gpac | The Recruitment Platform
A growing, employee-owned organization is seeking an experienced Director of Security and Compliance to lead its enterprise cybersecurity function.
The ideal candidate will have 8–12+ years of progressive enterprise security, cybersecurity, or technology leadership experience, including prior Director-level leadership and experience building or scaling a security organization.
This position will oversee security strategy, operations, architecture, IAM, cloud security, GRC, incident response, vulnerability management, third-party risk, and business continuity.
Responsibilities
· Develop and execute the enterprise security strategy and multi-year roadmap.
· Lead cybersecurity operations, monitoring, detection, response, and recovery.
· Lead incident response for significant security events.
· Oversee vulnerability management, endpoint protection, identity security, email security, backup resilience, and cloud security.
· Manage IAM and identity governance across Microsoft 365, Azure AD, and Google Cloud environments.
· Review security architecture for new technology platforms.
· Support security review and governance of AI/ML and agentic systems.
· Conduct enterprise and third-party security risk assessments.
· Manage security controls related to customer, contractual, regulatory, and cyber-insurance requirements.
· Support physical security, facility access, and critical infrastructure protection.
· Support business continuity and disaster recovery planning.
· Oversee security awareness and training.
· Own the annual security budget and technology investment plan.
· Lead, mentor, and develop the enterprise Security team.
Qualifications
· 8–12+ years of progressive cybersecurity or enterprise security experience.
· Prior Director-level or higher leadership experience required.
· 5+ years leading technical security teams and enterprise initiatives.
· Experience building or scaling a dedicated security function.
· Strong knowledge of:
o Security Operations
o IAM / Identity Governance
o EDR / XDR
o SIEM
o Network & Cloud Security
o Vulnerability Management
o Incident Response
o Security Architecture
o GRC
o Business Continuity / Disaster Recovery
· Experience with Microsoft 365, Azure, Google Cloud, and hybrid environments.
· Strong executive communication and leadership skills.
· Bachelor's degree in Cybersecurity, IT, Computer Science, Business, or related field.
· CISSP, CISM, CRISC, or similar certification preferred.
· Manufacturing, construction, industrial, or distributed operations experience preferred.
· Experience with AI/ML security governance is a plus.
· Familiarity with CrowdStrike, Druva, Barracuda, Microsoft Security, PAM, SIEM, vulnerability management, and security automation tools is a plus.
Compensation & Benefits
· $185,000–$213,000 Base Salary
· Employee Stock Ownership Program (ESOP)
· Discretionary Annual Bonus
· Medical, Dental & Vision Insurance
· 401(k) with Company Contributions
· Paid Time Off & Sick Time
· Paid Holidays
· Paid Parental Leave
· Tuition Reimbursement
· Employee Assistance Program
· Gym Reimbursement
This is an excellent opportunity for an experienced cybersecurity leader looking to take ownership of enterprise security strategy, operations, compliance, architecture, and team development.
To apply, submit an updated resume to jen.thiel@gogpac.com.
All inquiries and applications will remain confidential.
All qualified applicants will receive consideration without regard to race, age, color, sex (including pregnancy), religion, national origin, disability, sexual orientation, gender identity, marital status, military status, genetic information, or any other status protected by applicable laws or regulations. GPAC (Growing People and Companies) is an award-winning search firm specializing in placing quality professionals within multiple industries across the United States since 1990. We are extremely competitive, client-focused and realize that our value is in our ability to deliver the right solutions at the right time.