Responsible for shaping, operationalizing, and communicating the enterprise cybersecurity strategy
Driving measurable outcomes and a strong security culture across the organization
Combines strategic planning, performance management, training & awareness, and organizational engagement
Serves as a strategic partner to the VP, Cybersecurity Strategy, Governance, and Oversight
Translating cybersecurity vision into actionable roadmaps, meaningful metrics, and engagement initiatives
Partner with the VP to define, evolve, and maintain the enterprise cybersecurity strategy
Translate cybersecurity strategy into strategic objectives, key results, initiatives, and governance expectations
Establish and maintain cybersecurity governance frameworks
Provide oversight and transparency through consistent reporting on strategy execution
Design, implement, and maintain a comprehensive cybersecurity key risk and KPI framework
Collaborate with security teams to ensure metrics accurately reflect security outcomes
Develop and execute a cybersecurity awareness and training strategy
Collaborate with cross-functional teams to implement organization-wide security awareness campaigns
Build relationships across IT, Legal, Compliance, Risk Management, and business stakeholders
Requirements
Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Business Administration, Communications, or related field, or equivalent experience
Required
Post-graduate or professional qualification in related field
Preferred
Relevant industry certifications such as CISSP, CISM, CRISC, Security+, or similar
Preferred
10+ years’ relevant technology and business experience
Required
Minimum 5-7 years of progressive experience in cybersecurity, information security, or IT risk management
Required
Demonstrated experience developing and implementing cybersecurity metrics, KPIs, and reporting frameworks
Required
Proven experience developing, executing, and maturing cybersecurity strategies and roadmaps aligned to enterprise business objectives
Required
Proven track record of designing and delivering cybersecurity training and awareness programs
Required
Experience creating executive-level presentations and communicating technical concepts to non-technical audiences
Required
Strong analytical skills with experience collecting, analyzing, and visualizing security data
Required
Hands-on experience with security tools, technologies, and frameworks (NIST CSF, ISO 27001, CIS Controls)
Required
Experience managing projects and coordinating cross-functional initiatives
Required
Experience in a regulated industry (financial services, insurance, government, etc.)
Preferred
Background in strategy, governance, risk management, or compliance functions
Preferred
Proficiency with data management, data visualization, and business intelligence tools (e.g., Power BI, Snowflake, Alteryx)
Preferred
Experience with learning management systems (LMS) and security awareness platforms (e.g., KnowBe4, Proofpoint, SANS Security Awareness)
Preferred
Experience conducting phishing simulations
Preferred
Knowledge of adult learning principles and instructional design methodologies
Preferred
Prior experience managing vendor relationships and procurement processes
Preferred
Demonstrated success in driving cultural change and influencing behavior across organizations
Preferred
Experience with Governance, Risk, and Compliance (GRC) platforms