Carhartt, Inc.

Sr. Director, Cybersecurity

Carhartt, Inc.$160K — $200K *
Information Technology
11 - 15 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Computer Science, Cybersecurity, or related field; Master's preferred.
  • Minimum 15 years in cybersecurity or technology risk roles; 8 years in leadership.
  • Experience in Security Engineering, Operations, Identity and Access Management, and GRC.
  • Proven track record in developing enterprise cybersecurity strategies.
  • Ability to advise senior leaders on cyber risks and investment priorities.
  • Familiarity with NIST, ISO/IEC 27001, COBIT, and other cybersecurity frameworks.
  • Strong communication and negotiation skills, capable of simplifying technical issues.

Responsibilities

  • Own and implement multi-year cybersecurity strategy aligned with business needs.
  • Lead and develop teams across cybersecurity functions to meet performance goals.
  • Advise executives on cyber risks and necessary strategic responses.
  • Manage cybersecurity operating model and annual budgeting processes.
  • Establish and report on cybersecurity objectives and key risk indicators.
  • Build partnerships across IT, risk, compliance, and business functions.
  • Drive initiatives to enhance cyber resilience and threat-informed operations.

Benefits

  • Remote work flexibility with limited travel.
  • Comprehensive health and wellness programs.
  • Opportunities for professional development and certifications.
  • Robust retirement plan and matching contributions.
  • Supportive work culture in a tobacco-free environment.
Full Job Description
Position Details:

Title: Sr. Director, Cybersecurity

Department: Information Technology

Reports to: VP, IT Infrastructure and Security

Location: Dearborn

Job Classification: Remote

FLSA Status: Exempt

Job Band: Executive

Job Summary

The Senior Director of Cybersecurity is the enterprise leader accountable for the strategy, governance, operational effectiveness, and continual maturation of the cybersecurity program. The role leads four integrated capabilities: Security Engineering, Security Operations, Identity and Access Management, and Governance, Risk, and Compliance. This leader protects the confidentiality, integrity, and availability of information assets while enabling business objectives through risk-informed decision-making, resilient security architecture, effective operations, and clear accountability.

The position partners closely with the enterprise risk function to translate cyber threats, control gaps, and technology dependencies into business-oriented risk statements, scenarios, and reporting that can be aggregated into the overall enterprise risk program. The role regularly advises senior executives and business leaders, establishes investment priorities, and provides concise reporting on cyber risk exposure, program performance, resilience, and remediation progress.

Associate Responsibilities
  • Own and execute a multi-year enterprise cybersecurity strategy and roadmap aligned with business priorities, risk appetite, technology strategy, and regulatory obligations.
  • Lead, coach, and develop leaders and teams across the four cybersecurity functions; establish clear decision rights, succession plans, talent pipelines, operating rhythms, and measurable performance expectations.
  • Advise executive leadership on material cyber risks, emerging threats, major incidents, strategic tradeoffs, and investment needs using clear business and financial context.
  • Own the cybersecurity operating model, annual planning, budget, workforce strategy, sourcing model, vendor portfolio, and prioritization of capabilities and initiatives.
  • Establish program-level objectives, key risk indicators, key performance indicators, maturity targets, and executive reporting that demonstrate risk reduction and operational outcomes.
  • Build strong partnerships across Information Technology, Enterprise Risk, Legal, Privacy, Internal Audit, Compliance, Human Resources, Finance, Supply Chain, and business functions.
  • Define and maintain the enterprise cybersecurity strategy, target-state capabilities, policy architecture, control framework, and prioritized roadmap.
  • Provide strategic direction for enterprise security architecture and security-by-design practices across cloud, on-premise, applications, infrastructure, data, and third-party services.
  • Present cyber risk posture, incidents, trends, program performance, and investment recommendations to senior leadership and appropriate governance bodies.
  • Lead annual and long-range planning, including budget development, capital and operating forecasts, resource allocation, sourcing decisions, and benefits realization.
  • Oversee major cybersecurity transformation initiatives and ensure dependencies, risks, milestones, and outcomes are actively managed.
  • Maintain external awareness of threat, regulatory, technology, and industry developments; translate relevant changes into program priorities.
  • Establish a threat-informed operating model with clear severity criteria, escalation paths, service levels, playbooks, evidence requirements, and communication protocols.
  • Direct response to significant cybersecurity incidents, coordinating containment, eradication, recovery, executive communications, legal and privacy engagement, and lessons learned.
  • Sponsor exercises and simulations that validate incident response, crisis management, business continuity dependencies, and executive decision-making.
  • Lead cybersecurity governance, policy and standards, risk assessment, compliance, control assurance, third-party cyber risk, awareness, exception management, and audit coordination.
  • Maintain an enterprise cyber risk taxonomy and consistent methods for identifying, assessing, documenting, treating, accepting, monitoring, and escalating cyber risks.
  • Oversee compliance with applicable legal, regulatory, contractual, and industry requirements and align the control environment to recognized cybersecurity frameworks.
  • Coordinate independent assessments, audits, remediation plans, risk acceptances, and evidence quality; ensure accountable owners and sustainable closure of findings.
  • Drive role-based cybersecurity awareness and behavior-change programs in partnership with business and enabling functions.
  • Partner with the enterprise risk function to integrate cyber risk into the enterprise risk management framework, governance cadence, risk register, and executive reporting.
  • Translate technical findings and threat conditions into business risk scenarios that describe affected objectives, plausible impacts, likelihood considerations, control effectiveness, dependencies, and treatment options.
  • Calibrate cyber risk ratings and escalation thresholds with enterprise risk criteria so cyber risks can be consistently compared, aggregated, and prioritized alongside other enterprise risks.
  • Provide timely inputs for enterprise risk assessments and reporting, including material changes in exposure, emerging risks, concentration risks, systemic dependencies, remediation commitments, and accepted residual risk.
  • Facilitate risk ownership decisions with business and technology executives and ensure material risk acceptance is documented at the appropriate level of authority.
  • Collaborate on risk appetite and tolerance statements, scenario analysis, executive exercises, and risk-informed investment planning.
  • Set clear objectives and conduct regular operating reviews across services, incidents, risks, controls, projects, vendors, budgets, and talent.
  • Oversee strategic vendors, managed services, consultants, and technology partners, including service quality, contractual performance, concentration risk, and value realization.
  • Define and test continuity plans for critical cybersecurity services and leadership coverage.
  • Represent the cybersecurity function in enterprise planning, major technology decisions, and other strategic initiatives as needed.


Required Education
  • Bachelor's degree in Computer Science, Information Systems, Cybersecurity, Engineering, Business, Risk Management, or a related field, or equivalent combination of education and relevant experience.
  • Master's degree in Cybersecurity, Information Systems, Business Administration, Risk Management, or a related discipline preferred.
  • One or more relevant professional certifications preferred, such as CISSP, CISM, CISA, CRISC, CGEIT, or comparable security, risk, audit, cloud, or architecture credentials.

Required Skills & Experience
  • Minimum of 15 years of progressively responsible experience across cybersecurity, information technology, technology risk, or related disciplines.
  • Minimum of 8 years of people leadership experience, including leadership of managers or multiple cybersecurity functions in a complex enterprise environment.
  • Demonstrated experience leading or providing executive oversight across Security Engineering, Security Operations, Identity and Access Management, and GRC.
  • Proven success developing and executing enterprise cybersecurity strategies, roadmaps, operating models, and multi-year transformation programs.
  • Experience advising senior executives and governance bodies on cyber risk, incident response, program performance, and investment priorities.
  • Experience integrating cyber risk reporting with enterprise risk management, including risk taxonomy, scenario development, aggregation, appetite or tolerance, escalation, and executive reporting.
  • Deep working knowledge of recognized cybersecurity and technology governance frameworks, such as NIST, ISO/IEC 27001, COBIT, CIS Controls, and ITIL.
  • Demonstrated experience with security architecture, cloud and infrastructure security, security operations, incident response, vulnerability management, threat intelligence, IAM, third-party risk, compliance, audit, privacy, and resilience concepts.
  • Experience managing substantial operating and capital budgets, strategic suppliers, managed services, and cross-functional portfolios.
  • Exceptional business acumen, executive presence, written communication, presentation, negotiation, and influence skills.
  • Ability to convert complex technical issues into concise business risk narratives and actionable decisions.
  • Demonstrated ability to lead through ambiguity, manage competing priorities, build consensus, and drive accountable execution in a fast-paced environment.

Physical Requirements and Working Conditions
  • Typical office and remote-work environment with extended periods using a computer.
  • Availability outside normal business hours as needed for significant incidents, exercises, or business-critical events.
  • Domestic and international travel may be required based on business needs.
  • This position has a Remote location: Associate will have no regular requirement to be on-site. Travel on-site is limited to special events.
  • Carhartt is a tobacco free workplace.

#LI-REMOTE

About Carhartt, Inc.

Carhartt, Inc. is a leading American workwear manufacturer that was founded in 1889. The company produces a range of clothing items including jackets, coats, vests, shirts, pants, and other accessories. Carhartt, Inc. is headquartered in Dearborn, Michigan and has manufacturing facilities in the United States and Mexico. The company is known for its durable and high-quality products that are designed to withstand harsh working conditions. Carhartt, Inc. has a strong brand presence in the United States and is expanding its operations globally.
Learn more about Carhartt, Inc.
Size
5,000 employees
Industry
Founded
1889

Similar Jobs

More Jobs at Carhartt, Inc.

More Information Technology Jobs

Find similar Sr. Director, Cybersecurity jobs: