- Company Name
- NASCAR
- Job Title
- Director, Information Security
- Job Description
-
Job title: Director, Information Security
Role Summary:
Lead the enterprise-wide information security organization, defining strategy, governance, risk management, compliance, and incident response to protect corporate, operational, and media assets across cloud, on‑premises, and event environments.
Expectations:
- Translate business objectives into actionable cybersecurity strategy.
- Demonstrate measurable improvement in risk posture and security program maturity.
- Build a culture of security awareness and accountability throughout the organization.
Key Responsibilities:
- Design and execute a multi‑year cybersecurity roadmap covering risk management, incident response, compliance, threat detection, vulnerability, and IAM programs.
- Establish and maintain security governance frameworks, policies, and standards (NIST, ISO 27001, CIS, SOC, PCI DSS).
- Oversee enterprise risk management, ensuring risk assessments, mitigation plans, and residual risk acceptance are embedded in operations.
- Partner with IT, Cloud, Engineering, Legal, and Risk to integrate security into strategic initiatives, product launches, broadcast systems, and new technologies.
- Serve as senior escalation point for major security incidents, breaches, or investigations, delivering executive communications and post‑incident reviews.
- Present cybersecurity posture, key metrics, and investment performance to leadership.
- Manage the annual security budget, vendor relationships, and cross‑functional program execution.
- Foster security awareness and proactive defense through training, policies, and leadership visibility.
Required Skills:
- 10+ years of progressive cybersecurity experience, including 4+ years in leadership roles.
- Deep knowledge of enterprise security architecture, risk management, and governance frameworks (NIST, ISO 27001, CIS, SOC, PCI DSS).
- Experience with cloud platforms (AWS, Azure), endpoint, identity, and network security technologies.
- Proven incident response leadership and security transformation experience.
- Strong analytical, communication, and presentation skills with ability to influence all levels.
- Budget management, vendor negotiation, and program management capabilities.
Required Education & Certifications:
- Bachelor’s degree in Information Security, Computer Science, Engineering, or related field (advanced degree preferred).
- Senior‑level certifications: CISSP, CISM, CISA, CRISC, CCISO, or equivalent.
Daytona beach, United states
On site
Senior
17-02-2026