Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Director, Cyber & Information Security

Jobleads-US

Career Opportunities: Director, Cyber & Information Security (6960)

Founded in Australia in 1917, Sims Limited (Sims) is a global leader in metal recycling and circular solutions for technology. We play a critical role in advancing circularity anddecarbonisationby supplying recycled materials and re-purposed products that help preserve our planet.

At Sims, we believe in developing our people. With a strong promote-from-within philosophy and a range ofprogrammesthat support continuous learning, we offer opportunities for meaningful, long-term careers. Employing more than 4,100 people worldwide, weoperateover 155 facilities across 13 countries. Simsprovidesthe stability, transparency, and professional growth opportunities of a publicly tradedorganisation, all driven by our purpose: to create a world without waste.

Executive Summary

This role serves as the senior cybersecurity leader for Sims and acts as the organization's designated cybersecurity authority. Reporting to the VP, Infrastructure & Security, the Director is responsible for developing and executing the enterprise cybersecurity, technology risk, compliance, governance, resilience, and information security strategies while ensuring alignment with business objectives, operational realities, and regulatory obligations.

The Director leads cybersecurity operations, cyber risk management, governance, compliance, identity security, third-party risk, operational technology security, customer security assurance, incident response, cyber resilience, and AI security programs. The role provides an independent and transparent assessment of cyber risk while partnering closely with Infrastructure, Enterprise Applications, Data & AI, Legal, Compliance, Operations, and executive leadership.

The Director acts as Sims' day-to-day cybersecurity leader and primary security subject matter expert, providing meaningful risk reporting, strategic recommendations, and operational leadership while supporting executive and Board-level decision making.

Key Responsibilities

1. Cybersecurity Strategy, Governance & Risk Management

  • Develop and execute a multi-year cybersecurity and technology risk strategy aligned to Sims' business objectives, risk appetite, operational environment, and regulatory obligations.
  • Maintain and continuously improve enterprise cybersecurity governance frameworks, policies, standards, procedures, and security controls.
  • Lead the Cybersecurity Governance, Risk, and Compliance (GRC) program.
  • Establish and maintain cybersecurity governance forums, decision rights, risk escalation processes, and accountability models.
  • Maintain enterprise cyber and technology risk registers, key risk indicators, treatment plans, and risk reporting.
  • Provide an independent and transparent view of cyber risk while escalating material concerns through the VP, Infrastructure & Security and established governance channels.
  • Support technology strategy, M&A activity, major technology investments, and business initiatives through cybersecurity risk assessments and recommendations.

2. Information Security & Cybersecurity Operations

  • Lead enterprise cybersecurity operations, including security monitoring, detection engineering, vulnerability management, threat intelligence, security architecture, identity security, cloud security, data protection, and incident response.
  • Establish and maintain technical and administrative controls to protect Sims' information assets.
  • Oversee cybersecurity incident response activities and serve as Incident Commander during significant cybersecurity incidents.
  • Ensure operational readiness through regular testing of response plans, ransomware playbooks, recovery exercises, and crisis management procedures.
  • Drive continuous cybersecurity maturity improvements based on evolving threats and business requirements.
  • Retain architecture authority, incident command, and cybersecurity decision-making within Sims regardless of sourcing arrangements.

3. Technology Governance, Compliance & Assurance

  • Maintain enterprise technology and security governance standards and control frameworks aligned to NIST CSF, ISO 27001, CIS Controls, and applicable industry requirements.
  • Coordinate technology control assessments and remediation activities.
  • Partner with Internal Audit, Legal, Compliance, Privacy, and external auditors to support assessments and examinations.
  • Maintain evidence demonstrating security control effectiveness.
  • Ensure compliance with applicable laws, regulations, contractual obligations, privacy requirements, customer commitments, and reporting requirements.
  • Manage interactions with regulators, auditors, cyber insurers, and major customers on cybersecurity matters.

4. Operational Technology (OT) & Industrial Security

  • Establish and maintain appropriate cybersecurity capabilities across operational technology environments, including processing facilities, recycling yards, industrial equipment, site networks, sensors, and connected systems.
  • Partner with Operations, Engineering, Plant Leadership, and OT vendors to secure environments without disrupting production.
  • Establish standards for segmentation, remote access, monitoring, vendor access, and compensating controls for legacy equipment.
  • Ensure cybersecurity requirements are incorporated into automation, IoT, and operational technology projects.
  • Develop OT-specific incident response and recovery capabilities.
  • Own identity security strategy, including privileged access management, workforce identities, service accounts, third-party access, and access recertification.
  • Establish security architecture standards for cloud, infrastructure, networks, endpoints, applications, and SaaS platforms.
  • Partner with Infrastructure teams to embed security by design into platform engineering and operational processes.
  • Maintain cloud security guardrails for Microsoft Azure, Microsoft 365, SAP, Dynamics 365, and other strategic platforms.
  • Ensure backup, recovery, and cyber-resilience controls can withstand destructive cyber events.

6. Application, Data & AI Security

  • Establish security requirements for enterprise applications, integrations, APIs, and custom-developed solutions.
  • Lead data protection initiatives covering classification, access controls, encryption, retention, and regulatory requirements.
  • Partner with Data & AI teams to establish governance and security guardrails for AI, agents, copilots, and automation platforms.
  • Conduct threat modeling and security reviews for major technology and AI initiatives.
  • Ensure AI solutions are deployed responsibly with appropriate controls around identity, access, data exposure, monitoring, and vendor risk.

7. Third-Party Risk & Customer Security Assurance

  • Lead enterprise third-party cybersecurity risk management.
  • Establish vendor assessment methodologies, security requirements, ongoing monitoring processes, and remediation expectations.
  • Partner with Procurement and Legal to embed cybersecurity requirements into contracts.
  • Support customer security reviews, due diligence requests, audits, and security assessments.
  • Act as a senior representative during major customer discussions involving cybersecurity, risk, compliance, and security assurance.

8. Cyber Resilience & Business Continuity

  • Lead technology resilience, disaster recovery, cyber recovery, and cyber elements of business continuity planning.
  • Define recovery objectives for critical business and operational services.
  • Conduct technical and executive-level resilience exercises.
  • Validate recovery capabilities through realistic testing and evidence-based performance metrics.
  • Continuously improve resilience capabilities based on emerging threats, lessons learned, and operational experience.
  • Lead and develop a high-performing global cybersecurity, risk, and compliance team.
  • Manage managed security providers and specialized security partners through outcome-based governance.
  • Develop cybersecurity roadmaps, investment recommendations, and staffing plans.
  • Provide cybersecurity metrics, risk reporting, and executive briefings to leadership.
  • Participate in Executive Leadership Team, Risk Committee, and Board reporting activities in partnership with the VP, Infrastructure & Security.
  • Promote a strong enterprise culture of security, accountability, and risk ownership.

A career with Sims provides you with the opportunity to work with an organization whose goal is to be the world’s safest and most responsible recycling company. Our people achieve this by creating a zero-harm workplace, being exemplary members of the communities in which we operate, and being responsible stewards of the environment. We also offer competitive pay and a range of attractive benefits.

Sims is proud to be an equal opportunity employer. We value the diversity of all of our employees and are committed to creating an inclusive working environment where everyone can contribute, advance on merit, and realize their full potential. Sims does not discriminate with regard to race, sex, religion, color, national origin, citizenship status, disability, age, marital or familial status, sexual orientation, gender identity, gender expression, veteran status, housing status, source of income, or any other status protected by federal, state, or local laws. This applies to any employment decision, including recruiting, hiring, placement, promotion, termination, layoff, recall, transfer, leaves of absence, compensation, and training. Qualified applicants with a disability in need of a reasonable accommodation may request such without fear of reprisal or discrimination.

To achieve our purpose to create a world without waste to preserve our planet, we are guided by our Principles of Purpose: Be Safe + Well, Band Together, Be Accountable + Transparent, Consistently Innovate, Inspire with Purpose, Celebrate + Have Fun.

#J-18808-Ljbffr Jobleads-US
Vacancy posted 2 days ago
Similar jobs that could be interesting for youBased on the Director, Cyber & Information Security in Chicago, IL vacancy
  •  ...defense against today's most sophisticated cyber threats - both known and unknown? Do you...  ...for the outcomes that keep our clients secure?If yes, then Deloitte's Cyber Detect and...  ...delivery-model evolution, Security Information and Event Management (SIEM) modernization... 
    Suggested
    Local area
    Visa sponsorship

    Deloitte

    Chicago, IL
    1 day ago
  • $115k - $140k

    Job Summary:BDO is seeking an IT PCI Cyber Compliance Manager to join BDO’s thriving Cyber...  ...and products to help them reduce their information risks and digital footprint while...  ...to deliver services regarding national security, cyber assessments, PCI, NIST, ISO, HIPAA... 
    Suggested
    Work at office
    Remote work

    BDO International

    Chicago, IL
    22 hours ago
  •  ...Are you passionate about shaping the cyber and organizational risk posture of leading...  ...provider in helping to transform the cyber security services marketplace. Managing our...  ...point and trusted advisor to client chief information security officers, chief information officers... 
    Suggested
    Local area
    Visa sponsorship

    Deloitte

    Chicago, IL
    1 day ago
  • $148.2k - $292.3k

     ...Full Stack Engineer Manager in Deloitte Cyber’s Digital Trust & Privacy practice, you...  ...communicate effectively with business, security, privacy, legal, and compliance stakeholders...  ...in Computer Science, Engineering, Information Technology, Cybersecurity, or equivalent... 
    Suggested
    Local area
    Visa sponsorship

    Deloitte

    Chicago, IL
    3 days ago
  •  ...solutions across critical domains, including cyber. Within that environment, this role...  ...Requests for Proposal and Requests for Information activities, including solution scoping,...  ...science, information systems, information security, mathematics, decision sciences, risk management... 
    Suggested
    Contract work
    Local area
    Visa sponsorship

    Deloitte

    Chicago, IL
    1 day ago
  • $190k

     ...Explore our BCG Culture and Values for more information.About BCG PlatinionBCG Platinion's...  ...functional stakeholder groups to existing security teams.You’re Good At:Understanding the role...  ...designs, and IT architectures.Utilizing cyber risk quantification to reduce... 
    Work at office
    Local area

    The Boston Consulting Group

    Chicago, IL
    3 days ago
  •  ...time, actionable insights to physicians, providing critical information about the right treatments for the right patients, at the right...  ...Senior Manager, you will own the medical device cyber security program at Tempus AI. You will act as the crucial bridge between... 
    Full time
    Shift work

    Tempus

    Chicago, IL
    3 days ago
  • $119.6k - $197.35k

     ...DescriptionLeads the organization’s GRC program to strengthen the security posture, reduce risk, and ensure compliance with NIST CSF, PCI...  ...data protection programs to ensure security of sensitive information.Lead vulnerability management programs, ensuring timely remediation... 
    Hourly pay
    Full time
    Part time

    Ann & Robert H. Lurie Children's Hospital of Chicago

    Chicago, IL
    22 hours ago
  • $107k - $214.5k

     ...and data protection risk (CDPR), comprised of dedicated cybersecurity professionals dedicated exclusively to serving the cyber security and information protection needs of our clients. This group includes experienced consultants located throughout the country dedicated... 
    Full time
    Work experience placement
    Internship
    Local area
    Shift work

    RSM International

    Chicago, IL
    4 days ago
  • $134.5k - $265.1k

    Position Summary Our Deloitte Cyber team understands the unique challenges and...  ...with confidence, and proactively manage to secure success.Recruiting for this role ends on...  ...Saviynt.Understand complex business and information technology management processes. Execute... 
    Local area
    Visa sponsorship

    Deloitte

    Chicago, IL
    22 hours ago
  •  ...roadmap, policies, and SOPs, aligning with the enterprise data security strategy. You will partner with R&D and engineering to embed...  ...and SSDLC into device development. The role requires deep FDA cyber guidance knowledge, ISO 14971/13485 familiarity, and proficiency... 

    Jobleads-US

    Chicago, IL
    3 days ago
  •  ...professional goals. Join us.Your role.Your work will include, but not be limited to: Performing and/or managing Information Technology (IT) audits and security assessments in various industries with a focus in the public sector.Knowledge of information security... 
    Work at office
    Flexible hours
    Night shift

    Plante Moran

    Chicago, IL
    4 days ago
  • $134.5k - $265.1k

     ...Lead working sessions with client stakeholders to gather technical, functional, and business requirements and establish use cases to inform future state architecture.Architect:Navigate complex IT architectures to incorporate privacy technology solutions.General awareness... 
    Local area

    Deloitte

    Chicago, IL
    22 hours ago
  • $137.4k - $240.4k

     ...a portfolio of cybersecurity capabilities spanning Application Security (e.g. API Security, Secure Software Development practices, etc....  ...including regular communication and consultation to keep them informed and involved.Ensure clear, consistent, and timely communication... 
    Full time
    For contractors
    H1b
    Worldwide
    Flexible hours

    Northern Trust

    Chicago, IL
    22 hours ago
  •  ...coolest projects you can imagine.ABOUT ACCENTURE SECURITYAccenture Security helps organizations prepare, protect, detect, respond to, and...  ...opportunities, paid holidays, and paid time off. See more information on our benefits here: U.S. Employee Benefits | AccentureRole Location... 
    Full time
    Work experience placement
    Live in
    Work at office
    Local area

    Accenture

    Chicago, IL
    3 days ago
  •  ...And we are looking to hire an experienced Cyber Intelligence practitioner and consultant...  ...an already outstanding team.Accenture Security helps organizations prepare, protect, detect...  ...holidays, and paid time off. See more information on our benefits here:U.S. Employee... 
    Full time
    Work experience placement
    Live in
    Work at office
    Local area

    Accenture

    Chicago, IL
    22 hours ago
  • $163.4k - $322.1k

     ...advisory, and delivery efforts that help clients strengthen physical security programs, align security capabilities to enterprise priorities,...  ...mentor and provide clear guidance to othersThe teamDeloitte’s Cyber Defense & Resilience practice helps organizations protect... 
    Local area
    Visa sponsorship

    Deloitte

    Chicago, IL
    1 day ago
  • $134.5k - $265.1k

    Position Summary Our Deloitte Cyber Defense & Resilience team recognizes that resilient organizations must protect not only data...  ...people, facilities, assets, and operations. Join our Physical Security consulting team to help clients address evolving threats... 
    Contract work
    Local area
    Visa sponsorship

    Deloitte

    Chicago, IL
    1 day ago
  • $185k - $225k

     ...modelling, and finance.What will you do in this role?• This role has direct responsibility for pricing and portfolio management of all Cyber Reinsurance business written across the globe through offices in US, London and Zurich.• This role may include managing supporting... 
    Full time
    Worldwide

    Axis Capital

    Chicago, IL
    3 days ago
  • $141.92k - $212.89k

     ...is the largest independent regulator of securities firms doing business in the United States...  ...As a Senior Principal Risk Specialist, Cyber Engagements, you'll play a pivotal role...  ...drives attendee engagement with relevant information and aligned with company goals.Develop Formal... 
    Full time
    Temporary work
    For contractors
    For subcontractor
    Local area
    Immediate start

    Financial Industry Regulatory Authority

    Chicago, IL
    3 days ago
  • $240k

     ...3rd through 5th year associate class for its Privacy and Data Security practice group in any of our office locations. The ideal candidate...  ...status, national origin, ancestry, medical condition, genetic information, marital status, physical or mental disability, parental... 
    Fixed term contract
    Work at office
    Overseas
    Flexible hours
    Shift work

    ArentFox Schiff LLP

    Chicago, IL
    1 day ago
  • $105.4k - $207.8k

    Position Summary Cyber Data Protection Senior ConsultantAre you passionate about...  ...requirements, but also enable secure growth, strengthen trust, and improve operational...  ...experience in data protection and information security, which may include Data Discovery... 
    Local area

    Deloitte

    Chicago, IL
    1 day ago
  •  ...Sims Limited, a global leader in metal recycling and circular solutions, seeks a Director of Cyber & Information Security to lead enterprise cybersecurity, risk, governance, and resilience. You will oversee operations across cyber defense, OT security, and AI safety,... 

    Jobleads-US

    Chicago, IL
    2 days ago
  •  ...Let’s see what we can achieve. Together. Summary The Chief Information Security Officer (CISO), working in collaboration with and in support...  ...leading a mature, business-aligned information security and cyber risk program. This role sets the strategic direction for the... 
    Work at office
    Remote work
    Relocation
    Visa sponsorship
    Relocation package

    DLA Piper

    Chicago, IL
    1 day ago
  • $82.6k - $162.8k

     ...outcomes for clients across industries. Qualifications Required: * BA/BS in Computer Engineering, Computer Science, Information Systems, Cyber Security, or equivalent demonstrated technical background * 2+ years of experience in infrastructure or application architecture... 
    Local area
    Visa sponsorship

    Deloitte

    Chicago, IL
    1 day ago
  • $105.4k - $207.8k

    Position Summary Our Deloitte Cyber team understands the evolving cybersecurity...  ...role, you will support Next-Generation Security Operations Center (SOC) capabilities built...  ...in computer science, cybersecurity, information systems, or equivalent work experience.5... 
    Work experience placement
    Local area
    Visa sponsorship

    Deloitte

    Chicago, IL
    2 days ago
  • $93.9k - $156.5k

    The Cyber Defense Response Analyst II is a mid-level technical role focused on responding...  ...Python and REST APIs to build/integrate security tools for incident response needs, while...  ...demonstrated ability to innovate within information technology domains.A "Researcher"... 
    Full time
    Worldwide
    Day shift
    Afternoon shift

    CME- Group

    Chicago, IL
    22 hours ago
  •  ...Travel Required: YesResponsibilities:Ensure implementation of secure operating systems, networks, and databases for the organization...  ...transmissions and erect firewalls to conceal confidential information during transmission and to prevent tainted digital transfers.Facilitate... 
    Work experience placement

    Axelon

    Chicago, IL
    1 day ago
  •  ...you'll make an ImpactAs a vCISO, you will serve as a fractional security leader and trusted advisor to Ntiva's GovCon clients, owning...  ...correspondence and process proceduresAbility to effectively present information and respond to questions from groups of managers, clients, and... 
    Temporary work
    Remote work
    Monday to Friday

    Ntiva

    Chicago, IL
    3 days ago
  • $68k - $133.9k

    Position Summary Build your career as an Analyst in Cyber Strategy, Growth & Transformation, helping clients...  ...Bachelor’s degree in Computer Engineering, Computer Science, Information Systems, Cyber Security, or another technical field • 1+ years of experience in infrastructure... 
    Local area
    Visa sponsorship

    Deloitte

    Chicago, IL
    1 day ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Director, Cyber & Information Security. Be the first to apply!