The Director, Information and Cybersecurity is responsible for developing and authorizing implementation of departmental policies. This position directs the activities of one or more functional areas through managers/senior managers who have overall responsibility for the successful operation of those assigned areas. This position has control of planning, staffing, budgeting, managing expense priorities, and recommending and implementing changes to methods. This position works on complex problems within information security functional areas by identifying and evaluating issues through assessments.
This role provides strategic thought leadership and disciplined security architecture leadership in both process and technology for Office Depot and all affiliates. This includes advising the CTO in the following areas:
- Security infrastructure strategic roadmap
- Security program development and delivery
- Security governance, policies, standards, guidelines and procedures
- Security infrastructure implementation, technology evaluation and solution recommendation
This position leads and manages a dedicated team of information security professionals, hires and trains new staff, conducts performance reviews, and provides leadership and coaching, including technical and personal development programs for team members. This role owns the Global IT Security infrastructure. It sets the security direction and standards for the organization. It requires close coordination and influence with the affiliated companies.
Primary Responsibilities:
- Lead the development, maintenance, communication and adoption of Information Security roadmaps and blueprints for Office Depot and affiliates.
- Develop and maintain Information Security governance, policies, standards, guidelines and procedures across all business units.
- Identify and present risk management issues to the CTO and IT Leadership team and support the security incident response process.
- Collaborate with IT, Legal, Audit, Compliance and other teams to develop and implement controls and configurations aligned with security policies and legal, regulatory and audit requirements.
- Consult with IT, security staff and stakeholders to ensure that security is factored into the evaluation, selection, installation and configuration of hardware, applications and software.
- Lead cross-functional security teams to implement and maintain a global security program to protect, detect and respond to security threats.
- Cultivate a security risk-aware environment where decision makers and staff understand and care about information security and consider security implications in their decision making.
- Develop and maintain supplier and consulting relationships and service contracts.
- Monitor compliance with information security policies and procedures, referring issues to the appropriate management and executives.
- Explore, evaluate and recommend the use of strategic, cost-optimized security solutions that improve resiliency and/or functionality of the enterprise.
Education and Experience:
- Level of Formal Education: Bachelors degree or equivalent experience
- Area of Study: Computer Science, Information Management, or Engineering
- Years of Experience: Minimum 10 years’ experience in related field plus 7 years in a supervisory role
- Type of Experience:
- Knowledge of industry practices and technical systems, and an understanding of the potential use of technology solutions in a business environment
- Security leadership experience in retail industry a plus
- Special Certifications:
- Professional designation/certification Certified Information Systems Security Professional (CISSP) or Certified Information Security Manager (CISM) is required
- Language Skills: English
- Technical Competencies:
- Experience with internationally recognized information security management best practices, such as International Standards Organization (ISO) 2700x and NIST Cybersecurity Framework (CSF)
- Experience with applicable legal and regulatory requirements, including, but not limited to, the Sarbanes-Oxley Act (SOX), California Consumer Privacy Act (CCPA), and Payment Card Industry Data Security Standard (PCI DSS)
- Proficiency in performing risk, business impact, control and vulnerability assessments, and in defining treatment strategies
- Knowledge of and experience in developing and documenting security architecture and plans, including strategic, tactical and project plans
- Knowledge of and experience with cloud architecture deployments across key security domains, including, but not limited to, Data Security, Network Security and Identity & Access Management
- Familiarity with the principles of cryptography and cryptanalysis
- Familiarity with agile development methodologies
- An understanding of operating system internals and network protocols
- Skills and Abilities:
- Strong negotiation and ability to coach and guide associates toward new levels of contribution
- Proven ability to work and interact closely with senior management levels to determine their business needs and obtain support for initiatives
- Strong leadership and organizational experience
- Strong technology skills with the ability to synthesize relevant information and make key decisions
- Strong analytical skills to relate security requirements to appropriate security controls
- Strong project management skills and experience in creating and managing project plans, including budgeting and resource allocation
- Excellent communication abilities and relationship building skills
- Information Systems:
- Familiarity with Clarity, Jira, Oracle HCM, SailPoint, GLPI and SmartSheets is a plus
- Personal Attributes:
- A dedicated and self-driven desire to think creatively and produce results
- Strong ownership over their responsible area
- Well-developed bias for action, moves quickly to take action and has the appropriate level of urgency
- Other/Preferred:
- Written, verbal, and presentation skills with the ability to effectively interact with internal and external business partners
- Ability to think strategically
- Ability to present at the executive level
- Understanding of complex automated systems
- Personal experience in leading the successful design and delivery of at least 2 enterprise-wide security tool deployments
It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.
About The ODP Corporation
The ODP Corporation is a leading provider of products and services through an integrated business-to-business (B2B) distribution platform and omnichannel presence, which includes world-class supply chain and distribution operations, dedicated sales professionals, online presence, and a network of Office Depot and OfficeMax retail stores. Through its operating companies Office Depot, LLC and ODP Business Solutions, LLC, The ODP Corporation empowers every business, professional, and consumer to achieve more every day.
Disclaimer
The above statements are intended to describe the general nature and level of work being performed by associates assigned to this classification and are not intended to be a complete list of all responsibilities, duties and skills required of associates so classified. Other duties may be assigned.
Pay, Benefits & Work Schedule
The company offers competitive salaries, a benefits package, which includes a 401(k) and more, along with plenty of opportunity to move and grow within our organization! For immediate consideration for this exciting position, please click the Apply Now button.
How to Apply
Click the Apply Now button and follow the instructions on each page. When you have completed the application, click the submit button.
Application Deadline
The job posting will remain open for a minimum of 3 days and will expire once the position has been filled.
Equal Employment Opportunity
The company is committed to providing equal employment opportunities in all employment practices. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, citizenship status, marital status, age, disability, protected veteran status, sexual orientation or any other characteristic protected by law.
We will consider for employment qualified applicants with arrest and conviction records City & County of San Francisco Fair Chance Ordinance.