高级总监,网络安全
Sr. Director, Cybersecurity
职位详情:
职位名称:高级总监,网络安全部:信息技术
汇报对象:IT基础设施与安全副总裁
工作地点:迪尔伯恩
职位分类:远程
FLSA状态:非豁免
职级:高管
职位概述:
网络安全高级总监是负责制定策略、治理、运营有效性以及网络安全计划持续改进的企业领导者。该职位领导四个集成能力:安全工程、安全运营、身份与访问管理,以及治理、风险和合规。该职位在通过风险导向的决策、弹性安全架构、有效运营和明确责任来保护信息资产的机密性、完整性和可用性的同时,推动业务目标的实现。
该职位与企业风险职能紧密合作,将网络威胁、控制差距和技术依赖转化为面向业务的风险陈述、情景和报告,这些内容可以整合到整体企业风险计划中。该职位定期向高级管理层和业务负责人提供建议,确定投资优先级,并提供关于网络风险暴露、计划绩效、弹性能力和修复进展的简洁报告。
秉承卡特(Carhartt)的勤奋精神,勤奋工作的价值观——可靠、诚实和信任——植根于我们创始人哈蒙德·卡特(Hamilton Carhartt)的遗产。他对服务勤奋人群的承诺继续激励着我们所做的每一件事。在这一遗产和我们使命的指引下——我们通过打造耐用的产品来服务和保护所有勤奋的人——我们致力于在每一个决定和每一件产品中坚持这些原则。
助理职责
- 负责并执行与业务优先事项、风险偏好、技术战略和监管义务一致的多年企业网络安全战略和路线图。
- 领导、指导并发展四个网络安全职能中的领导者和团队;建立清晰的决策权、继任计划、人才管道、运作节奏和可衡量的绩效期望。
- 使用清晰的商业和财务背景,向高管层提供有关重大网络风险、新兴威胁、重大事件、战略权衡和投资需求的建议。
- 负责网络安全运营模式、年度规划、预算、人员战略、采购模式、供应商组合以及能力优先级的制定。
查看英文原文
Position Details:
Title: Sr. Director, Cybersecurity Department: Information Technology Reports to: VP, IT Infrastructure and Security Location: Dearborn Job Classification: Remote FLSA Status: Exempt Job Band: Executive Job Summary The Senior Director of Cybersecurity is the enterprise leader accountable for the strategy, governance, operational effectiveness, and continual maturation of the cybersecurity program. The role leads four integrated capabilities: Security Engineering, Security Operations, Identity and Access Management, and Governance, Risk, and Compliance. This leader protects the confidentiality, integrity, and availability of information assets while enabling business objectives through risk-informed decision-making, resilient security architecture, effective operations, and clear accountability.
The position partners closely with the enterprise risk function to translate cyber threats, control gaps, and technology dependencies into business-oriented risk statements, scenarios, and reporting that can be aggregated into the overall enterprise risk program. The role regularly advises senior executives and business leaders, establishes investment priorities, and provides concise reporting on cyber risk exposure, program performance, resilience, and remediation progress.
Inspired by Hard Work At Carhartt, the values of hard work—dependability, honesty, and trust—are rooted in the legacy of our founder, Hamilton Carhartt. His commitment to serving hardworking people continues to inspire everything we do. Guided by his legacy and our mission—We serve and protect all hardworking people by building durable products—we remain dedicated to upholding these principles in every decision we make and every product we create. Associate Responsibilities
- Own and execute a multi-year enterprise cybersecurity strategy and roadmap aligned with business priorities, risk appetite, technology strategy, and regulatory obligations.
- Lead, coach, and develop leaders and teams across the four cybersecurity functions; establish clear decision rights, succession plans, talent pipelines, operating rhythms, and measurable performance expectations.
- Advise executive leadership on material cyber risks, emerging threats, major incidents, strategic tradeoffs, and investment needs using clear business and financial context.
- Own the cybersecurity operating model, annual planning, budget, workforce strategy, sourcing model, vendor portfolio, and prioritization of capabilities and initiatives.
- Establish program-level objectives, key risk indicators, key performance indicators, maturity targets, and executive reporting that demonstrate risk reduction and operational outcomes.
- Build strong partnerships across Information Technology, Enterprise Risk, Legal, Privacy, Internal Audit, Compliance, Human Resources, Finance, Supply Chain, and business functions.
- Define and maintain the enterprise cybersecurity strategy, target-state capabilities, policy architecture, control framework, and prioritized roadmap.
- Provide strategic direction for enterprise security architecture and security-by-design practices across cloud, on-premise, applications, infrastructure, data, and third-party services.
- Present cyber risk posture, incidents, trends, program performance, and investment recommendations to senior leadership and appropriate governance bodies.
- Lead annual and long-range planning, including budget development, capital and operating forecasts, resource allocation, sourcing decisions, and benefits realization.
- Oversee major cybersecurity transformation initiatives and ensure dependencies, risks, milestones, and outcomes are actively managed.
- Maintain external awareness of threat, regulatory, technology, and industry developments; translate relevant changes into program priorities.
- Establish a threat-informed operating model with clear severity criteria, escalation paths, service levels, playbooks, evidence requirements, and communication protocols.
- Direct response to significant cybersecurity incidents, coordinating containment, eradication, recovery, executive communications, legal and privacy engagement, and lessons learned.
- Sponsor exercises and simulations that validate incident response, crisis management, business continuity dependencies, and executive decision-making.
- Lead cybersecurity governance, policy and standards, risk assessment, compliance, control assurance, third-party cyber risk, awareness, exception management, and audit coordination.
- Maintain an enterprise cyber risk taxonomy and consistent methods for identifying, assessing, documenting, treating, accepting, monitoring, and escalating cyber risks.
- Oversee compliance with applicable legal, regulatory, contractual, and industry requirements and align the control environment to recognized cybersecurity frameworks.
- Coordinate independent assessments, audits, remediation plans, risk acceptances, and evidence quality; ensure accountable owners and sustainable closure of findings.
- Drive role-based cybersecurity awareness and behavior-change programs in partnership with business and enabling functions.
- Partner with the enterprise risk function to integrate cyber risk into the enterprise risk management framework, governance cadence, risk register, and executive reporting.
- Translate technical findings and threat conditions into business risk scenarios that describe affected objectives, plausible impacts, likelihood considerations, control effectiveness, dependencies, and treatment options.
- Calibrate cyber risk ratings and escalation thresholds with enterprise risk criteria so cyber risks can be consistently compared, aggregated, and prioritized alongside other enterprise risks.
- Provide timely inputs for enterprise risk assessments and reporting, including material changes in exposure, emerging risks, concentration risks, systemic dependencies, remediation commitments, and accepted residual risk.
- Facilitate risk ownership decisions with business and technology executives and ensure material risk acceptance is documented at the appropriate level of authority.
- Collaborate on risk appetite and tolerance statements, scenario analysis, executive exercises, and risk-informed investment planning.
- Set clear objectives and conduct regular operating reviews across services, incidents, risks, controls, projects, vendors, budgets, and talent.
- Oversee strategic vendors, managed services, consultants, and technology partners, including service quality, contractual performance, concentration risk, and value realization.
- Define and test continuity plans for critical cybersecurity services and leadership coverage.
- Represent the cybersecurity function in enterprise planning, major technology decisions, and other strategic initiatives as needed.
Required Education
- Bachelor's degree in Computer Science, Information Systems, Cybersecurity, Engineering, Business, Risk Management, or a related field, or equivalent combination of education and relevant experience.
- Master's degree in Cybersecurity, Information Systems, Business Administration, Risk Management, or a related discipline preferred.
- One or more relevant professional certifications preferred, such as CISSP, CISM, CISA, CRISC, CGEIT, or comparable security, risk, audit, cloud, or architecture credentials.
Required Skills & Experience
- Minimum of 15 years of progressively responsible experience across cybersecurity, information technology, technology risk, or related disciplines.
- Minimum of 8 years of people leadership experience, including leadership of managers or multiple cybersecurity functions in a complex enterprise environment.
- Demonstrated experience leading or providing executive oversight across Security Engineering, Security Operations, Identity and Access Management, and GRC.
- Proven success developing and executing enterprise cybersecurity strategies, roadmaps, operating models, and multi-year transformation programs.
- Experience advising senior executives and governance bodies on cyber risk, incident response, program performance, and investment priorities.
- Experience integrating cyber risk reporting with enterprise risk management, including risk taxonomy, scenario development, aggregation, appetite or tolerance, escalation, and executive reporting.
- Deep working knowledge of recognized cybersecurity and technology governance frameworks, such as NIST, ISO/IEC 27001, COBIT, CIS Controls, and ITIL.
- Demonstrated experience with security architecture, cloud and infrastructure security, security operations, incident response, vulnerability management, threat intelligence, IAM, third-party risk, compliance, audit, privacy, and resilience concepts.
- Experience managing substantial operating and capital budgets, strategic suppliers, managed services, and cross-functional portfolios.
- Exceptional business acumen, executive presence, written communication, presentation, negotiation, and influence skills.
- Ability to convert complex technical issues into concise business risk narratives and actionable decisions.
- Demonstrated ability to lead through ambiguity, manage competing priorities, build consensus, and drive accountable execution in a fast-paced environment.
Physical Requirements and Working Conditions
- Typical office and remote-work environment with extended periods using a computer.
- Availability outside normal business hours as needed for significant incidents, exercises, or business-critical events.
- Domestic and international travel may be required based on business needs.
- This position has a Remote location: Associate will have no regular requirement to be on-site. Travel on-site is limited to special events.
- Carhartt is a tobacco free workplace.
We are an equal opportunity employer, and all qualified applicants will receive consideration for employment without regard to race, color, ethnicity, disability, religion, national origin, gender, gender identity, gender expression, marital status, sexual orientation, age, protected veteran status, or any other characteristic protected by law.
All associates are required to understand and act in accordance with the Carhartt Core Values. Carhartt reserves the right to change, modify, suspend, interpret or cancel in whole or in any part, the job duties outlined above at any time and without advance notice to the employee.
Originally posted on Himalayas