • Practical leadership of ISO/IEC 27001 programs and audits; working knowledge of privacy management and ISO/IEC 27701 strongly preferred.
  • Experience directing incident response, vulnerability management, identity and access governance, third-party risk, security architecture, MDR/MSSP services and audit remediation. This must include experience responding to a business impacting incident.
  • Ability to advise executives, clients, auditors, counsel and technical leaders, including during incidents, regulatory scrutiny and high-impact decisions.
  • Working knowledge of modern Microsoft security and identity capabilities, cloud platforms, endpoint and network security, data protection, Purview, AI security and secure software practices.
  • Bachelors degree in information technology, cybersecurity, risk management or a related field, or equivalent relevant experience.
  • Relevant certification such as CISSP required or expected; CISM, CRISC, PMP, ISO 27001 Lead Implementer/Lead Auditor, or privacy credentials are valued.
Leadership Competencies

Business and risk judgment

Balances protection, client obligations, cost and speed; makes clear, defensible decisions under uncertainty.

Executive communication

Converts technical risk into concise business choices, ownership, investment and measurable outcomes.

Incident leadership

Provides calm, decisive authority during incidents and coordinates technical, legal, privacy and business response.

Enterprise influence

Builds trusted partnerships across IT, Legal, HR, Finance, Operations, consultants, clients and third parties.

Operational discipline

Establish durable governance, metrics, evidence, service ownership, succession and continuous improvement.

Talent leadership

Sets clear expectations, develops capability, delegates effectively and creates accountability without concentrating knowledge.

 

Life @ Exponent

To learn more about life at Exponent and our impact, please visit the following links:https://www.exponent.com/careers/life-exponenthttps://www.exponent.com/company/our-impact

 

We value and encourage diversity, equity and inclusion across all facets of our firm. Having a team built of people with different backgrounds, skills and perspectives allows us to provide better value to our clients and enjoy an enriched work environment.

 

Our firm is committed to offering a variety of programs and resources to support health and well-being. We believe that providing competitive benefits, as well as compensation and recognition programs, empowers our staff to do work that makes a difference.

Work Environment

At Exponent, we have found that in-person interactions deepen employee engagement and are crucial for development, for realizing the full potential of our talented and diverse teams, and forbuilding a more inclusive workplace where all have a sense of belonging. In our offices, you can expect a supportive culture and a collaborative, dynamic, multi-disciplinary work environment.I-Onsite

Compensation

The pay rate for this position is dependent on experience and capabilities which will be assessed during the interview process.

Benefits you will enjoy

Access benefits information on our Life@Exponent page:  https://www.exponent.com/careers/life-exponent

Job LocationsUS-AZ-Phoenix

About Exponent

Exponent is a multi-disciplinary engineering and scientific consulting firm that brings together more than 90 different disciplines to solve engineering, science, regulatory, and business issues facing our clients. The company has been providing solutions to complex problems for more than 50 years and has a reputation for technical expertise, objective analysis, and clear communication. Exponent's services include analysis and testing, engineering and design, human factors, environmental and health sciences, and regulatory consulting. The company serves clients in a wide range of industries, including aerospace, automotive, consumer products, energy, healthcare, and technology.
Learn more about Exponent
Size
1,215 employees
Market Cap
$5 billion
Industry
Net Income
$82.5 million
Founded
1967
5 Year Trend
+8.2%
Revenue
$399.9 million
NASDAQ

Similar Jobs

More Jobs at Exponent

More Information Technology Jobs

Find similar Director of Information Security jobs: