Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Director Information Security & Governance

Bonobos

Director, Information Security & Governance

The Director, Information Security & Governance serves as Phoenix Retail's senior information security leader with enterprise-wide accountability for the strategy, execution, and ongoing maturity of the company's information security, data protection, privacy controls, and AI security governance program. The role protects Phoenix Retail's omnichannel environment, including corporate systems, e-commerce platforms, store technology, customer and payment data, AI-enabled capabilities, and supporting infrastructure. The Director provides strategic leadership for the Information Security team, fostering a high-performance culture through mentorship and talent development to ensure the sustained operational excellence of the team and the organization.

Operating with the scope and presence of a Chief Information Security Officer, the Director leads enterprise security strategy, governance, policy, architecture, operations, incident response, AI security controls, and security risk management. The role advises executive leadership and the Board on security posture, emerging threats, regulatory obligations, business risk, and investments required to protect the company. This leader partners closely with Technology, Development, Legal, Procurement, Internal Audit, Compliance, Finance, and business stakeholders to embed security across enterprise technology and vendor ecosystems. The Director is a key stakeholder in Third-Party Risk Management and owns Phoenix's PCI-DSS program with full accountability for readiness and outcomes. This is a strategic leadership role requiring strong hands-on technical credibility. The Director must also be able to engage directly with technical matters, including SIEM activity, detection validation, threat hunting, incident investigations, and AI control monitoring when needed.

Key Responsibilities

  • Serve as enterprise owner for Phoenix Retail's information security strategy, roadmap, governance model, security policy framework, and AI security governance, aligned to business priorities and retail operating needs.
  • Lead and mature a security program built against the NIST Cybersecurity Framework, including measurable controls, maturity targets, risk-based prioritization, and reporting to executive leadership and the Board.
  • Design, implement, and monitor controls for AI technologies and use cases, including acceptable-use standards, administrative approvals, data handling requirements, identity and access guardrails, logging, vendor risk inputs, usage monitoring, and spend/consumption oversight.
  • Own PCI-DSS across corporate, e-commerce, and store/cardholder data environments, including scoping, segmentation, control design, assessor coordination, remediation, evidence, and executive accountability for outcomes.
  • Lead application security across Phoenix Retail's digital commerce and enterprise application portfolio, embedding secure design, code review/SAST/DAST, testing, and risk acceptance into the SDLC.
  • Lead network, cloud, endpoint, identity, collaboration, and infrastructure security architecture and operations, ensuring appropriate controls across corporate, e-commerce, store, GCP, Google Workspace, and other key environments.
  • Own security operations, 24x7 monitoring, detection engineering, escalation, and incident response; maintain enough hands-on fluency with the SIEM to validate detections, review alerts, and support active investigations when required.
  • Direct threat and vulnerability management, including scanning, prioritization, remediation governance, patch SLAs, penetration testing, attack surface management, and executive risk reporting.
  • Partner with Legal and Procurement as a key security stakeholder in Third Party Risk Management, including vendor due diligence, contract security requirements, AI and SaaS provider reviews, control assessments, ongoing monitoring, and remediation tracking.
  • Review and approve security designs for new technology initiatives, AI-enabled capabilities, cloud services, store technology, payment systems, and major vendor platforms before production deployment.
  • Lead enterprise incident response planning, crisis coordination, tabletop exercises, post-incident reviews, and communications with executive, legal, operational, and technical stakeholders.
  • Partner with Internal Audit on control testing, evidence, and remediation while maintaining appropriate independence and avoiding self-audit.
  • Recruit, lead, coach, and develop a high-performing security team; establish clear ownership, operating rhythms, performance expectations, and career paths.
  • Own the security budget, tooling roadmap, vendor portfolio, managed service relationships, SLAs, renewals, and investment recommendations, including cost governance for emerging security and AI-related capabilities.
  • Communicate security risk clearly from analyst to Board level, translating technical issues into business impact, risk decisions, and actionable priorities.

Required Experience & Qualifications

  • Bachelor's degree in Information Systems, Computer Science, Cybersecurity, or equivalent work experience.
  • 10+ years of progressive experience in information security, cybersecurity, technology risk, or a closely related area, including significant enterprise security leadership responsibility.
  • Demonstrated ability to operate as the senior security leader for a complex enterprise; retail, omnichannel, e-commerce, payment, or large distributed operating environment experience preferred.
  • Demonstrated proficiency with the NIST Cybersecurity Framework (CSF), including program design, maturity assessment, control mapping, remediation planning, and executive reporting.
  • Direct, accountable experience owning PCI-DSS in a merchant, e-commerce, payment, or retail environment.
  • Deep technical expertise across application security, network security, cloud and infrastructure security, endpoint security, identity and access management, vulnerability management, AI security governance, and security operations.
  • Ability to serve as the enterprise authority on securing AI-enabled tools, platforms, and workflows, with practical command of policy, administration, data protection, technical guardrails, monitoring, vendor governance, and cost-aware usage controls.
  • Familiarity with Google Cloud Platform (GCP) and Google Workspace environments, including administrative models, IAM, logging, data protection, and security configuration considerations.
  • Hands-on working proficiency with a major SIEM/SOC platform; Palo Alto XSIAM experience strongly preferred.
  • Proven incident response leadership, including high-severity security events, executive communications, tabletop exercises, post-incident reviews, and continuous improvement.
  • Experience leading and developing security teams, managed service providers, and cross-functional programs across Technology, Legal, Procurement, Internal Audit, and business stakeholders.
  • Experience presenting cybersecurity posture, risk, and investment recommendations to executive leadership, Audit Committee, or Board-level audiences.
  • CISSP or equivalent senior security credential required; CISM, CISA, CCSP, GIAC, or similar credentials are also valued.

Critical Skills & Attributes

  • CISO-level judgment and executive presence while operating effectively within a Director-level role.
  • Technically credible and current; able to challenge architecture, read SIEM detections, question control gaps, evaluate AI security risks, and contribute to investigations without displacing the team.
  • Strong AI security judgment; enables business use while enforcing administrative, technical, data, monitoring, and financial guardrails that are practical for a retail operating environment.
  • Strategic and pragmatic; balances risk reduction, customer trust, business speed, cost, and operational resilience.
  • Calm and decisive under pressure, especially during active incidents, peak retail periods, major releases, and audit/compliance cycles.
  • Strong communicator who can translate technical risk into business decisions for executives, Board members, auditors, attorneys, merchants, and engineers.
  • High ownership mindset; accountable for outcomes, not just recommendations.
  • Strong discretion, integrity, and judgment when handling sensitive security, legal, personnel, and incident information.
Vacancy posted 3 days ago
Similar jobs that could be interesting for youBased on the Director Information Security & Governance in Columbus, OH vacancy
  •  ...traditional retail, Bonobos is something you haven't seen before. Responsibilities POSITION OVERVIEW The Director, Information Security & Governance serves as Phoenix Retail’s senior information security leader, with enterprise-wide accountability for the... 
    Suggested
    Full time
    Contract work
    Work experience placement
    H1b
    Worldwide
    Visa sponsorship
    Work visa

    Express

    Columbus, OH
    3 days ago
  • $83k - $93k

     ...the Position Cologix is seeking a Security Manager to lead physical security operations...  ...for the performance, consistency, and governance of security operations, ensuring a...  ...disclosure, and deletion of consumers' personal information. The CCPA requires businesses to... 
    Suggested
    Full time
    Contract work
    Temporary work
    Local area
    Work visa
    Flexible hours

    Cologix

    Columbus, OH
    4 days ago
  • $91.4k - $187k

     ...Federal Consulting team seeks a Director of Delivery & Operations to...  ...risk early through gateway, governance, adoption, and readiness...  ...issue resolution across IT, security, finance, deal desk, and delivery...  ....** **Range and benefit information provided in this posting are... 
    Suggested
    Temporary work
    Work experience placement
    Work at office
    Flexible hours

    Oracle

    Columbus, OH
    2 days ago
  • $123.4k - $193.93k

    The Manager, Information Security & Risk (Purple Team) leads the organization’s adversarial testing, attack simulation, and detection validation...  ...into risk-informed decisions. Operational Excellence & Governance Establish repeatable, well-governed processes for... 
    Suggested
    Temporary work
    Local area
    Immediate start
    Flexible hours

    Cardinal Health

    Columbus, OH
    3 days ago
  •  ...Hospital Pharmacy Residency or equivalent experience preferred INFORMATION SECURITY Maintains confidentiality of log-on password(s) and security...  ...address or respond to findings. 10% Assists the department director in developing the department operating budget and monitoring... 
    Suggested
    Shift work

    Berger Health System

    Columbus, OH
    2 days ago
  • Global Security | Technical Security Product Delivery Manager, Vice President As a Product Delivery Manager in Global Security, you will...  .... Preferred Qualifications Relevant experience in information security or technology controls. Experience managing, implementing... 
    Work at office
    Monday to Friday
    Weekend work
    Afternoon shift

    JPMorgan Chase

    Columbus, OH
    2 days ago
  • $87.5k - $115k

     ...FCC rules and regulations. Manage compliance with critical security policies, including account, password security, vulnerability...  ...affiliation, military or veteran status, citizenship status, genetic information, or any other basis protected by federal, state or local law.... 
    Full time
    Temporary work
    Part time
    Local area

    TEGNA

    Columbus, OH
    22 hours ago
  •  ...processing, strengthen resolution operations and payroll data governance, and partner across teams to deliver automation and process...  ...health, or physical disability needs. Visit our FAQs for more information about requesting an accommodation. JPMorgan Chase & Co. is an... 
    Local area

    JPMorganChase

    Columbus, OH
    3 days ago
  •  ...how marketing work gets done. With a strong focus on financial governance and process optimization, the Marketing Operations Manager...  ...reports to ensure leadership and stakeholders are consistently informed on advertising-related initiatives and impact • Process improvement... 
    Work at office
    Local area

    Safelite Group, Inc.

    Columbus, OH
    22 hours ago
  • $170.6k - $390k

     ...practice – the best place in the world to grow your career in information security! The opportunity The Senior Network Security...  ...technical leader responsible for designing, implementing, and governing secure network architectures across the enterprise. This role... 
    Summer holiday
    Remote work
    Flexible hours

    EY

    Columbus, OH
    22 hours ago
  • $70.1k - $91.6k

    The Chronicle Of Higher Education, Inc. seeks an Assistant Director for the Center on Responsible AI and Governance (CRAIG) at The Ohio State University in Columbus, OH. This role involves assisting with strategic planning, fundraising, and managing relationships with... 

    The Chronicle Of Higher Education, Inc.

    Columbus, OH
    1 day ago
  •  ...Association to provide strategic oversight for community associations. You will ensure excellence in operations, financial management, and governance while serving as a trusted advisor to boards. The ideal candidate has over 5 years of progressive experience in community... 

    Collective-House-Realty

    Columbus, OH
    1 day ago
  • $160.1k - $240.1k

    Job Summary The Director of Enterprise Data Operations leads NiSource...  ...-to-end data operating model—governing, enabling, and running the...  ...value while maintaining strong security and compliance. Strategy &...  ...utilities and broader industry to inform roadmap, standards, and... 

    012 NiSource Corporate Services Co

    Columbus, OH
    4 days ago
  •  ...Director, Security Compliance Known for being a great place to work and build a career, KPMG provides audit, tax and advisory services...  ...comprehensive specialist-level knowledge of risk, compliance, and information security controls to develop and execute a multi-... 
    Temporary work
    H1b
    Local area

    Kpmg India

    Columbus, OH
    4 days ago
  • $64k - $65k

    Data Center Security Officer Pay Range: $64,000-65,000 annually Why Join Securitas? Weekly Pay: Get paid every week! Career Growth Opportunities...  ...For Critical Thinkers: Ability to assess situations and make informed decisions. Observant: Diligent in monitoring and assessing... 
    Weekly pay
    Shift work
    Weekend work

    Securitas Security Services USA, Inc.

    Columbus, OH
    1 day ago
  • 012 NiSource Corporate Services Co in Columbus, Ohio is seeking a Director of Enterprise Data Operations. This role involves leading the data governance framework and cloud data strategy, ensuring high-quality data availability for analytics. You will establish service... 

    012 NiSource Corporate Services Co

    Columbus, OH
    4 days ago
  • $64k - $65k

     ...Data Center Security Officer   Pay Range: $64,000-65,000/ annually   Why Join Securitas? Weekly Pay: Get paid every week! Career...  ...: Critical Thinkers: Ability to assess situations and make informed decisions. Observant: Diligent in monitoring and assessing... 
    Weekly pay
    Local area
    Shift work
    Weekend work

    Securitas

    Columbus, OH
    22 hours ago
  • $130k - $140k

     ...Description Role: Manager, Security Operations Location:...  ...Operations Reports to: Senior Director, Security Operations Role...  ...the operational delivery, governance, and assurance of...  ...annual incentive program, and information on benefits offered is here.... 
    Full time

    Pearson

    Columbus, OH
    4 days ago
  • Fairygodboss is seeking a strategic leader in network security to define and execute a multi-year product strategy. You'll influence executive stakeholders while overseeing a team managing complex security solutions. The ideal candidate will have 10+ years of experience... 

    Fairygodboss

    Columbus, OH
    1 day ago
  • Shape the future of network security at one of the world's most complex and consequential technology environments. This is your opportunity...  ...within large, complex enterprise technology environments and governance frameworks Background in security engineering or architecture... 

    Fairygodboss

    Columbus, OH
    1 day ago
  • Newcomer Funeral Service Group in Columbus, Ohio, is seeking a licensed Funeral Director In Charge to lead daily operations at one of its funeral homes. This role requires strong leadership, exceptional communication skills, and a commitment to compassionate service. Responsibilities... 

    Newcomer Funeral Service Group

    Columbus, OH
    1 day ago
  • A leading data security company is seeking a personable Account Manager based near Columbus, Ohio. The role involves selling and presenting products to enterprise accounts, managing client relationships, and achieving sales quotas. The ideal candidate has over 5 years... 

    Varonis

    Columbus, OH
    22 hours ago
  •  ...Global Security Manager (NJUS) Company: QS Security Services LLC Area of Interest: Security Location: Columbus, OH, US, 43219 Req...  ...compliance with security standards Education: Bachelor's in Information Technology or related field Certifications and Licenses:... 
    Temporary work
    For contractors
    Flexible hours

    NetJets

    Columbus, OH
    4 days ago
  •  ...the Cloud Solutions Team. This leader will design and execute a secure AWS ecosystem supporting pediatric research and will be...  ...in a relevant field and three years of experience in hospital information systems management. The ideal candidate will have exceptional... 

    Nationwide-Children

    Columbus, OH
    1 day ago
  •  ...tech-driven, and performance-focused Strong compensation + clear growth path Long-term stability - multi-year contract already secured What you’ll do As an Operations Supervisor, you’ll lead daily warehouse operations while driving performance,... 
    Long term contract

    RemX

    Columbus, OH
    4 days ago
  • $130k - $140k

    Pearson is seeking a Manager, Security Operations to oversee cybersecurity services for government and regulated clients. This pivotal role involves acting as the primary point of accountability to ensure compliance with contractual and regulatory obligations. Responsibilities... 

    Pearson

    Columbus, OH
    1 day ago
  • Cardinal Health is seeking a Director of Application Security to lead the application security strategy across various segments, ensuring effective risk management and compliance in the development lifecycle. This role involves collaborating with teams on security practices... 
    Remote job

    Cardinal Health

    Dublin, OH
    22 hours ago
  • $125k - $175k

     ...appropriate, and employ advanced organizational tools and methods. Communication: Can effectively communicate complex ideas and information to diverse audiences and can facilitate effective communication between others. Presentation: Can design and deliver engaging presentations... 
    Worldwide
    Flexible hours

    SHI

    Columbus, OH
    22 hours ago
  • ## Director, Application Security (Cybersecurity Defense)Applylocations: US-Nationwide-FIELDtime type: Full timeposted on: Posted Todayjob requisition...  ...Commercial Technology environments, enabling consistent governance, scalable processes, and effective risk mitigation across... 
    Temporary work
    Local area
    Immediate start
    Remote work
    Flexible hours

    Cardinal Health

    Dublin, OH
    22 hours ago
  • $135.4k - $208.1k

    Hobbsnews is seeking a Director of Application Security to lead the enterprise application security strategy while ensuring alignment with cybersecurity...  ...security and the ability to establish strong governance frameworks within the software development lifecycle. The... 
    Remote job

    Hobbsnews

    Dublin, OH
    4 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Director Information Security & Governance. Be the first to apply!