Full-Time

Director – Security Governance

Posted on 9/10/2024

Solventum

Solventum

Compensation Overview

$222k - $271.4kAnnually

+ Variable Incentive Pay

Senior

Remote in USA

Relocation assistance may be authorized.

Category
Cybersecurity
IT Project Management
IT & Security
Required Skills
Management
Requirements
  • Bachelor’s Degree or higher from an accredited institution OR High School Diploma/GED or higher from a (completed and verified prior to start) and a minimum of sixteen (16) years of experience in Information Technology/Information Security.
  • Extensive background in Governance, Risk & Compliance, with particular focus on Governance in Healthcare or other highly regulated industry.
  • Experience building and optimizing best practice Enterprise Risk Management, Third Party Risk Management, Risk Quantification, as well as Data Governance and Artificial Intelligence (AI).
  • Supporting certifications and coursework demonstrating continual learning. CISSP strongly preferred, or equivalent experience across a broad spectrum of Information Security disciplines
  • Ten (10) years of experience building and leading global IT, digital and/or cybersecurity programs in a private, public, government or military environment
  • Minimum five (5+) years leading Information Security Governance programs
  • Successful track record developing and leading information governance programs, policies, procedures, and best practices.
  • Experience working with Risk, Security and/or Audit frameworks (SOX, HiTrust, SOC2, PCI, ISO 27001/2, NIST CFS / 800-53, FedRAMP, StateRAMP, and EIC 62443, etc.)
Responsibilities
  • Develop and execute gold-standard information security governance strategy and program. Drive culture of transparency, integrity, and accountability.
  • Focus efforts to support cyber- and business resilience, ensuring the organization is well-prepared to counter risks to continuity of operations.
  • Develop the appropriate security checkpoints against software and infrastructure development lifecycles, shifting effort to prevent rework and build security by design into every project.
  • Establish a robust Findings & Remediation program that identifies trends in newly discovered risks, provides actionable reporting, identifies root cause, and works collaboratively to reduce inherent risk and technical debt.
  • Identify, mitigate, and track to closure risks across the enterprise, providing actionable data and recommended solutions to organization leadership.
  • Use expertise to scale programs up and down to meet the current regulatory environment and the risk appetite of the organization.
  • Establish and maintain robust data security governance, including creation, classification, retention, retrieval, and disposal of records.
  • Monitor regulatory changes and industry standards.
  • Coordinate the transfer of information into or out of the firm in compliance with organizational policies. When necessary, ensure the proper execution of destruction orders.
  • Implement supporting protocols and processes to ensure statutory, regulatory, ethical and privacy requirements are met for the management of physical and electronic information.
  • Support data governance efforts across the organization, including but not limited to data classification, data retention and disposal, data sharing, records management, archiving data, and data privacy.

Company Stage

N/A

Total Funding

N/A

Headquarters

N/A

Founded

N/A

INACTIVE