Senior Director of Cybersecurity POST NUMBER: 484304
|
Position Title: Sr. Director of Cybersecurity |
Reports To (Title Only): Chief Information Officer |
|
Department: Global Technology |
Supervises: YES |
|
Date: July 15, 2026 HR Number: |
|
POSITION SUMMARY
Reporting to the Chief Information Officer, the Sr. Director of Cybersecurity is LifeWave's senior cybersecurity leader, responsible for a risk-based cybersecurity program that protects company assets while supporting innovation, international growth, regulatory compliance, and digital commerce. This role provides leadership for protecting the confidentiality, integrity, and availability of company information assets, business systems, digital commerce platforms, distributor systems, cloud services, and corporate infrastructure.
The Sr Director of Cybersecurity partners with the cybersecurity risk committee (CIO, Legal, Compliance) and works closely with executive leadership, legal, privacy, infrastructure, application development, and business stakeholders to assess and manage cyber risk. The position is accountable for enterprise security architecture, threat management, vulnerability management, cyber resilience, incident response, identity and access management, security awareness, third-party security risk management, and cybersecurity governance.
Success is measured through a secure, resilient, scalable, business-aligned cybersecurity program supporting LifeWave's operations across multiple international markets.
SUPERVISORY RESPONSIBILITIES
-
Lead internal cybersecurity personnel and contractors.
-
Manage relationships with managed security providers, MDR providers, vulnerability management partners, penetration testing firms, and cybersecurity consultants.
-
Direct security architecture, security operations, security engineering, governance, risk, and incident response functions.
-
Provide leadership and mentorship for security professionals globally.
ESSENTIAL DUTIES AND RESPONSIBILITIES
Cybersecurity Strategy & Governance
-
Develop and maintain the enterprise cybersecurity strategy, roadmap, standards, and policies.
-
Establish a risk-based cybersecurity program aligned to business objectives and organizational risk tolerance.
-
Partner with executive leadership to ensure appropriate visibility into cyber risks and mitigation efforts.
-
Create and maintain governance processes, reporting mechanisms, and executive dashboards; provide regular updates to the CIO, General Counsel, and Cybersecurity Risk Committee, and support the CIO in preparing periodic Board updates.
-
Support the adoption and maintenance of security frameworks including ISO 27001, NIST, CIS Controls, and applicable regulatory requirements.
-
Establish cybersecurity KPIs, performance metrics, and service-level objectives for internal teams and external providers.
Security Operations & Incident Response
-
Direct enterprise security monitoring and detection capabilities through internal teams and managed security providers, including MDR, SIEM, EDR, and threat intelligence services.
-
Establish and maintain incident response procedures, playbooks, and crisis management processes; lead investigations and coordinate response across business and technology teams.
-
Conduct post-incident reviews and drive continuous improvement.
-
Ensure appropriate logging, monitoring, and forensic capabilities exist across the organization.
-
Establish governance and operational standards for Microsoft security capabilities, including Defender, Sentinel or equivalent SIEM integrations, Entra ID, conditional access, privileged access, endpoint protection, secure score management, and audit logging.
Vulnerability & Exposure Management
-
Own the technology vulnerability management program, including scanning, remediation governance, prioritization, and reporting.
-
Oversee external attack surface management and adversarial exposure validation.
-
Establish risk-based remediation programs and service-level expectations.
-
Track and report vulnerability trends, remediation performance, and risk posture.
-
Coordinate remediation with infrastructure, cloud, application, and business teams.
Security Architecture & Engineering
-
Establish enterprise security architecture standards and security design principles.
-
Review major technology projects and ensure cybersecurity requirements are incorporated throughout the project lifecycle.
-
Define secure architecture patterns for Microsoft 365 & Azure; SaaS E-commerce, ERP, and CRM systems; and internal and external AI.
-
Lead implementation of zero-trust security principles across corporate systems and applications.
-
Evaluate emerging cybersecurity technologies and make adoption recommendations.
Identity & Access Management
-
Mature governance and controls for identity and access management, including Microsoft Entra ID, privileged access management, MFA, conditional access, joiner/mover/leaver processes, and identity governance.
-
Ensure periodic access reviews and segregation-of-duty controls are maintained.
Governance, Risk & Compliance
-
Develop and manage cybersecurity risk assessments across the enterprise; bring risk acceptance decisions above a defined severity/impact threshold to the CIO or risk committee for approval.
-
Partner with legal, compliance, privacy, quality, and regulatory teams.
-
Develop security standards supporting responsible adoption of AI technologies including Microsoft Copilot, generative AI platforms, AI governance, data protection, and emerging AI-related cyber risks.
-
Support internal and external audits, and maintain cybersecurity metrics, risk reporting, and policy/control documentation.
-
Manage cybersecurity policy lifecycle and related control documentation.
-
Design, implement, monitor, and provide evidence for technical cybersecurity controls that support PCI-DSS, GDPR, CCPA, PIPEDA and similar
-
Support cyber insurance renewal, underwriting evidence, and control validation, as well as executive attestations, audit evidence packages, and board-level risk reporting as requested by the CIO, General Counsel, or designated governance body.
Third-Party Risk
-
Develop a vendor security assessment program.
-
Evaluate cybersecurity risks associated with vendors, suppliers, service providers, and technology partners.
-
Review security requirements in contracts and vendor agreements.
-
Participate in acquisition, implementation, and onboarding reviews for new technology solutions.
Security Awareness & Culture
-
Manage an enterprise security awareness program, including phishing simulation and training initiatives.
-
Foster a culture of shared responsibility for cybersecurity across all business units.
-
Develop executive and leadership-focused cyber-risk awareness programs.
Leadership & Financial Management
-
Develop and manage cybersecurity budgets.
-
Establish measurable cybersecurity objectives and key results.
-
Lead strategic planning and workforce development activities.
-
Build high-performing teams capable of supporting a global business environment.
-
Ensure vendor accountability through defined KPIs, SLAs, and outcome-based performance measures.
Role Boundaries and Decision Rights
-
Owns cybersecurity strategy, security architecture, technical security controls, vulnerability management, security monitoring, incident response coordination, identity security, and cybersecurity risk reporting.
-
Has authority to require remediation of critical cybersecurity risks, establish minimum security standards, and escalate unresolved risks through executive governance.
-
Partners with Legal, Compliance, and Privacy on regulatory interpretation, privacy obligations, breach notification decisions, external communications, and audit/compliance attestations.
-
Partners with Infrastructure, Platform Engineering, Enterprise Applications, and IT Product teams to ensure secure design, implementation, operation, and remediation of technology platforms.
-
May recommend risk acceptance, remediation plans, compensating controls, and escalation; formal acceptance of material cybersecurity risk requires approval by the CIO or designated governance body.
-
Does not independently own privacy-law interpretation, regulatory filings, contractual legal positions, or final compliance attestations unless expressly delegated by executive leadership.
QUALIFICATIONS AND EXPERIENCE
-
Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Engineering, or related field, or equivalent experience.
-
10 years of progressively responsible cybersecurity experience including 5 years leading cybersecurity programs and teams.
-
Experience operating in a multinational organization.
-
Comfortable operating as a hands-on, execution-oriented security leader in a growing organization, balancing program leadership with practical implementation, vendor oversight, and cross-functional remediation follow-through.
-
Experience working with cloud security technologies, particularly Microsoft Azure and M365.
-
Experience managing external cybersecurity service providers and remediation across teams that do not directly report to cybersecurity.
-
Experience with enterprise SaaS, e-commerce, cloud, and identity-centric security environments
Preferred
-
CISSP, CISM or similar certification
-
Experience building or maturing a cybersecurity program in a mid-sized or high-growth organization
-
Microsoft Security Certifications (SC-100, SC-200, SC-300)
TRAVEL
Occasional travel to global LifeWave locations.
EEO Notice
Vaco by Highspring is an Equal Opportunity Employer and does not discriminate against any employee or applicant for employment because of race (including but not limited to traits historically associated with race such as hair texture and hair style), color, sex (includes pregnancy or related conditions), religion or creed, national origin, citizenship, age, disability, status as a veteran, union membership, ethnicity, gender, gender identity, gender expression, sexual orientation, marital status, political affiliation, or any other protected characteristics as required by federal, state or local law.
Vaco by Highspring and its parents, affiliates, and subsidiaries are committed to the full inclusion of all qualified individuals. As part of this commitment, Vaco by Highspring and its parents, affiliates, and subsidiaries will ensure that persons with disabilities are provided reasonable accommodations. If reasonable accommodation is needed to participate in the job application or interview process, to perform essential job functions, and/or to receive other benefits and privileges of employment, please contact HR@vaco.com.
Vaco by Highspring also wants all applicants to know their rights that workplace discrimination is illegal.
Representation Notice
By submitting to this position, you agree that you will be giving Vaco by Highspring the exclusive right to present your as a candidate for the foregoing employment opportunity. You further agree that you have represented information about yourself accurately and have not affirmatively misrepresented your qualifications. You also agree to maintain as confidential, to the fullest extent permitted by law, any information you learn from Vaco by Highspring about the position and you will limit disclosure of information about the position only to the extent necessary to perform any obligations in furtherance of your application. In exchange, Vaco by Highspring agrees to exercise reasonable efforts to represent you through all solicitation, job screening and resume dispersal.
For residents of Ontario, Canada: Based on Highspring’s discussions with its Client, Highspring’s understanding is that this position for employment is a current vacancy (either through Highspring as a contractor or with the client directly).
Privacy Notice
Vaco by Highspring and its parents, affiliates, and subsidiaries (“we,” “our,” or “Vaco by Highspring”) respects your privacy and are committed to providing transparent notice of our policies.
- California residents may access Vaco by Highspring HR Notice at Collection for California Applicants and Employees here.
- Virginia residents may access our state specific policies here.
- Residents of all other states may access our policies here.
- Canadian residents may access our policies in English here and in French here.
- Residents of countries governed by GDPR may access our policies here.
Additionally, submissions to this position are subject to the use of AI to perform preliminary candidate screenings, focused on ensuring minimum job requirements noted in the position are satisfied. More details about Vaco by Highspring’s use of AI can be found here (https://www.highspring.com/ai-use-notices/). Further assessment of candidates beyond this initial phase will be conducted by recruiters and hiring managers. Vaco by Highspring does not know and cannot opine on if its client’s use of AI products in hiring.
Pay Transparency Notice
Determining compensation for this role (and others) at Vaco by Highspring depends upon a wide array of factors including but not limited to:
- the individual’s skill sets, experience and training;
- licensure and certification requirements;
- office location and other geographic considerations;
- other business and organizational needs.
With that said, as required by local law, Vaco by Highspring believes that the following salary range referenced above reasonably estimates the base compensation for an individual hired into this position in geographies that require salary range disclosure. The individual may also be eligible for discretionary bonuses.