Director, Information Security

MetroGistics Holdings, LLC
St. Louis, MO, United States
about 1 month ago
Apply on www.indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
7 years minimum
Compensation
$170,000.0 - $180,000.0
Working hours
Regular working hours
Job source

Tech stack

Artificial Intelligence Cyber Security Phishing Software Vulnerability Management Information Technology Patch Management

Job description

Reporting directly to the Chief Information Officer, this highly visible leadership role will serve as the single accountable owner for information security across the organization. You will have the opportunity to shape the future of cybersecurity at ACERTUS- developing our enterprise security strategy, strengthening governance and risk management, overseeing security operations and external partners, and ensuring our security capabilities continue to evolve alongside the business.

This is an opportunity for a security leader who enjoys both building strategy and making it happen. You will operate as a trusted advisor to executive leadership while remaining close enough to the work to drive implementation, solve problems, assess emerging risks, and create measurable improvements across the organization.

You will lead one direct report and oversee relationships with outsourced NOC/SOC providers and security vendors while partnering closely with leaders across Technology, Operations, Legal, Compliance, and other areas of the business.

What You’ll Do

  • Develop and execute ACERTUS’ enterprise information security strategy and multi-year security roadmap.
  • Establish and mature security governance, policies, standards, procedures, and enterprise risk-management practices.
  • Maintain visibility into organizational cyber risk and lead decisions related to risk mitigation, transfer, and acceptance.
  • Oversee outsourced NOC/SOC providers and other security partners, ensuring clear expectations, accountability, service levels, and escalation processes.
  • Lead cybersecurity incident response activities across preparation, detection, containment, recovery, post-incident review, and continuous improvement.
  • Advance vulnerability and patch-management capabilities and establish measurable remediation expectations and security performance metrics.
  • Build and mature third-party cybersecurity risk-management practices, including vendor assessments and ongoing risk monitoring.
  • Lead security compliance and audit-readiness efforts, including SOC 2 and frameworks such as NIST CSF and ISO 27001.
  • Monitor emerging cybersecurity risks and technologies-including the evolving impact of artificial intelligence-and implement appropriate controls.
  • Serve as the primary security advisor for customer security requirements, regulatory inquiries, and internal and external audits.
  • Lead the Security Oversight Committee and provide clear, actionable reporting on cybersecurity posture, risk, and priorities to executive leadership and the Board.
  • Champion a strong culture of security awareness through education, training, and phishing simulation programs.
  • Lead and develop internal security talent while building scalable capabilities to support ACERTUS’ continued growth., During your first several months, you’ll develop a comprehensive understanding of ACERTUS’ security environment, assess the current threat landscape and security partners, evaluate audit and SOC 2 readiness, and establish clear direction around patch management, third-party risk, and security priorities.

From there, you’ll begin putting a scalable security strategy into action- strengthening security and AI awareness, advancing remediation and third-party risk programs, optimizing external security partnerships, demonstrating measurable improvements, and preparing to communicate recommendations and progress alongside the CIO to executive leadership and the Board.

Requirements

We’re looking for a well-rounded cybersecurity leader who can move comfortably between enterprise strategy and hands-on execution. You should bring the credibility to advise executives and present to senior leadership while also having the curiosity and practical mindset to dig into security operations, vendor performance, vulnerabilities, incidents, and risk., * Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or a related field, or an equivalent combination of education and experience.

  • 7+ years of progressive information security experience, including experience leading or playing a significant role in an enterprise security program.
  • Experience developing cybersecurity strategy, governance, risk-management programs, and security roadmaps.
  • Demonstrated experience building, standing up, or significantly maturing security programs and capabilities.
  • Experience communicating cybersecurity risk, strategy, and performance to executive leaders, Boards, or governance committees.
  • Knowledge of SOC 2 and security frameworks such as NIST CSF and/or ISO 27001.
  • Experience overseeing outsourced security providers such as NOC/SOC, MSSP, or MDR partners.
  • Experience with third-party or vendor cybersecurity risk management.
  • Current CISSP, CISM, or equivalent security certification.
  • Strong executive presence, communication skills, and the ability to build trusted relationships across technical and non-technical teams., * Experience with AI-related cybersecurity risks, controls, or security practices.
  • Experience with SOC 2 audit readiness, vulnerability management, or enterprise patch-management programs.
  • Experience supporting customer security requirements and assessments.
  • Experience working within complex environments involving multiple systems, integrations, acquisitions, or legacy applications.
  • Experience within transportation, logistics, automotive, or another operationally complex industry.
  • Experience working in a high-growth or private equity-backed organization.
  • A Master’s degree or additional certifications such as CISA, GIAC, or CCSP.

Benefits & conditions

3.03.0 out of 5 stars St. Louis, MO 63123 Remote $170,000 - $180,000 a year, The anticipated base salary range for this position is $170,000-$180,000, depending on experience, skills, and qualifications. This position is also eligible for an annual bonus opportunity.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:29 min

Evaluating phishing emails that leverage artificial time constraints

Mauro Verderosa · LIVE

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

2:01 min

The necessity of developer intelligence amidst automated attack generation

Julian Totzek-Hallhuber Julian Totzek-Hallhuber · World Congress 2024

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

1:48 min

Use cases for managing micro frontend dependency versions

Lucas Braeschke Lucas Braeschke +1 · World Congress 2025

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

Videos

See all

Related articles

See all