- Company Name
- Subaru of America
- Job Title
- CISO Director - Information Security
- Job Description
-
**Job Title**
CISO Director – Information Security
**Role Summary**
Senior executive responsible for establishing and executing a comprehensive information security strategy and program. Leads security operations, incident response, policy development, vendor management, and cloud security initiatives while aligning IT security with business objectives, managing multi‑million dollar budgets, and mentoring an inclusive security team.
**Expectations**
- Deliver enterprise‑wide security vision and roadmap.
- Ensure timely achievement of financial and service targets.
- Build and sustain a culture of security ownership across the organization.
- Provide executive presence, consensus building, and strategic partnership with business leaders.
- Foster diversity, inclusion, and career development within the security workforce.
**Key Responsibilities**
- Strategic Planning & Financial Oversight: develop long‑term security strategy, cloud security roadmap, and multi‑year IT roadmaps; define and manage $4‑10 M annual budgets.
- Leadership & Operations Management: direct security teams, set priorities, provide coaching, and maintain operational oversight of security programs.
- Incident Response & Service Delivery: lead incident response planning, enforce SLAs, negotiate vendor contracts, and monitor service delivery against agreed standards.
- Project Planning & Resource Allocation: design, implement, and evaluate secure, scalable solutions; assess ROI; allocate resources for large IT projects.
- Policy Development & Compliance: create and enforce policies in collaboration with Legal, Compliance, and GovRel; ensure adherence to laws and regulations.
- Change Management & Innovation: advocate for technological upgrades, drive new processes, and keep abreast of emerging threats and industry trends.
**Required Skills**
- Strategic thinking and security architecture design
- Incident response & threat intelligence
- Risk management & compliance (GDPR, SOX, CCPA, etc.)
- Vendor & contract management
- Budgeting, forecasting, and financial stewardship
- Leadership, coaching, and team building
- Cloud security (AWS, Azure, GCP) and DevSecOps practices
- Strong communication with executive and cross‑functional stakeholders
- Change management and continuous improvement mindset
**Required Education & Certifications**
- Bachelor’s degree in Computer Science, Information Security, or related field (MBA or Master’s preferred).
- Professional security certifications: CISSP, CISM, CISA, CRISC, CCSP, or equivalent.
- Project Management certification (PMP/PRINCE2) considered an advantage.