Director of Cyber Security
Sims Limited
Sims Metal (Sims) is a global leader in metal recycling. With facilities worldwide, Sims supports the circular economy by making resources available for future use. As a responsible corporate citizen, we continuously seek new ways to broaden our participation in the environmental sector, ensuring that our future is as bright, safe, and secure as it has ever been in our long history.
Executive Summary
This role serves as the senior cybersecurity leader for Sims and acts as the organization's designated cybersecurity authority. Reporting to the VP, Infrastructure & Security, the Director is responsible for developing and executing the enterprise cybersecurity, technology risk, compliance, governance, resilience, and information security strategies while ensuring alignment with business objectives, operational realities, and regulatory obligations.
The Director leads cybersecurity operations, cyber risk management, governance, compliance, identity security, third-party risk, operational technology security, customer security assurance, incident response, cyber resilience, and AI security programs. The role provides an independent and transparent assessment of cyber risk while partnering closely with Infrastructure, Enterprise Applications, Data & AI, Legal, Compliance, Operations, and executive leadership.
The Director acts as Sims' day-to-day cybersecurity leader and primary security subject matter expert, providing meaningful risk reporting, strategic recommendations, and operational leadership while supporting executive and Board-level decision making.
Key Responsibilities
1. Cybersecurity Strategy, Governance & Risk Management
- Develop and execute a multi-year cybersecurity and technology risk strategy aligned to Sims' business objectives, risk appetite, operational environment, and regulatory obligations.
- Maintain and continuously improve enterprise cybersecurity governance frameworks, policies, standards, procedures, and security controls.
- Lead the Cybersecurity Governance, Risk, and Compliance (GRC) program.
- Establish and maintain cybersecurity governance forums, decision rights, risk escalation processes, and accountability models.
- Maintain enterprise cyber and technology risk registers, key risk indicators, treatment plans, and risk reporting.
- Provide an independent and transparent view of cyber risk while escalating material concerns through the VP, Infrastructure & Security and established governance channels.
- Support technology strategy, M&A activity, major technology investments, and business initiatives through cybersecurity risk assessments and recommendations.
2. Information Security & Cybersecurity Operations
- Lead enterprise cybersecurity operations, including security monitoring, detection engineering, vulnerability management, threat intelligence, security architecture, identity security, cloud security, data protection, and incident response.
- Establish and maintain technical and administrative controls to protect Sims' information assets.
- Oversee cybersecurity incident response activities and serve as Incident Commander during significant cybersecurity incidents.
- Ensure operational readiness through regular testing of response plans, ransomware playbooks, recovery exercises, and crisis management procedures.
- Drive continuous cybersecurity maturity improvements based on evolving threats and business requirements.
- Retain architecture authority, incident command, and cybersecurity decision-making within Sims regardless of sourcing arrangements.
3. Technology Governance, Compliance & Assurance
- Maintain enterprise technology and security governance standards and control frameworks aligned to NIST CSF, ISO 27001, CIS Controls, and applicable industry requirements.
- Coordinate technology control assessments and remediation activities.
- Partner with Internal Audit, Legal, Compliance, Privacy, and external auditors to support assessments and examinations.
- Maintain evidence demonstrating security control effectiveness.
- Ensure compliance with applicable laws, regulations, contractual obligations, privacy requirements, customer commitments, and reporting requirements.
- Manage interactions with regulators, auditors, cyber insurers, and major customers on cybersecurity matters.
4. Operational Technology (OT) & Industrial Security
- Establish and maintain appropriate cybersecurity capabilities across operational technology environments, including processing facilities, recycling yards, industrial equipment, site networks, sensors, and connected systems.
- Partner with Operations, Engineering, Plant Leadership, and OT vendors to secure environments without disrupting production.
- Establish standards for segmentation, remote access, monitoring, vendor access, and compensating controls for legacy equipment.
- Ensure cybersecurity requirements are incorporated into automation, IoT, and operational technology projects.
- Develop OT-specific incident response and recovery capabilities.
5. Identity, Cloud & Enterprise Platform Security
- Own identity security strategy, including privileged access management, workforce identities, service accounts, third-party access, and access recertification.
- Establish security architecture standards for cloud, infrastructure, networks, endpoints, applications, and SaaS platforms.
- Partner with Infrastructure teams to embed security by design into platform engineering and operational processes.
- Maintain cloud security guardrails for Microsoft Azure, Microsoft 365, SAP, Dynamics 365, and other strategic platforms.
- Ensure backup, recovery, and cyber-resilience controls can withstand destructive cyber events.
6. Application, Data & AI Security
- Establish security requirements for enterprise applications, integrations, APIs, and custom-developed solutions.
- Lead data protection initiatives covering classification, access controls, encryption, retention, and regulatory requirements.
- Partner with Data & AI teams to establish governance and security guardrails for AI, agents, copilots, and automation platforms.
- Conduct threat modeling and security reviews for major technology and AI initiatives.
- Ensure AI solutions are deployed responsibly with appropriate controls around identity, access, data exposure, monitoring, and vendor risk.
7. Third-Party Risk & Customer Security Assurance
- Lead enterprise third-party cybersecurity risk management.
- Establish vendor assessment methodologies, security requirements, ongoing monitoring processes, and remediation expectations.
- Partner with Procurement and Legal to embed cybersecurity requirements into contracts.
- Support customer security reviews, due diligence requests, audits, and security assessments.
- Act as a senior representative during major customer discussions involving cybersecurity, risk, compliance, and security assurance.
8. Cyber Resilience & Business Continuity
- Lead technology resilience, disaster recovery, cyber recovery, and cyber elements of business continuity planning.
- Define recovery objectives for critical business and operational services.
- Conduct technical and executive-level resilience exercises.
- Validate recovery capabilities through realistic testing and evidence-based performance metrics.
- Continuously improve resilience capabilities based on emerging threats, lessons learned, and operational experience.
9. Leadership, Executive Communication & Talent Development
- Lead and develop a high-performing global cybersecurity, risk, and compliance team.
- Manage managed security providers and specialized security partners through outcome-based governance.
- Develop cybersecurity roadmaps, investment recommendations, and staffing plans.
- Provide cybersecurity metrics, risk reporting, and executive briefings to leadership.
- Participate in Executive Leadership Team, Risk Committee, and Board reporting activities in partnership with the VP, Infrastructure & Security.
- Promote a strong enterprise culture of security, accountability, and risk ownership.
Equal Opportunity Employer
Sims is proud to be an equal opportunity employer. We value the diversity of all of our employees and are committed to creating an inclusive working environment where everyone can contribute, advance on merit, and realize their full potential. Sims does not discriminate based on race, sex, religion, color, national origin, citizenship status, disability, age, marital or familial status, sexual orientation, gender identity, gender expression, veteran status, housing status, source of income, or any other status protected by federal, state, or local laws. This applies to any employment decision, including recruiting, hiring, placement, promotion, termination, layoff, recall, transfer, leaves of absence, compensation, and training. Qualified applicants with a disability in need of a reasonable accommodation may request such without fear of reprisal or discrimination.
To find out more, please visit for more information on Sims and its commitment to sustainability.
$134.5k - $265.1k
Position Summary Data Privacy ManagerAs a Manager in Deloitte’s Digital Trust & Privacy practice, you will lead the discovery, design, and implementation of privacy technology solutions that help organizations address regulatory requirements, strengthen data governance...SuggestedLocal area- ...leading the frontline defense against today's most sophisticated cyber threats - both known and unknown? Do you want to own and evolve... ...line, and being accountable for the outcomes that keep our clients secure?If yes, then Deloitte's Cyber Detect and Respond team could be...SuggestedLocal areaVisa sponsorship
- ...to work with leading-edge technologies and take on some of the coolest projects you can imagine.ABOUT ACCENTURE SECURITYAccenture Security helps organizations prepare, protect, detect, respond to, and recover across all points of the security lifecycle. Our OT Security...SuggestedFull timeWork experience placementLive inWork at officeLocal area
- ...architecture that disrupts conventional practices. And we are looking to hire an experienced Cyber Intelligence practitioner and consultant to an already outstanding team.Accenture Security helps organizations prepare, protect, detect, respond to, and recover, at all points...SuggestedFull timeWork experience placementLive inWork at officeLocal area
$115k - $140k
Job Summary:BDO is seeking an IT PCI Cyber Compliance Manager to join BDO’s thriving Cyber Practice. This practice provides global solutions... ...Duties:Manages teams to deliver services regarding national security, cyber assessments, PCI, NIST, ISO, HIPAA, SWIFT Certification,...SuggestedWork at officeRemote work- Position Summary Are you passionate about shaping the cyber and organizational risk posture of leading companies at enterprise... ...integrated services provider in helping to transform the cyber security services marketplace. Managing our industry-leading services...Local areaVisa sponsorship
$163.4k - $322.1k
...advisory, and delivery efforts that help clients strengthen physical security programs, align security capabilities to enterprise priorities,... ...mentor and provide clear guidance to othersThe teamDeloitte’s Cyber Defense & Resilience practice helps organizations protect...Local areaVisa sponsorship$148.2k - $292.3k
Position Summary As a Full Stack Engineer Manager in Deloitte Cyber’s Digital Trust & Privacy practice, you will operate at the... ...engineering teams, and communicate effectively with business, security, privacy, legal, and compliance stakeholders.Recruiting for...Local areaVisa sponsorship- ...right patients, at the right time.The RoleAs the Medical Device Cybersecurity Senior Manager, you will own the medical device cyber security program at Tempus AI. You will act as the crucial bridge between enterprise-wide security strategy and product-level medical device...Full timeShift work
$190k
...relationships ranging from cross-functional stakeholder groups to existing security teams.You’re Good At:Understanding the role technology plays in... ...lifecycles, system designs, and IT architectures.Utilizing cyber risk quantification to reduce uncertainty around cyber risk and...Work at officeLocal area$119.6k - $197.35k
...Report.Day (United States of America)Location680 Lake Shore DriveJob DescriptionLeads the organization’s GRC program to strengthen the security posture, reduce risk, and ensure compliance with NIST CSF, PCI DSS, HIPAA, and HITECH. Oversee team operations, strategy execution...Hourly payFull timePart time- ...delivering risk management solutions across critical domains, including cyber. Within that environment, this role leads the delivery, growth,... ...s degree in computer science, information systems, information security, mathematics, decision sciences, risk management, mechanical...Contract workLocal areaVisa sponsorship
$185k - $225k
...modelling, and finance.What will you do in this role?• This role has direct responsibility for pricing and portfolio management of all Cyber Reinsurance business written across the globe through offices in US, London and Zurich.• This role may include managing supporting...Full timeWorldwide$134.5k - $265.1k
Position Summary Our Deloitte Cyber Defense & Resilience team recognizes that resilient organizations must protect not only data... ...people, facilities, assets, and operations. Join our Physical Security consulting team to help clients address evolving threats...Contract workLocal areaVisa sponsorship$141.92k - $212.89k
...Regulatory Authority) is the largest independent regulator of securities firms doing business in the United States. Our mission is to protect... ...the financial sector? As a Senior Principal Risk Specialist, Cyber Engagements, you'll play a pivotal role in strengthening the...Full timeTemporary workFor contractorsFor subcontractorLocal areaImmediate start$120k - $165k
...Description:The Manager, Cybersecurity Operations owns day to day security operations and incident response, with a strong focus on... ...Awareness Month activities, and targeted campaigns.Partner with the Director of Infrastructure and Security on KPIs, operational risk...Full timeTemporary workWork at officeNight shiftWeekend workAfternoon shift3 days per week$107k - $214.5k
...Cybersecurity and data protection risk (CDPR), comprised of dedicated cybersecurity professionals dedicated exclusively to serving the cyber security and information protection needs of our clients. This group includes experienced consultants located throughout the country...Full timeWork experience placementInternshipLocal areaShift work$193.5k - $227.7k
...Monroe is excited to hire a Cybersecurity - Senior Manager to deliver on full lifecycle Cyber projects for various industries, which may involve strategy & roadmap development, security controls reviews & remediation/hardening, risk advisory, compliance assessments,...Local areaImmediate startFlexible hours2 days per week1 day per week$134.5k - $265.1k
Position Summary Our Deloitte Cyber team understands the unique challenges and opportunities businesses face in cybersecurity.... ...with resilience, grow with confidence, and proactively manage to secure success.Recruiting for this role ends on 12/31/2026Work you’ll...Local areaVisa sponsorship$136k - $196k
...track program effectiveness and ecosystem resilience using modern data analytics. Serve as the primary liaison for global Policy, Security, Communications, and Marketing to support high-profile program launches and to build compelling narratives for external...Temporary work- ...roadmap, policies, and SOPs, aligning with the enterprise data security strategy. You will partner with R&D and engineering to embed... ...and SSDLC into device development. The role requires deep FDA cyber guidance knowledge, ISO 14971/13485 familiarity, and proficiency...
$130k - $150k
...leading success in mergers and acquisitions Job Description In this role, you will manage the Security Incident Response team; for detecting and identifying cyber threats, as well as containment and remediation of these threats. This role owns the full incident...Full timeImmediate start- ...Join us.Your role.Your work will include, but not be limited to: Performing and/or managing Information Technology (IT) audits and security assessments in various industries with a focus in the public sector.Knowledge of information security frameworks including COBIT,...Work at officeFlexible hoursNight shift
$155.6k - $306.8k
Position Summary Deloitte Cyber understands the unique challenges and opportunities businesses face in cybersecurity. Deloitte... ...resilience, grow with confidence, and proactively manage their security posture.Recruiting for this role ends on 12/31/2026.Work you...Local areaVisa sponsorship$134.5k - $265.1k
Position Summary Cyber Network Security Architecture - Manager / Manager, Strategy, Growth, and Transformation Are you interested in improving the cyber and organizational risk profiles of leading companies? Do you want to be involved in delivering Cyber services...Local areaVisa sponsorship$65 - $75 per hour
...Job Title: Cyber Security Project Manager Location: Hybrid – Chicago, IL Openings: 4 positions Base Pay Range $65.00/hr - $75.00/hr Role Overview We are seeking experienced Cybersecurity Project Managers to lead strategic initiatives across key cybersecurity...Work at office- ...seeks a senior leader to head Cybersecurity Architecture and Engineering. You will guide a large team of architects, drive strategic security initiatives, and ensure alignment with business goals and enterprise strategy. Emphasis on risk reduction, compliance, and...
- ...professional to shape the global media narrative for Accenture Cybersecurity at a time when AI-driven threats, cyber resilience, critical infrastructure protection and secure digital transformation are defining the next era of business risk. This experienced professional will...Full timeLive inWork at officeLocal area
$137.4k - $240.4k
...provide strategic leadership, governance, and execution oversight for a portfolio of cybersecurity capabilities spanning Application Security (e.g. API Security, Secure Software Development practices, etc.), Data Protection, and SaaS Security. The role is accountable for...Full timeFor contractorsH1bWorldwideFlexible hours$80k - $100k
...visit covista.com and follow us on LinkedIn , Instagram and YouTube . Job Description Reporting to the Sr. Director, Enterprise Safety & Security, the Manager of Enterprise Safety & Security (ESS) is responsible for providing support to field operations of the...Full timeWork at officeFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Director of Cyber Security. Be the first to apply!
- cyber security lead Chicago, IL
- director - cyber security Chicago, IL
- senior manager cyber security Chicago, IL
- cybersecurity manager Chicago, IL
- cyber insurance Chicago, IL
- cyber Chicago, IL
- cyber sales Chicago, IL
- cybersecurity certificate Chicago, IL
- cybersecurity administrator Chicago, IL
- work from home cyber security Chicago, IL




