Skip to content

Open nowPosted 55 days ago

Director, Information Security & Compliance

Overhead Door11 open roles

Where
Lewisville, TX, United States
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowDirector, Information Security & ComplianceOverhead Door · Lewisville, TX, United States
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Overhead Door's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

8.2% of postings close within 7 days. Measured by our own scanner across the market. Overhead Door postings stay open a median of 3 days.

Share of postings closed within
  1. 1.8%1 day
  2. 3.6%3 days
  3. 8.2%7 days
  4. 15.2%14 days
  5. 34.0%30 days
This job: posted 55 days ago

Overhead Door median: 3 days open

The posting

Job Description

The Director of Information Security and Compliance provides strategic and operational leadership for Information Security and IT Risk Compliance efforts. The role manages and coordinates core aspects of security administration, identity and access management, audit response, and vulnerability assessments within the boundaries of acceptable risk. The director will conduct audits/assessments for IT Compliance, IT Security and Data Privacy. New implementations and operational maintenance of existing business-critical applications will be examined. The role extends to any part of the business that has risk associated with information assets. The Director of Enterprise Security and Compliance reports directly to the Chief Information Officer.

Responsibilities

Overall Responsibilities:

  • Serve as advisor to executive leadership on information security risks, IT compliance issues, and industry trends that will require prioritization, funding, and/or implementation support.
  • Oversee all information security related technologies and third-party vendor relationships.
  • Partner with Infrastructure, Operations and development teams to drive adoption and implementation of information security policies, procedures, standards, and incident handling processes.
  • Serve as liaison with leadership, legal, and internal audit, to analyze new requirements, standards, and capabilities and to determine feasibility and timing of implementation of new programs and capabilities.
  • Conduct assessments/audits to confirm operational effectiveness of IT general controls and identify risk.
  • Manage development and assignment of access roles for all users across ERP platforms.
  • Provide risk metrics to management regarding audit performance and findings.
  • Assist control owners with root cause analysis and track risk management action plan progress.
  • Guide efforts to create common control framework and uniform compliance reporting standard.

Specific Responsibilities:

  • Planning and reviewing annual review of compliance requirements influencing operations and initiatives in information security, privacy, and IT risk management.
  • Performing examination of security controls to determine design and operational effectiveness.
  • Coordinate, plan, manage and maintain activities related to application security for multiple ERP systems and related applications, including but not limited to user profile assignments, system access permissions and user account maintenance.
  • Evaluate information security related technologies and implement the solutions.
  • Planning and reviewing annually the risks influencing the effectiveness of information security, privacy, and information security risk management.
  • Studying risk assessments conducted by business owners and support functions to incorporate relevant tests in assessment plans.
  • Conducting IT controls management testing of controls independent of the audit schedule to save time during audits.
  • Communicating with different levels of IT and business leaders on drivers of the information security risk assessment agenda.
  • Preparing the communications schedule with all stakeholders — CIO, CFO, Internal Audit, etc.
  • Identifying and tracking assessment/audit performance metrics.
  • Implementing and supervising the issue tracking and resolution process.
  • Reviewing IT audit risk assessments conducted by internal audit team members.
  • Planning third-party audits in consultation with IT, Internal Audit, business process owners and vendor management.
  • Reviewing third-party attestation and audit reports and providing feedback to business leaders and risk owners.
  • Collaborating with the internal audit team, their agents, and external auditors.
  • Monitoring Information Security assessment best practices in the industry to determine opportunities for improvement, including tools and processes.
  • Assisting business and support functions in evaluating tools and technology that support the enterprise's risk management approach.
  • Providing recommendations to business and IT leaders on practices followed in the industry to mitigate risks.

Qualifications

Qualifications:

  • Bachelor’s Degree in Business, Accounting, Information Technology, or other quantitative discipline.
  • 10+ years of broad privacy and data protection, compliance or legal experience
  • 5+ years of audit/assessment experience with PCI or SOX
  • 3+ years leading a team of auditors or compliance analysts
  • Sound understanding of security principles including logical access controls, change control, least privilege, segregation of duties, computer operations, network security, vulnerability management, and secure coding.
  • Broad technical understanding of data management platforms (e.g., IBM DB2, Oracle, Microsoft SQL Server, etc.) and associated data security controls.
  • Strong technology acumen and the ability to assess data privacy gaps in products/services design.
  • Expert understanding of data classification, data protection, and data retention standards and practices.
  • Familiarity with common enterprise and web application technologies.
  • Experience with management and oversight of ERP security and role-based access management.
  • Experience with project management best practices and collaborating with PMO.
  • Experience with common information security management frameworks, such as International Organization for Standardization (ISO) 2700x, ITIL, CSC20, COBIT and National Institute of Standards and Technology (NIST) frameworks.
  • Expert understanding of data protection regulations and standards (e.g., PCI, Safe Harbor, EU Data Protection Directive, etc.).
  • Strong analytical and time management skills
  • Ability to maintain a high degree of confidentiality

Preferred Requirements:

  • Experience with Oracle’s eBusiness Suite and Identity Management products
  • Certified Information Security Auditor (CISA)
  • PMI Project Management Professional (PMP)
  • Payment Card Industry (PCI) Internal Security Assessor (ISA)
  • Certified Information Privacy Professional (CIPP) or Certified Information Privacy Manager (CIPM)
  • Industry Standard Security certifications including: SANS/GIAC GSNA, ISACA CISM, ISC2 CISSP, and ISC2 CSSLP.
From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Overhead Door's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Overhead Door's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Overhead Door's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.