Senior Director, Information Security - Job DescriptionRole SummaryThe Senior Director of Information Security is the leader of the enterprise security program and the single point of accountability for the company's security posture across IT, Operational Technology (OT), product, and customer-facing domains. This role acts as the primary liaison between the security organization and senior leadership, ensuring that security strategy is connected to business objectives and that cross-functional security teams operate in a coordinated, consistent manner.
While several security functions are organizationally distributed across the Product, Software & Services (OT), and CTO organizations, this role holds end-to-end functional ownership of the security program and ensures these streams remain aligned to a single security strategy, risk appetite, and set of standards - with a global focus spanning IT and OT, manufacturing, cloud, and SaaS environments.
Organizational ContextThe Senior Director of Information Security reports to the CIO with a direct line of communication to the Audit & Risk Committee on security and risk topics. The role operates as a matrixed leadership position: direct ownership of the security functions landing in the IT Organization, and functional (dotted-line) authority over security functions landing in the Product, Software & Services (OT), and CTO organizations.
Key ResponsibilitiesSecurity Strategy, Governance & Executive Liaison- Own and continuously evolve the enterprise security strategy, roadmap, and operating model.
- Serve as the connection point between executive leadership / the Board Audit and Risk Committee and the operational aspects of security, translating risk into business terms.
- Establish and maintain enterprise-wide security policies, standards, and a common risk framework applied consistently across all streams.
- Ensure cross-functional security teams are aligned, avoiding duplication and closing coverage gaps across IT and OT.
IT Security - Directly Owned- Security Operations: own the SOC, incident response, red team, and threat management, ensuring consistent incident management and response across IT and OT.
- Information Security: own security compliance and security audit management, including external audits across cloud, manufacturing, and SaaS environments.
- Customer-facing operational security (IT-landed): own customer security incident management and SaaS environment security as global functions, ensuring proper processes and adherence to legal and regulatory requirements.
Functional Alignment Across Other OrganizationsSets standards, defines requirements, and governs execution for security functions that land outside IT, while respecting each organization's operating model:
- Product Security (Product Org): secure SDLC / P-Gate, pen testing, and security scanning.
- OT / Software & Services Security: PKI and the customer-facing identity provider (IDP).
- Customer-facing security (CTO / Product Org): security pre-sales and post-sales, and customer contract review.
Cross-Stream Operating Model- Maintain a single, coherent security operating model and define the interfaces, RACI, and escalation paths between IT, Product, OT, and customer-facing functions.
- Drive consistent standards, metrics, reporting, and maturity assessment across all streams, and champion a security culture across the organization.
Qualifications & Experience- Senior security leadership experience (typically 8+ years in security, with significant time in a leadership role) spanning enterprise IT and at least one of OT / product / SaaS security.
- Demonstrated ability to lead in a matrixed environment, exercising influence over teams not under direct reporting lines.
- Strong command of security governance, risk, and compliance, including external audit management across cloud, manufacturing, and SaaS contexts.
- Hands-on understanding of SOC operations, incident response, threat management, secure SDLC, PKI, and identity.
- Proven executive communication skills, including Board-level engagement.
- Relevant certifications (e.g., CISSP, CISM, or equivalent) preferred.
Key Performance Indicators (illustrative)- Reduction in mean time to detect / respond (MTTD / MTTR) across IT and OT.
- Successful completion of external security audits (cloud, manufacturing, SaaS).
- Consistency of security standards adoption across all landing organizations.
- Customer incident handling and SaaS security commitments met within regulatory requirements.
Job Title: Senior Director, Information SecurityRequisition ID: 22246
Location: