> Markdown version of [/jobs/ext/1113675-group-director-cyber-risk-security-engineering](https://www.wearedevelopers.com/jobs/ext/1113675-group-director-cyber-risk-security-engineering). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Group Director, Cyber Risk & Security Engineering - **Company:** Chanel - **Location:** New York, NY, United States - **Experience:** Expert - **Salary:** $127,000.0 - $195,000.0 - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Microsoft Azure, Cloud Engineering, Encodings, Cyber Security, Information Leak Prevention, Identity and Access Management, PCI Data Security Standards, Ansible, Security Information and Event Management, Software Engineering, Google Cloud, Information Technology, Cybercrime, Terraform, Devsecops - **Published:** June 30, 2026 - **Apply:** https://cc.wd3.myworkdayjobs.com/ChanelCareers/job/New-York/Group-Director--Cyber-Risk---Security-Engineering_JOBREQ00114152-1 ## About the Role * Extensive hands-on experience in cyber engineering, implementing and managing enterprise security solutions across cloud-native and hybrid environments (Azure, AWS, GCP), networks, and endpoints * Proficiency in secure software development, DevSecOps, and infrastructure-as-code (Terraform, Ansible), embedding security in CI/CD pipelines * Advanced expertise with security technologies (SIEM, EDR, PAM, firewalls, encryption), focusing on governance and reporting * Strong leadership conducting threat modeling, technical assessments, and remediation * Deep knowledge of secure communications, identity and access management, and data loss prevention * Practical experience applying industry frameworks and standards (NIST 800-53, ISO 27001, CIS) to achieve scalable, business-aligned security outcomes * Experience with PCI DSS assessments and readiness (preferred) * Proven ability to communicate complex technical and risk concepts clearly to senior leadership, * Hybrid work model with 3 days onsite required * Minimum of 10 years in cyber security engineering, including hands-on leadership in designing and implementing security solutions, risk assessments, and awareness programs across complex enterprise environments * Bachelor's degree in computer science, information technology, or equivalent; Security-specific certifications (such as CISSP, CISM, CISA) are preferred ## Description CHANEL is hiring a Group Director, Cyber Risk & Security Engineering. We are looking for a Security Engineering, Governance and Cyber Risk champion to join our Information Security Team onsite in the New York City area. You will play a leading role, reporting directly into the Head of Information Security, in safeguarding the integrity and reputation of The House by ensuring adherence to regulatory requirements, industry standards, and internal policies, while garnering awareness to influence behavior change. You will collaborate cross-functionally with teams across the enterprise including Tech, Legal, Operations, Retail, and with our global partners to assess risks, implement continuous monitoring programs, and drive a culture of cyber resilience and accountability across the organization. Our ideal candidate will demonstrate a unique blend of leadership, information security domain expertise, strong risk management acumen, business judgement, creativity, entrepreneurial spirit, communication skills, and embrace diverse perspectives. What impact you can create at CHANEL: * Strengthen CHANEL's ability to identify, assess, and prioritize cyber risks, enabling confident decision-making on remediation, acceptance, or transfer * Lead the implementation and integration of security controls across digital and physical environments, collaborating with engineering, architecture, and operations to embed robust protection at every layer * Translate technical risks into actionable requirements and behaviors, fostering a culture of secure operations and empowering teams enterprise-wide * Build and scale impactful security awareness programs, driving measurable behavior change and elevating security practices across corporate, retail, and operations environments * Drive a scalable, intuitive approach to identity and access governance, ensuring the right individuals have timely access while minimizing business friction * Identify and address information security program gaps, advising on remediation and influencing adoption in partnership with the Head of Information Security * Act as a decisive tech leader, taking informed risks and making recommendations quickly within a complex, matrixed organization You are energized by: * Delivering security as a service to a large, complex organization with both online and physical retail presence in a rapidly growing environment with cyber threats that are continuously evolving * Developing and elevating security processes for efficiency and easy adoption while delivering high-quality scalable solutions that minimize cyber risk * Fostering a message that information security enables the business and its objectives by educating and garnering awareness to a range of audiences, both technical and non-technical, while also actively listening to their needs ensuring alignment with program versus organizational objectives * Working in a highly collaborative environment as a courageous leader and developing talent to support the growth of the business * Navigating complexity and monitoring risk on the regional and global level in close partnership with the wider Information Security team driving consistent transformation and change ## Related Videos - [Dev & Test in the Cloud? Deploy your cloud environments with Ansible & Terraform](https://www.wearedevelopers.com/videos/1607-dev-test-in-the-cloud-deploy-your-cloud-environments-with-ansible-terraform) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Infrastructure as Code: The Developer's Secret Weapon](https://www.wearedevelopers.com/videos/1221-infrastructure-as-code-the-developer-s-secret-weapon) - [A Brief History of Data Storage](https://www.wearedevelopers.com/videos/974-a-brief-history-of-data-storage) - [Terraform for Developers](https://www.wearedevelopers.com/videos/3-terraform-for-developers) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Building Security Champions](https://www.wearedevelopers.com/magazine/87-building-security-champions) - [The Best Software Developer Blogs to Read](https://www.wearedevelopers.com/magazine/156-the-best-software-developer-blogs-to-read)