Director of Information Security
Boost your chances before you apply.
DBM Global Inc
Phoenix, AZ, US
Summary
The Director of Information Security is responsible for developing and executing the enterprise cybersecurity strategy and roadmap to protect organizational assets. This role oversees security operations, incident response, risk management, and ensures secure-by-design principles are integrated across infrastructure and applications.
Job Description
Job Details: Job Location: DBMG Headquarters - Phoenix, AZ, Salary Range: Undisclosed, Position Value Proposition
As the Director of Information Security at DBMG, you are responsible for leading and advancing the organization’s cybersecurity program to protect information assets, technology, systems, infrastructure, and business operations. This role provides strategic and operational leadership across cybersecurity risk management, security operations, architecture, vulnerability management, incident response, identity and access security, data protection, third-party cybersecurity risk, and security awareness.
Core Responsibilities
Develop and execute the enterprise cybersecurity strategy, roadmap, policies, standards, and security priorities aligned with business objectives and enterprise risk.
Identify, assess, prioritize, and communicate cybersecurity risks across infrastructure, applications, cloud environments, identities, data, and third parties.
Oversee security operations, including threat monitoring, detection, vulnerability management, incident response, and continuous improvement of security capabilities
Establish and maintain enterprise security architecture and ensure secure-by-design principles are incorporated into infrastructure, cloud, applications, DevSecOps, and technology initiatives
Lead cybersecurity incident response and preparedness, including incident playbooks, tabletop exercises, containment, recovery, and post-incident improvement
Provide leadership for identity and access security, privileged access, endpoint protection, network and cloud security, and data protection capabilities
Develop and maintain cybersecurity awareness and training programs that strengthen employee security behaviors and organizational readiness
Establish cybersecurity metrics and reporting that provide the CIO and executive leadership with visibility into security posture, material risks, incidents, vulnerabilities, and risk-reduction initiatives
Partner with Infrastructure, DevSecOps, applications, and other technology teams to ensure cybersecurity controls are implemented, operated effectively, and remediated when deficiencies are identified.
Key Performance Indicators
Success in this role may be measured through:
Reduction in material cybersecurity risk exposure
Critical and high-risk vulnerability remediation performance
Security incident frequency, severity, and response effectiveness
Security control and tooling coverage
Identity and privileged-access risk reduction
Cybersecurity awareness and phishing-resilience metrics
Progress against the approved cybersecurity roadmap
Timely remediation of identified cybersecurity deficiencies
Required Qualifications
Bachelor’s degree in Cybersecurity, Information Security, Computer Science, Information Technology, or a related field.
Certified Information Systems Security Professional (CISSP) certification required within 12 months of hire.
8+ years of progressive experience in cybersecurity, information security, security engineering, or security operations.
3+ years of cybersecurity leadership experience.
Strong knowledge of cybersecurity risk management, security architecture, threat detection, vulnerability management, incident response, identity and access management, cloud security, endpoint security, and data protection.
Demonstrated ability to communicate cybersecurity risk and business impact to executive and non-technical stakeholders.
Strong leadership, collaboration, analytical, and decision-making skills.
Preferred Qualifications
Experience working in complex, distributed, multi-business-unit environments.
Experience securing Microsoft Azure, Microsoft 365, hybrid infrastructure, and enterprise applications.
Additional relevant cybersecurity certifications such as CISM, CCSP, GIAC, or cloud security certifications.
Core Competencies
Cybersecurity Leadership • Risk Management • Security Architecture • Security Operations • Incident Response • Vulnerability Management • Identity & Access Security • Executive Communication • Business Acumen • Cross-Functional Leadership • Accountability
Role Boundary
The Director of Information Security owns the technical and operational cybersecurity program, including cybersecurity architecture, security operations, incident response, vulnerability remediation, identity security, security tooling, and related technical controls
Independent IT compliance assurance, SOX and regulatory control testing, audit coordination, compliance evidence management, and compliance framework readiness are owned by the IT Compliance Manager and the appropriate Compliance/Internal Audit organization.
Additional Duties & Responsibilities
This job description is not an exclusive or exhaustive list of all responsibilities and functions that an employee in this position may be asked to perform. Duties and responsibilities may be changed, expanded, reduced, or delegated by management to meet the business needs of the company.
Work Environment
Position requires as many hours needed to fulfill the daily and weekly obligations required to carry out the functions. Working long days including evenings and weekends can be required for this position. This position is generally indoors in a climate controlled office environment. Reasonable accommodations will be made upon request for those who have disabilities that qualify under the American with Disabilities Act.
DBM Global Inc is an Equal Opportunity Employer
Qualifications:
Majority-owned by INNOVATE Corp. (NYSE: VATE), DBM Global is a leading structural steel and industrial construction company that operates across commercial and industrial sectors. We provide end-to-end construction services, including design assist, engineering, BIM, modeling and detailing, project management, steel fabrication, sitework/ civil, MEP, piping, equipment installation, advanced field erection, and modular manufacturing.
With 11 shops and 1.8M+ square feet of shop space, DBM Global leverages its unrivaled scale and operational flexibility to deliver world class value to its clients through a portfolio of companies which provide building expertise, an innovative mindset, and a collaborative approach.
To learn more about DBM Global Inc., please visit our website at www.dbmglobal.com
DBM Global Inc. is an Equal Opportunity Employer
Company size
1,001-5,000 employees
Industry
Construction
Org type
Public Company
Headquarters
Phoenix, Arizona
Majority-owned by INNOVATE Corp. (NYSE: VATE), DBM Global is a leading structural steel and industrial construction company that operates across commercial and industrial sectors. We provide end-to-end construction services, including design assist, engineering, BIM, modeling and detailing, project management, steel fabrication, sitework/ civil, MEP, piping, equipment installation, advanced field erection, and modular manufacturing.
With 11 shops and 1.8M+ square feet of shop space, DBM Global leverages its unrivaled scale and operational flexibility to deliver world class value to its clients through a portfolio of companies which provide building expertise, an innovative mindset, and a collaborative approach.
To learn more about DBM Global Inc., please visit our website at www.dbmglobal.com
DBM Global Inc. is an Equal Opportunity Employer
Company size
1,001-5,000 employees
Industry
Construction
Org type
Public Company
Headquarters
Phoenix, Arizona