Vice President, Information Security and Privacy
Yuhaaviatam of San Manuel Nation · Highland, CA, United States
About The Role
Under the direction of the Senior Vice President, Chief Information Security and Risk Officer (CISRO), the Vice President of Information Security & Privacy is responsible for leading and advancing the enterprise information security and privacy programs to ensure the protection of information assets and the effective management of privacy risks. The Vice President provides strategic leadership and operational oversight for cybersecurity, privacy, and program governance in alignment with risk management and compliance objectives, while driving the development, implementation, and continuous improvement of security and privacy policies, standards, and controls. Working collaboratively across the enterprise, the Vice President partners with business, technology, risk, legal, compliance, and operational leaders to support regulatory requirements, strengthen risk management practices, and promote a culture of security and privacy awareness.
This position also oversees security and privacy operations, monitoring, reporting, and program performance to ensure alignment with organizational objectives and enterprise risk posture.
ESSENTIAL DUTIES AND RESPONSIBILITIES
- Lead the implementation and continuous improvement of the enterprise information security and privacy programs, ensuring alignment with organizational objectives, risk management strategies, and regulatory requirements.
- Direct and oversee information security operations, security engineering, governance, risk management, privacy, vulnerability management, incident response, threat intelligence, and data protection functions to ensure the confidentiality, integrity, and availability of enterprise information assets.
- Develop, implement, and maintain security and privacy policies, standards, procedures, and control frameworks based on industry-recognized practices, regulatory requirements, and organizational risk tolerance.
- Provide leadership and direction to security and privacy leaders and team members, ensuring the development of technical, regulatory, and business competencies while planning for future organizational capabilities and resource needs.
- Partner with business, technology, legal, compliance, human resources, internal audit, and operational leaders to integrate security and privacy requirements into enterprise initiatives, projects, systems, and business processes.
- Establish and maintain security and privacy governance processes, including risk identification, assessment, treatment, and reporting, to support informed decision-making and risk-based prioritization across the enterprise.
- Oversee the enterprise privacy program, including privacy impact and risk assessments, data protection requirements, regulatory compliance activities, privacy-by-design practices, and the management of privacy incidents and inquiries.
- Create, communicate, and implement risk-based processes for third-party and vendor risk management, including the assessment and treatment of risks associated with partners, consultants, service providers, and other external parties.
- Oversee security and privacy monitoring, incident response, investigations, and threat intelligence activities, ensuring timely escalation, response, and remediation of identified risks and events.
- Monitor the evolving threat, regulatory, and privacy landscape, advising executive leadership on emerging risks, compliance obligations, and appropriate mitigation strategies.
- Develop and maintain program metrics, key performance indicators, dashboards, and executive reporting to measure program effectiveness, support resource allocation decisions, and communicate risk posture to senior leadership.
- Collaborate with enterprise leaders to support business continuity, disaster recovery, data governance, artificial intelligence governance, and other risk-related initiatives that impact information security and privacy.
- Prepare and deliver presentations, strategic updates, and recommendations to executive leadership, enterprise risk committees, and other governance bodies as required.
- Perform other duties as assigned to support the efficient operation of the department.
SUPERVISORY RESPONSIBILITIES
Carries out supervisory responsibilities in accordance with the organization’s policies and applicable laws. Responsibilities include interviewing, hiring and training employees; planning, assigning reviewing and directing work; evaluating and appraising performance; rewarding and disciplining employees; addressing complaints and resolving problems. Make hiring decisions and designs individual development plans with succession planning in mind for all key roles.
EDUCATION , EXPERIENCE AND QUALIFICATIONS
- Bachelor’s Degree in Business Administration or an Information Technology-related field required. Master’s Degree a strong plus (MBA, Information Technology or Legal/Compliance related degree preferred).
- Minimum twelve (12) years of experience in a combination of information security, risk management, and IT
Similar roles you might like
See all →This is an external listing. JobSpring does not represent or verify the employer. Report this listing
