freehire launches on Product Hunt on 26 August.

Follow →

Unknown company

Discussion

Director of Cybersecurity

Summary

Lead a cybersecurity team to protect company systems, data, and compliance, overseeing incident response, vulnerability management, and risk reporting across infrastructure and cloud platforms.

OVERVIEW

The Director of Cybersecurity is responsible for leading the day-to-day operations, technical direction, and continued development of the Cybersecurity and Technology Compliance functions. This role oversees a team of Cybersecurity Engineers and Analysts responsible for protecting the company’s technology and data assets across infrastructure, networks, servers, cloud platforms, endpoints, identity systems, applications, and business systems.

This role also provides leadership oversight for the Technology Compliance function, including the Technology Compliance Manager and Compliance Analysts responsible for supporting ITGCs, SOX requirements, access reviews, control testing, evidence collection, remediation tracking, audit readiness, vendor risk support, and alignment with company technology standards and control frameworks.

This position is intended for a cybersecurity leader with a strong technical foundation, preferably someone who began their career in systems administration, infrastructure, or technology operations before moving into cybersecurity leadership. The ideal candidate will understand how enterprise systems are built, administered, monitored, secured, and recovered, and will use that knowledge to lead practical and effective cybersecurity and compliance operations.

The Director of Cybersecurity will be responsible for security operations, incident response coordination, vulnerability management, security tool effectiveness, identity and access security, technology compliance oversight, audit support, security awareness, cybersecurity risk reporting, and continuous improvement of cybersecurity and compliance processes. This role requires the ability to lead people, manage priorities, communicate clearly with technical and non-technical stakeholders, and ensure Cybersecurity and Technology Compliance support the broader Technology Team and business objectives.

KEY RESPONSIBILITIES

  • Lead, coach, and develop the Cybersecurity and Technology Compliance teams, including providing direction for ITGCs, SOX support, access reviews, control testing, evidence collection, remediation tracking, and audit readiness. Establish clear expectations, priorities, performance goals, accountability, cross-training, and documentation standards.
  • Develop and execute short-term and long-term Cybersecurity and Technology Compliance strategies, roadmaps, maturity plans, and operational improvement initiatives aligned with business objectives and enterprise risk priorities.
  • Oversee daily cybersecurity operations, including alert review, investigation, escalation, incident response, documentation, and reporting.
  • Lead and strengthen incident response capabilities, including triage, containment, eradication, recovery, communications, after-action reviews, runbooks, escalation paths, and control improvements.
  • Oversee the administration, configuration, monitoring, tuning, adoption, and effectiveness of cybersecurity platforms and related tools.
  • Ensure security controls are integrated into infrastructure, cloud, endpoint, network, application, identity, and data environments.
  • Oversee the vulnerability management program, including scanning, risk-based prioritization, remediation coordination, exception management, validation, tracking, and reporting.
  • Provide oversight for identity, privileged access, authentication, conditional access, and account lifecycle security controls.
  • Oversee Technology Compliance activities and partner with Technology Operations, Technology Engineering, Internal Audit, and business stakeholders to ensure technology practices align with company policies, ITGCs, SOX requirements, NIST standards, and other applicable control frameworks.
  • Develop and maintain the company’s cybersecurity risk-management strategy, including risk identification, assessment, ownership, remediation, acceptance, escalation, and reporting.
  • Lead the cybersecurity components of the third-party risk-management program, including vendor criticality, cybersecurity requirements, due diligence, risk assessments, ongoing monitoring, exceptions, remediation, and lifecycle reviews.
  • Maintain a centralized view of cybersecurity risks, control gaps, audit findings, accepted risks, and remediation plans across MarineMax and its subsidiaries.
  • Ensure accurate cybersecurity and technology compliance documentation, procedures, evidence, and reporting are maintained to support operations, audits, access reviews, control testing, vendor risk reviews, and remediation efforts.
  • Develop and maintain cybersecurity and technology compliance metrics, scorecards, dashboards, and periodic reporting to measure control effectiveness, identify trends, track remediation, and communicate risk to Technology Leadership and other stakeholders.
  • Oversee cybersecurity vendors, managed security services, contract renewals, platform investments, and budget recommendations to ensure expected business and security value is achieved.
  • Translate cybersecurity risks, control gaps, and technical recommendations into clear business, operational, financial, and compliance impacts for leadership.
  • Oversee cybersecurity awareness initiatives, phishing simulation programs, and user-focused security communications.
  • Maintain awareness of emerging threats, technologies, regulatory expectations, and security practices, and promote continuous learning across Cybersecurity, Technology Compliance, and the broader Technology organization

QUALIFICATIONS AND EXPERIENCE

  • Bachelor’s degree in Computer Science, MIS, Engineering, Cybersecurity, or a related field preferred; directly related experience may be considered in lieu of degree.
  • Industry accepted certifications such as AAISM, CISM, CISSP, CISA, and CRISC are preferred but not required.
  • Minimum 8–10 years of directly related technology or cybersecurity experience in an enterprise environment required.
  • Minimum 5 years of experience leading or managing a cybersecurity team required.
  • Prior hands-on experience in systems administration, infrastructure, technology operations, or a related technical discipline is strongly preferred.
  • Strong understanding of Windows Server, virtualization, Microsoft 365, identity, networking, cloud, and enterprise infrastructure technologies is required.
  • Experience supporting risk management, internal control, and technology governance frameworks, including COSO, COBIT, and NIST, is desired.
  • Experience supporting at least three SOX audit cycles, including access reviews, control testing, and remediation activities, is required.
  • Experience with enterprise cybersecurity platforms such as CrowdStrike, CyberArk, Tenable, Varonis, Microsoft 365 security tools, and related technologies is preferred.
  • Experience with public cloud environments, database security, Cisco Meraki, Palo Alto firewalls, and enterprise network security is desired.
  • Strong leadership, coaching, prioritization, analytical, and problem-solving skills.
  • Excellent written and verbal communication skills, with the ability to explain cybersecurity risks, recommendations, and technical details to team members, project teams, business stakeholders, auditors, and Technology Leadership.
  • Self-starter with strong time management, documentation, relationship management, follow-through, and decision-making skills.

See also