Director OF Information Security
$212.4kErnst & Young Advisory Services Sdn Bhd
Global Lead Security Compliance & Enforcement - Director Other locations: Anywhere in Country Date: Aug 31, 2026 Requisition ID: 1738358 At EY, we’re all in to shape your future with confidence. We’ll help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go. Join EY and help to build a better working world. The opportunity The Global Lead Security Compliance & Enforcement owns the strategy, operating model, and outcomes for the global Security Compliance function within Technology Assurance, Risk & Policy. The role transforms Security Compliance into a proactive, intelligence-driven, and enforcement-capable organization that reduces risk debt, sustains critical governance, risk, and compliance operations and provides defensible, audit-ready governance. The Director creates clear global accountability for security compliance and converts fragmented or ambiguous risk situations into prioritized action. Using policy, compliance-posture data, risk appetite, escalation protocols, and executive decision forums, the role addresses situations in which ownership, remediation capacity, enforcement authority, or risk tolerance are unclear. This includes clearing persistent enforcement backlogs, sequencing scarce specialist capacity across concurrent initiatives, expanding control monitoring, resolving technology-lifecycle exposure, and establishing governance for frontier AI and DataGuard obligations. Working with CTOs, Service Line Quality Leaders, Technology Risk & Compliance, Information Security leadership, risk and control owners, technology teams, and audit and governance stakeholders, the Director balances policy requirements with business impact, technology delivery, client confidence, and documented risk acceptance. The role sets the multi-year roadmap, leads a globally distributed organization, and provides senior leaders with decision-quality information on compliance posture, risk trends, enforcement, and remediation. Key Responsibilities Strategic Leadership Define and execute the global Security Compliance strategy, target operating model, multi-year roadmap, priorities, performance measures, and resource plan in alignment with risk appetite and business objectives. Lead and develop a globally distributed, capability-led organization that proactively addresses the highest-risk exposures while sustaining business-as-usual GRC operations and talent succession. Compliance Governance & Enforcement Own global policy compliance and the Non-Compliance Consequence Framework, including consistent enforcement, escalation, investigation, corrective action, backlog reduction, and documented risk acceptance. Build data-driven risk intelligence and expand control monitoring and assurance through clear evidence, metrics, trends, dashboards, executive reporting, and risk burn-down tracking. Direct remediation and technology-lifecycle governance, including out-of-SLA vulnerability triage, End-of-Life exposure, exceptions, and emerging AI and DataGuard obligations. AI Governance & Emerging Technologies Establish compliance governance, monitoring, accountability, and reporting for frontier AI, DataGuard, and other emerging-technology obligations. Stakeholder & Executive Engagement Partner with CTOs, Service Line Quality Leaders, risk, security, audit, governance, and technology teams to balance policy, business impact, client confidence, and delivery, while advancing automation and continuous improvement. Supervision Responsibilities The Director reports to the Global Leader, Technology Assurance, Risk & Policy within Information Security and leads the global Security Compliance function. Knowledge and Skills Requirements Deep knowledge of cyber security, technology and data risk, policy compliance, control assurance, GRC operations, enterprise remediation, exception governance, and risk acceptance. Practical understanding of ISO 27001/27002, ISO 31000, COBIT, unified compliance frameworks, audit expectations, and enterprise control obligations. Ability to translate technical exposure and compliance data into business risk, executive action, documented decisions, and measurable risk reduction. Proven capability to design and lead global operating models, portfolio governance, monitoring, evidence, metrics, dashboards, executive reporting, and automation enablement. Strong judgment in enforcement, escalation, corrective action, remediation prioritization, business continuity, and allocation of scarce specialist capacity in a matrixed organization. Executive communication and stakeholder partnership skills across senior leaders, client-serving teams, technology delivery, risk and control owners, audit, and governance forums. Job Requirements Demonstrated ability to lead a global security compliance, technology risk, control assurance, or GRC function of comparable complexity and strategic scope. Demonstrated experience resolving complex cross-functional issues through data, policy, risk appetite, escalation protocols, and executive decision forums. Experience establishing priorities and measurable outcomes, managing a portfolio of concurrent initiatives, and allocating specialist capacity while continuous operations remain active. Experience directing policy-compliance enforcement, non-compliance remediation, control monitoring, technology-lifecycle risk, exception governance, and risk-acceptance processes. Ability to engage directly with executive technology, quality, risk, security, service-line, audit, and governance stakeholders and present compliance posture, trends, and remediation progress. Ability to lead distributed teams, coach leaders and staff, align responsibilities and objectives to capability, and develop succession and talent strategies. Education and Certification Requirements A relevant educational background in cyber security, information security, technology risk, IT or data risk management, governance, compliance, or a related discipline is expected. Relevant professional certifications in information security, technology risk, governance, audit, or compliance are preferred, particularly credentials aligned with ISO 27001/27002, ISO 31000, COBIT, or unified compliance frameworks. Experience Requirements A minimum of 12 years of professional experience is required in complex, enterprise-scale security compliance, technology risk, policy, control assurance, GRC operations, or remediation environments. Candidates should demonstrate experience leading distributed teams and capability leaders, operating in a matrixed global organization, advising senior executives, transforming operating models, managing enforcement and escalation, expanding monitoring and assurance, and converting ambiguous cross-functional risks into prioritized remediation or documented risk acceptance. What we offer you The compensation ranges below are providedin order to comply with United States pay transparency laws. Other geographies will follow their local salary guidelines, which may not be a direct conversion of published US salary ranges. At EY, we’ll develop you with future-focused skills and equip you with world-class experiences. We’ll empower you in a flexible environment, and fuel you and your extraordinary talents in a diverse and inclusive culture of globally connected teams. Learnmore . We offer a comprehensive compensation and benefits package where you’ll be rewarded based on your performance and recognized for the value you bring to the business. The base salary range for this job in all geographic locations in the US is $212,400 to $443,900. The base salary range for New York City Metro Area, Washington State and California (excluding Sacramento) is $254,900 to $504,500. Individual salaries within those ranges are determined through a wide variety of factors including but not limited to education, experience, knowledge, skills and geography. In addition, our Total Rewards package includes medical and dental coverage, pension and 401(k) plans, and a wide range of paid time off options. Join us in our team-led and leader-enabled hybrid model. Our expectation is for most people in external, client serving roles to work together in person 40-60% of the time over the course of an engagement, project or year. Under our flexible vacation policy, you’ll decide how much vacation time you need based on your own personal circumstances. You’ll also be granted time off for designated EY Paid Holidays, Winter/Summer breaks, Personal/Family Care, and other leaves of absence when needed to support your physical, financial, and emotional well-being. EY focuses on high-ethical standards and integrity among its employees and expects all candidates to demonstrate these qualities. EY | Building a better working world EY is building a better working world by creating new value for clients, people, society and the planet, while building trust in capital markets. Enabled by data, AI and advanced technology, EY teams help clients shape the future with confidence and develop answers for the most pressing issues of today and tomorrow. EY teams work across a full spectrum of services in assurance, consulting, tax, strategy and transactions. Fueled by sector insights, a globally connected, multi-disciplinary network and diverse ecosystem partners, EY teams can provide services in more than 150 countries and territories. EY provides equal employment opportunities to applicants and employees without regard to race, color, religion, age, sex, sexual orientation, gender identity/expression, pregnancy, genetic information,national origin, protected veteran status, disability status, or any other legally protected basis, including arrest and conviction records, in accordance with applicable law. EY is committed to providing reasonable accommodation to qualified individuals with disabilities including veterans with disabilities. If you have a disability and either need assistance applying online or need to request an accommodation during any part of the application process, please call 1-800-EY-HELP3, select Option 2 for candidate related inquiries, then select Option 1 for candidate queries and finally select Option 2 for candidates with an inquiry which will route you to EY’s Talent Shared Services Team (TSS) or email the TSS at View email address on click.appcast.io . Nearest Major Market: New York City Nearest Secondary Market: Newark EY refers to the global organization, and may refer to one or more, of the member firms of Ernst & Young Global Limited, each of which is a separate legal entity. Ernst & Young Global Limited, a UK company limited by guarantee, does not provide services to clients. #J-18808-Ljbffr
- ...ViiV Healthcare in Durham, NC seeks a Director of Access Strategy – HIV Prevention to shape US market access for HIV prevention medicines. You will oversee payer engagement, pricing narratives, and cross-functional alignment with strategic pricing and reimbursement teams...SuggestedRelocation
- ...Optiv is seeking a Regional Director of Cybersecurity to lead a sales team in the South Central region. This remote role, Texas-based,... ...strong pipeline with accurate forecasts. You will recruit and coach security sales professionals, develop territory plans, and partner with...SuggestedRemote work
- ...U.S. Bank is seeking a Director of Security Configuration Automation & Engineering to define and execute strategy across the enterprise. You... ...and enable secure operations at scale. As a member of the Information Security Posture and Configuration Management leadership team...Suggested
- ...Clover Health is seeking a Director of Governance, Risk, and Compliance (GRC) to define and execute security governance and risk strategy for a public, technology-enabled healthcare company. The role leads enterprise-level governance, risk decisions, and compliance readiness...Suggested
- ...enterprise Identity and Access Management (IAM) program to ensure secure, reliable, and compliant access to critical business systems,... ...initiatives. Collaborates with enterprise architecture, information security, infrastructure, and application development teams to...SuggestedFull timeContract workLocal areaWorldwide
$65k - $70k
JOB SUMMARY The Director of Security serves as the key point of contact for the JCC and provides strategic direction and leadership for... ...experience with discreet handling of sensitive and confidential information. WHAT YOU’LL DO Directs or completes tasks associated...Contract workWork at officeLocal areaWeekend workAfternoon shift$74k - $77k
...parenting support and support to young adults. Position: Director of Security and Operation Reports To: Vice President Location:... ...the security and privacy of individually identifiable health information. Understand all aspects of contract requirements and communicate...Permanent employmentFull timeContract workImmediate start- Concentra, Inc. in Addison, TX, seeks a Director of Security - GRC to lead governance, risk management, and compliance across the enterprise. The role requires deep knowledge of regulatory frameworks, cloud and SaaS environments, and third-party risk management. You will...
- Director of Safety and Security JobID: 2155 Reports to Superintendent Position Type: Administration Date Posted: 8/31/2026 Location: Various... ...administrators and maintains statistics regarding this information Secures facilities, equipment, students and personnel by...Local area
$306k - $360k
At Asana, security is foundational to our mission of helping teams work together effortlessly... ...trust at scale. We are seeking a Director of Security Engineering to lead and grow... ...requirements with business needs, making risk-informed decisions, and communicating the "why"...Work at officeLocal areaWork from home- Sequencing Inc. is seeking a Director of Security to develop and oversee a comprehensive security program for its genomics and AI platform. This director-level role involves managing compliance initiatives, including HIPAA and SOC 2, and combating threats to sensitive...Remote job
$163.4k - $322.1k
...with resilience, grow with confidence, and proactively manage to secure success. Recruiting for this role ends on 12/31/2026. Work you... ...: Bachelor's degree in Computer Science, Cybersecurity, Information Technology, Engineering, or a related fieldMaster's degree in...Work at officeLocal areaVisa sponsorship- Join a high-impact product team shaping how customers securely access digital experiences every day. You’ll grow your product craft while... ...health or physical disability needs. Visit our FAQs for more information about requesting an accommodation.Equal Opportunity Employer/...Work visa
$134.5k - $265.1k
...with resilience, grow with confidence, and proactively manage to secure success. Recruiting for this role ends on 12/31/2026. Work you... ...of Science degree in Computer Science, Cyber Security, Information Security, Engineering, or Information TechnologyPrevious consulting...Local areaVisa sponsorship$143k - $210k
...in March 2025. Learn more at .What You’ll Do:The Data Center Security organization at CoreWeave is responsible for protecting our global... ...gender identity, national origin, veteran status, or genetic information.As part of this commitment and consistent with the Americans...Permanent employmentFull timeContract workTemporary workFor contractorsCasual workWork at officeFlexible hours- ...continue to scale our platform and enterprise customer base, security has become a strategic differentiator. We're looking for a leader... ...15+ years of progressive experience in cybersecurity, information security, cloud security, or infrastructure security. 5+ years...Full timeWork at officeRemote workFlexible hours2 days per week
- ...ultimate goal is to build perfect search over all the world’s information, far beyond Google. If you want to build massive-scale ML systems... ...the place for you. What You’ll Own Define Exa’s company-wide security strategy, operating model, risk framework, and multiyear...H1b
$250k - $330k
...—and for your life outside it. Our employee NPS sits in the high 80s. We move billions of dollars through our systems. That makes security existential, and it's why we're making our first dedicated security hire. About the role You’ll be our first Head of Security. There...Remote workWorldwideShift work- ...Global Security | Technical Security Product Delivery Manager, Vice President As a Product Delivery Manager in Global Security, you... ...skills and capabilities Relevant experience in information security or technology controls. Experience managing, implementing...Work at officeMonday to FridayWeekend workAfternoon shift
$159.1k - $265.1k
...clients understand, analyze, and respond to various business opportunities and challenges.Work you’ll doAs a Manager on the Complex Securities team, you will be responsible for:Supporting Deloitte audit teams and non-audit clients with valuation analyses for complex...- Tremendous is seeking its first Head of Security to own the company’s security posture end‑to‑end. You will work closely with engineering on production infrastructure, code security, and incident response, while shaping policy and vendor security. This is a hands-on leadership...Remote job
- Forward Financing is seeking a Manager, Security Operations to defend our infrastructure, SaaS, and endpoints by building and leading a team of security engineers. You will drive AI security strategy, incident response, and risk assessments while collaborating with cross...Remote work
$109.37k - $123.04k
## Senior Manager, IT Security OperationsApplylocations: Washington, DC: New York, NYtime... ...integrity and confidentiality of sensitive information, and maintaining the overall security... ...Partner with Chief Technology Officer, Senior Director of Information Technology, and Virtual...Work experience placementWork at officeLocal areaRemote work- Data Science & Engineering Experts, Inc. is seeking a full-time Head of AI Security for a 100% remote role in the United States. You will own security strategy and execution for AI products, cloud environments, model and tool integrations, and customer-facing security...Remote jobFull time
$90 - $95 per hour
Senior Program Manager (Security Systems Access Control Migration)Location: Jersey City, NJ or Houston, TX Pay: $90-95/hrThe role will... ...Qualifications:Bachelor's degree in business administration, Information Systems, Computer Science, or another related field10 years of...- American Dream is seeking a Security Director in East Rutherford, NJ to lead the security and safety program for a premier shopping center. You will shape policies, procedures, and post orders, and oversee all security operations including patrols, CCTV, access control,...
- At NiCE, we don’t limit our challenges. We challenge our limits. Always. We’re ambitious. We’re game changers. And we play to win. We set the highest standards and execute beyond them. And if you’re like us, we can offer you the ultimate career opportunity that will light...
$40 per hour
...that’s exactly what you’ll do every time you come to work! As a Director of Operations, you’re not just directing daily hotel operations... ...of health plans that keep you and your family coveredFinancial security for your future - Our retirement plans make it easier to save...WorldwideNight shift$165k - $175k
...operational excellence, CoreSite is a place to make an impact. Director of Security Programs Role: As a member of the Data Center Operations... ...to protecting the privacy and security of personal information submitted by applicants. The California Consumer Privacy Act...Full timeContract workFor contractorsWork at officeVisa sponsorshipWork visa2 days per week$85k - $95k
...Security Manager Brooklyn, New York, United States Fairstead is a purpose-driven real estate firm dedicated to building affordable... ...Security Manager provides strategy and activities related to information security and physical security of the property(s). The...Work at officeImmediate startAll shiftsFlexible hoursShift work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Director OF Information Security. Be the first to apply!


