Director, Information Security
Centric Brands Inc.
About Us Centric Brands is a leading lifestyle brand collective that designs, sources, markets and sells high quality products in multiple segments, including women's, men's and kid's apparel, accessories, entertainment and beauty. Centric Brands is focused on our customers and our brands that will drive the company's future growth. We are defined by innovation as we seize new opportunities and thrive in an environment informed by creativity and thinking that is both analytical and outside the box. Centric Brands reflects a team built on respect, for others and for the hard work it takes to achieve our goals and build our bright future together. Specific Responsibilities Would Include Position Overview
The Director of Information Security is responsible for developing and executing Centric Brands' enterprise cybersecurity strategy, protecting company information assets, and reducing cyber risk across the global business. This role leads security operations, governance, compliance, incident response, and emerging technology security programs while partnering with business and technology leaders to enable secure growth.
This position will be based in Greensboro, NC. It will follow a hybrid work schedule of Monday-Thursday in office with Friday being a remote work day. This schedule is subject to change based on business needs. Responsibilities Strategy, Governance, and Executive Leadership
• Provide strategic leadership for, and develop, implement, and operate, a company-wide information security program.
• Advise senior leadership on security program direction and resource investment.
• Develop and manage the information security budget, aligning investments with risk priorities.
• Report regularly to executive leadership on security posture, risk reduction, incident readiness, and program maturity against defined KPIs.
• Manage and facilitate global information security governance processes.
• Establish annual and long-range security and compliance goals, define security strategies, metrics, reporting mechanisms and program services; and create maturity models and a roadmap for continual program improvements.
• Stay abreast of information security issues and regulatory changes affecting consumer goods, retail and trade at the state, national and global levels, participate in policy and practice discussions, and communicate to leadership on a regular basis about those topics.
• Engage in professional development to maintain continual growth in professional skills and knowledge essential to the position. Team Leadership
• Mentor/Coach the Information Security Office team members and implement professional development plans for team members. Communicate clear goals and objectives.
• Partner with infrastructure, network, cloud, application, and end-user computing teams to implement and maintain enterprise security standards and controls. Policy, Compliance, and Audit
• Lead the development and implementation of effective and reasonable policies and practices to secure protected and sensitive data and ensure information security and compliance with relevant legislation and legal interpretation.
• Coordinate and track all information technology and security related audits including scope of audits, timelines, auditing agencies and outcomes. Work with auditors as appropriate to keep audit focus in scope, maintain excellent relationships with audit entities and provide a consistent perspective that continually puts the company in its best light.
• Provide guidance, evaluation and advocacy on audit responses.
• Work with leadership and relevant responsible compliance department leadership to build cohesive security and compliance programs for the company to effectively address global statutory and regulatory requirements.
• Develop a strategy for dealing with increasing number of audits, compliance checks and external assessment processes for internal/external auditors, PCI, CCPA, and GDPR.
• Support Legal Discovery requests when required. Security Awareness and Training
• Work closely with IT leaders, technical experts and various leaders on a wide variety of security issues that require an in-depth understanding of the IT environment in their units.
• Create education and awareness programs and advise operating units at all levels on security issues, best practices, and vulnerabilities.
• Pursue employee-focused security initiatives addressing phishing, social engineering, and identity protection. Incident Response and Resilience
• Keep abreast of security incidents and act as primary control point during significant information security incidents. Convene a Security Incident Response Team (SIRT) as needed, or requested, in addressing and investigating security incidents that arise.
• Own and maintain the company's incident response plan, including playbooks and regular tabletop exercises with business stakeholders.
• Convene Ad Hoc Security Committee as appropriate and provide leadership for breach response and notification actions for the company.
• Partner with IT and business leaders to develop and test business continuity, disaster recovery, and cyber resilience plans. Risk Management and Third-Party Risk
• Establish and oversee a third-party risk management program, including security assessments of vendors, licensing partners, and key service providers.
• Provide leadership, direction and guidance in assessing and evaluating information security risks and monitor compliance with security standards and appropriate policies.
• Support cyber insurance renewals, security questionnaires, and claims coordination. Security Operations and Engineering
• Develop, implement and administer technical security standards, as well as a suite of security services and tools to address and mitigate security risk.
• Establish and oversee a vulnerability management program, including scanning, penetration testing, and remediation tracking.
• Oversee day-to-day security operations, including MDR/SOC partner management, security monitoring and detection, threat intelligence, and endpoint and email security.
• Set direction for cloud security posture and zero-trust architecture in partnership with infrastructure and application teams.
• Establish governance for identity and access management, including privileged access controls and periodic access reviews.
• Examine impacts of new technologies on the company's overall information security. Establish processes to review implementation of new technologies to ensure security compliance.
• Establish governance, risk management, and security standards for artificial intelligence (AI), generative AI, machine learning, and automation technologies. Partner with business and technology leaders to enable responsible and secure adoption of AI solutions across the enterprise.
Our Best Fit Candidate Would Have Skills and Requirements • Bachelor's degree in Information Systems, Computer Science, or related field required.
• CISSP, CISM, or equivalent security certification strongly preferred.
• Minimum of 10 years' experience in information security, including 5+ years leading security teams or programs.
• Experience presenting security posture, risk, and program metrics to executive leadership.
• Experience leading global security programs; retail, consumer goods, or manufacturing industry experience a plus.
• Excellent communication skills - both written and verbal.
• Exceptional, hands-on leader with a style that is engaging, innovative, and collaborative.
• Ability to be flexible, work under pressure and tight deadlines.
• Ability to travel as needed; once per quarter.
• Ability and availability to work occasional nights and weekends.
• Experience with Fortinet/FortiGate/Forticlient, Crowdstrike MDR/EDR, BitLocker, File Vault, MS Defender, and Azure Security services is a plus.
In return, we provide an industry-competitive salary, along with a comprehensive benefits plan (medical, dental, vision) that includes a matching 401(k), Summer Fridays, generous PTO, merchandise discounts, excellent career development opportunities, and a work environment that reflects our industry leadership. Our social impact program, Centric Cares, focuses on volunteerism to make a difference in communities we live and work in and our D&I committee is shaping the future of diversity, equity and inclusion at Centric Brands though workshops, resources and inspiring conversation. At Centric Brands, we believe our people are our greatest asset, and we seek to structure competitive compensation offers to ensure that we are able to attract and retain the best talent. Our job postings include an annual base salary range at the time of employment. The stated base salary range represents our good faith estimate as to what candidates are likely to expect, and we tailor our offers within the range based on several factors, including the selected candidate's educational and professional experience, industry knowledge, location, technical and communication skills, and other factors that may prove relevant during the selection process. Base salary is a part of a total compensation package, which, depending on the position, may also include commission earnings, annual bonus and other Centric Brands sponsored benefit programs. Be part of our growing community by getting involved with groups, teams and initiatives like Be Green, Be Giving, and Be Celebrated. Centric Brands is an Equal Opportunity Employer Please note that Centric Brands will only reach out to interview, make an offer of employment or conduct onboarding activities for candidates who have applied through our careers site. When interviewing for a position, the candidate experience will include live interaction, such as a video conference or telephone call, with a Recruiter and/or company employee(s). We will never ask for any money or payments from applicants at any point in the recruitment process. Be aware of suspicious recruitment activity. If you think you are a victim of an employment scam, you may contact your local law enforcement agency and/or visit the Federal Trade Commission website here: #LI-KW1 #LI-Hybrid
The Director of Information Security is responsible for developing and executing Centric Brands' enterprise cybersecurity strategy, protecting company information assets, and reducing cyber risk across the global business. This role leads security operations, governance, compliance, incident response, and emerging technology security programs while partnering with business and technology leaders to enable secure growth.
This position will be based in Greensboro, NC. It will follow a hybrid work schedule of Monday-Thursday in office with Friday being a remote work day. This schedule is subject to change based on business needs. Responsibilities Strategy, Governance, and Executive Leadership
• Provide strategic leadership for, and develop, implement, and operate, a company-wide information security program.
• Advise senior leadership on security program direction and resource investment.
• Develop and manage the information security budget, aligning investments with risk priorities.
• Report regularly to executive leadership on security posture, risk reduction, incident readiness, and program maturity against defined KPIs.
• Manage and facilitate global information security governance processes.
• Establish annual and long-range security and compliance goals, define security strategies, metrics, reporting mechanisms and program services; and create maturity models and a roadmap for continual program improvements.
• Stay abreast of information security issues and regulatory changes affecting consumer goods, retail and trade at the state, national and global levels, participate in policy and practice discussions, and communicate to leadership on a regular basis about those topics.
• Engage in professional development to maintain continual growth in professional skills and knowledge essential to the position. Team Leadership
• Mentor/Coach the Information Security Office team members and implement professional development plans for team members. Communicate clear goals and objectives.
• Partner with infrastructure, network, cloud, application, and end-user computing teams to implement and maintain enterprise security standards and controls. Policy, Compliance, and Audit
• Lead the development and implementation of effective and reasonable policies and practices to secure protected and sensitive data and ensure information security and compliance with relevant legislation and legal interpretation.
• Coordinate and track all information technology and security related audits including scope of audits, timelines, auditing agencies and outcomes. Work with auditors as appropriate to keep audit focus in scope, maintain excellent relationships with audit entities and provide a consistent perspective that continually puts the company in its best light.
• Provide guidance, evaluation and advocacy on audit responses.
• Work with leadership and relevant responsible compliance department leadership to build cohesive security and compliance programs for the company to effectively address global statutory and regulatory requirements.
• Develop a strategy for dealing with increasing number of audits, compliance checks and external assessment processes for internal/external auditors, PCI, CCPA, and GDPR.
• Support Legal Discovery requests when required. Security Awareness and Training
• Work closely with IT leaders, technical experts and various leaders on a wide variety of security issues that require an in-depth understanding of the IT environment in their units.
• Create education and awareness programs and advise operating units at all levels on security issues, best practices, and vulnerabilities.
• Pursue employee-focused security initiatives addressing phishing, social engineering, and identity protection. Incident Response and Resilience
• Keep abreast of security incidents and act as primary control point during significant information security incidents. Convene a Security Incident Response Team (SIRT) as needed, or requested, in addressing and investigating security incidents that arise.
• Own and maintain the company's incident response plan, including playbooks and regular tabletop exercises with business stakeholders.
• Convene Ad Hoc Security Committee as appropriate and provide leadership for breach response and notification actions for the company.
• Partner with IT and business leaders to develop and test business continuity, disaster recovery, and cyber resilience plans. Risk Management and Third-Party Risk
• Establish and oversee a third-party risk management program, including security assessments of vendors, licensing partners, and key service providers.
• Provide leadership, direction and guidance in assessing and evaluating information security risks and monitor compliance with security standards and appropriate policies.
• Support cyber insurance renewals, security questionnaires, and claims coordination. Security Operations and Engineering
• Develop, implement and administer technical security standards, as well as a suite of security services and tools to address and mitigate security risk.
• Establish and oversee a vulnerability management program, including scanning, penetration testing, and remediation tracking.
• Oversee day-to-day security operations, including MDR/SOC partner management, security monitoring and detection, threat intelligence, and endpoint and email security.
• Set direction for cloud security posture and zero-trust architecture in partnership with infrastructure and application teams.
• Establish governance for identity and access management, including privileged access controls and periodic access reviews.
• Examine impacts of new technologies on the company's overall information security. Establish processes to review implementation of new technologies to ensure security compliance.
• Establish governance, risk management, and security standards for artificial intelligence (AI), generative AI, machine learning, and automation technologies. Partner with business and technology leaders to enable responsible and secure adoption of AI solutions across the enterprise.
Our Best Fit Candidate Would Have Skills and Requirements • Bachelor's degree in Information Systems, Computer Science, or related field required.
• CISSP, CISM, or equivalent security certification strongly preferred.
• Minimum of 10 years' experience in information security, including 5+ years leading security teams or programs.
• Experience presenting security posture, risk, and program metrics to executive leadership.
• Experience leading global security programs; retail, consumer goods, or manufacturing industry experience a plus.
• Excellent communication skills - both written and verbal.
• Exceptional, hands-on leader with a style that is engaging, innovative, and collaborative.
• Ability to be flexible, work under pressure and tight deadlines.
• Ability to travel as needed; once per quarter.
• Ability and availability to work occasional nights and weekends.
• Experience with Fortinet/FortiGate/Forticlient, Crowdstrike MDR/EDR, BitLocker, File Vault, MS Defender, and Azure Security services is a plus.
In return, we provide an industry-competitive salary, along with a comprehensive benefits plan (medical, dental, vision) that includes a matching 401(k), Summer Fridays, generous PTO, merchandise discounts, excellent career development opportunities, and a work environment that reflects our industry leadership. Our social impact program, Centric Cares, focuses on volunteerism to make a difference in communities we live and work in and our D&I committee is shaping the future of diversity, equity and inclusion at Centric Brands though workshops, resources and inspiring conversation. At Centric Brands, we believe our people are our greatest asset, and we seek to structure competitive compensation offers to ensure that we are able to attract and retain the best talent. Our job postings include an annual base salary range at the time of employment. The stated base salary range represents our good faith estimate as to what candidates are likely to expect, and we tailor our offers within the range based on several factors, including the selected candidate's educational and professional experience, industry knowledge, location, technical and communication skills, and other factors that may prove relevant during the selection process. Base salary is a part of a total compensation package, which, depending on the position, may also include commission earnings, annual bonus and other Centric Brands sponsored benefit programs. Be part of our growing community by getting involved with groups, teams and initiatives like Be Green, Be Giving, and Be Celebrated. Centric Brands is an Equal Opportunity Employer Please note that Centric Brands will only reach out to interview, make an offer of employment or conduct onboarding activities for candidates who have applied through our careers site. When interviewing for a position, the candidate experience will include live interaction, such as a video conference or telephone call, with a Recruiter and/or company employee(s). We will never ask for any money or payments from applicants at any point in the recruitment process. Be aware of suspicious recruitment activity. If you think you are a victim of an employment scam, you may contact your local law enforcement agency and/or visit the Federal Trade Commission website here: #LI-KW1 #LI-Hybrid
Vacancy posted 4 days ago
Similar jobs that could be interesting for youBased on the Director, Information Security in Greensboro, NC vacancy
- ...Chief Security Officer About the Company Diverse provider of document management products & solutions Industry Information Technology and Services Type Public Company Founded 1906 Employees 10,001+ Categories Hardware Software Information...SuggestedWork at office
$60.4k - $71.25k
...properties are managed — making them smarter, more efficient, and more secure. We are a fast-growing team passionate about innovation,... ...Employer In connection with your application, we collect information that identifies, reasonably relates to or describes you ("...SuggestedFull timeContract workCasual workWork at officeImmediate startRemote work$150k - $170k
SENIOR OPERATIONS MANAGER Location: Greensboro, NC Salary: $150,000–$170,000 + Annual Bonus + Equity Schedule: Full-Time | Day Shift Benefits: Day 1 Medical Benefits + 401(k) Match + Employee Stock Program POSITION OVERVIEW Our client, a global leader...SuggestedFull timeShift workDay shift- ...monthly basis as needed.Acts as a mediator with employee and/or customer disputes.Works with sales/marketing team members to stay informed of market conditions (competitors and utilization trends) and customer needs.Makes direct customer contact routinely to ensure customer...SuggestedWork experience placementWork at officeLocal area
$16 - $22 per hour
Supervisor As a Supervisor at Lucky Strike Entertainment, you will lead the floor on every shift, support your team across bowling, arcade, food and beverage, bar, and events, and deliver the kind of guest experience that makes people want to come back. What You'...SuggestedHourly payFlexible hoursShift workNight shift$160k
...of a core location in our North American network of labs, which sees outstanding year over year growth. Please read on for more information about this exciting career opportunity.In This Role:You will be managing teams, including direct manager and supervisor reports.You...Full timeLocal areaWorldwideShift workDay shift- ...neededHandle opening and closing duties and help ensure safety, security, and proper use of company propertyRespond to incidents or... ...their rights pursuant to federal employment laws. For further information, please review the Know Your Rights notice from the Department...Work at officeFlexible hoursShift workAfternoon shift
$125k - $150k
...Director of Operations Location: Dexian Greensboro--Winston-Salem--High Point Area Base pay range: $125,000.00/yr - $150,000.00/yr Overview... ...identity, national origin, ancestry, citizenship, genetic information, marital status, disability, or any other characteristic...Full time- Operations Manager In TrainingThis is not a conventional training program. We cultivate a collaborative and mutually aligned approach with our location managers, ensuring they are provided with the essential tools and development opportunities to autonomously operate and...Work at officeLocal areaRelocationRelocation packageFlexible hours
- ...and government facilities. POSITION SUMMARY The Senior Director of Business Operations serves as a key member of the leadership... ...Director is accountable for improving the systems, processes, information, leadership discipline, and execution required to scale HHY profitably...Work at office
- ...Job Description Job Description Brady Integrated Security has brought together some of the best minds in the commercial security... ...etc. to satisfy the customer's requirements Provides needed information to the Engineering and Service Department to ensure jobs are completed...Temporary workWork at officeImmediate startWeekend work
$25 per hour
Job Description Job Description About the Role Parallel Fragrances is looking for a dependable, detail-oriented Operations Lead to own the day-to-day flow of our office and fulfillment operations. This is the person who ensures every operational task is completed...Hourly payContract workFor contractorsWork at officeMonday to FridayShift work$73.3k - $120.7k
...scheduleManage projects, assign Technicians, oversee ordering of equipment and material, and assure that proper customer sign-offs are secured per JSOX requirementsProvide leadership and supervision to technician team and be responsible for the team's development and...Contract workWork experience placementWork at officeLocal area- ...controlled. Control inventory at the branch level, ordering inventory in accordance with company restocking protocol. Ensures inventory is securely monitored, and any quantity discrepancies identified will be investigated and corrected. Reporting inaccuracies such as losses,...Local area
$15 - $21 per hour
...including receiving payments, preparing deposits, and maintaining security protocols.Train and mentor new associates and support store... ...such as filing, data entry, and reconciliation of missing information while maintaining accuracy.Follow CarMax Environmental, Health...Hourly payFull timeWork at officeNight shift- The Supervisor Cardiac Cath Lab is accountable for directing and providing leadership to designated areas in Heart and Vascular services. This includes educational, clinical, and operational responsibility for the Cardiac Catheterization Lab, Electrophysiology Lab, and ...
- ...but it influences much of what we do in the other three sections. The Associate Director of Campus Operations is responsible for leading the ministries of Guest Experience, Safety/Security, Facilities, and Connections at the Campus. Duties include volunteer recruitment...Part timeWork at office
$155k - $165k
The Director of Revenue Operations is responsible for architecting and leading CCL’s end-to-end revenue operating model. This role establishes... ...their rights pursuant to federal employment laws.For further information, please review the Know Your Rights notice from the Department...Contract workTemporary workFlexible hours- My client is seeking an experienced Director of Operations to lead project operations across a growing restoration and reconstruction organization. This individual will have broad responsibility for the project lifecycle, overseeing projects from pre-sale through closeout...Contract workFor subcontractor
- Location: Greensboro, North Carolina(with oversight of multi-site Southeast operations) Reports To: Owner / President / General Manager Travel: Regular travel to current and future Southeast locations. Position Summary The Operations Manager is responsible for the safe,...Hourly payWork at office
- Sales & Operations Manager - Med Spa We are seeking a hands-on, results-driven Sales & Operations Manager to take full ownership of sales performance and daily practice operations within our luxury medical spa. This role is ideal for a high-energy leader who thrives...Seasonal workLocal areaNight shift
$13.75 per hour
...skills, experience, qualifications, work location, and market conditions. These ranges may be modified in the future. For additional information on this role’s compensation package, please reach out to the designated recruiter for this role." At Gopuff, we know that life...Hourly payFull timeFlexible hoursShift workNight shiftDay shiftAfternoon shift- Supervisor, Last Mile Operations Accelerate your career at RXO RXO is a leading provider of transportation solutions. With cutting-edge technology at the center, we're revolutionizing the industry with our massive network and commitment to finding solutions for every...Work at office
- ...confidential legal and investigative files, ensuring the accuracy, security, and defensibility of the division’s records. The position... ...condition, veteran status, political affiliation, genetic information or sexual orientation and sexual identity. Employee Benefits...Permanent employmentContract workWork at officeRemote workFlexible hours
- Must Have Technical/Functional Skills Manufacturing Operation Management (MOM)/MES execution/solution Experience Consulting experience in Digital plant operation /Exposure to Industry 4.0 concepts Experience in handling business transformation programs, ...
- ...paid time off (including Company holidays), tuition reimbursement, a retirement savings plan with company match, and more! More information about benefits may be found here. Many positions also have variable pay opportunities including commission, bonus, performance...Permanent employmentTemporary workFor contractorsRelocation
- .../TSA regulations. Work with Safety and Security to ensure compliance and adherence to federal... ...efficiently and provide most up‑to‑date information in a timely manner to external and... ...airline. Other duties as assigned by the Director, Charter Services. Qualifications...Full timeContract workNight shift
- Hoffman Building Technologies, Inc. in Greensboro, NC is seeking an HR Coordinator to support daily HR operations, manage employee inquiries, maintain HRIS data, and prepare reports to assist leadership decisions. You will assist with recruiting, onboarding, benefits administration...
- AdaptHealth is seeking a Branch Manager to lead all branch operations, coordinating clinical and non-clinical staff while acting as liaison with regional leadership. The role drives program development, manages referrals, and ensures compliance with federal, state, and ...Local area
- GenerationEd is seeking a People Operations Support Partner to provide comprehensive administrative support to the People Operations department and manage employee correspondence, records, and lifecycle activities. The role ensures accurate records, timely communications...
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Director, Information Security. Be the first to apply!
Related searches






