> Markdown version of [/jobs/ext/2987303-director-data-applications-security](https://www.wearedevelopers.com/jobs/ext/2987303-director-data-applications-security). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Director, Data & Applications Security - **Company:** Smithfield Foods, Inc. - **Location:** Smithfield, VA, United States - **Experience:** Expert - **Salary:** $160,000.0 - $202,500.0 - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Static Program Analysis, Code Review, Databases, Data as a Services, Information Leak Prevention, Data Masking, Data Security, Open Web Application Security, Systems Development Life Cycle, Sherwood Applied Business Security Architecture, Software Engineering, Tokenization, Software Vulnerability Management, Data Processing, Cloud Platform System, Data Classification, Software Security, Mitre Att&ck, Togaf, Hardware Asset Management - **Published:** September 18, 2026 - **Apply:** https://diversityjobs.com/main/sendform/8/8/28176/1/18353530?backUrl=%2Fcareer%2F18353530%2FDirector-Data-Applications-Security-Virginia-Smithfield ## About the Role To perform this job successfully, an individual must be able to perform each essential duty satisfactorily. The requirements listed below are representative of the knowledge, skill, and/or ability required. Reasonable accommodations may be made to enable individuals to perform the essential functions. * Education & Experience: Bachelor's degree from an accredited four-year college or university and 10+ years of relevant experience in Data & Applications Security; or equivalent combination of education and experience required. * Leadership: 5+ years of demonstrated experience in team management/development required. * Certifications: CISSP, CISM, or equivalent certification is required. * Enterprise Experience: Experience working in multinational organizations with complex, integrated IT and OT environments. * Data Protection Expertise: Proven knowledge in data classification strategies, high-risk data handling, data masking, tokenization, encryption, and cryptographic controls. * AI Risk and Governance: Knowledge and experience implementing, managing, and assessing AI risk and governance frameworks. * SDLC & Application Security: Deep understanding of Secure Software Development Lifecycle (SSDLC), code review methodologies, and static/dynamic code analysis. * Risk & Security Strategy: Strong background in risk management, cybersecurity strategy development, and implementation of related technologies and tools. * Frameworks & Standards Proficiency: Working knowledge of SABSA, TOGAF, NIST, ISO 27000, and familiarity with OWASP Top 10, SANS 25, MITRE ATT&CK, and CWEs. * Communication Skills: Excellent written and verbal communication skills, with the ability to effectively engage and negotiate across all levels of the organization. * Collaborative Work Ethic: Respects others, works well in fast-paced environments, and builds strong, team-oriented relationships. OTHER SKILLS THAT MAKE YOU STAND OUT: * MS IT or MBA preferred. ## Description The below statements are intended to describe the general nature and level of work being performed by people assigned to this job. They are not intended to be an exhaustive list of all responsibilities, duties, and skills required of personnel so classified. May perform other duties as assigned. * Strategic Collaboration: Regularly meet with the CISO and align with Data Services and Infrastructure leadership to ensure strategic alignment, business satisfaction, and continuous improvement in cybersecurity services. * Data Security Governance: Develop and implement enterprise-wide data classification, taxonomy, and governance policies to drive consistent data protection and compliance. * Data Loss Prevention: Develop, manage, monitor, and deploy the enterprise strategy and tools for data loss prevention. * Risk Management: Identify, measure, and minimize security risks across application, database, network, host, artificial intelligence, and cloud environments with a focus on data and application security. * Capability Assessment & Roadmap: Assess the effectiveness of current data security capabilities, identify gaps, and develop a comprehensive security strategy and execution roadmap. * Vulnerability Management: Collaborate with IT and OT leaders to manage vulnerabilities in systems supporting data and application functions. * Vendor Oversight: Manage security vendor relationships and evaluate the effectiveness of products and services related to data and application protection. * Audit & Compliance Support: Support internal and external cybersecurity audits for systems and service providers to ensure regulatory and policy compliance. * Software and Asset Management: Set direction, manage, and support software and hardware asset management standards, capabilities, and reporting. * Leadership: Drives a positive employee experience through leadership by way of employee development and coaching. ## Related Videos - [Are Code Reviews Worth It? Insights from 16 Years of Review Data](https://www.wearedevelopers.com/videos/1135-are-code-reviews-worth-it-insights-from-16-years-of-review-data) - [Kubernetes and Microservices with Multi-Model Databases](https://www.wearedevelopers.com/videos/382-kubernetes-and-microservices-with-multi-model-databases) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Build a CI/CD pipeline to automate code reviews and ensure code quality](https://www.wearedevelopers.com/videos/349-build-a-ci-cd-pipeline-to-automate-code-reviews-and-ensure-code-quality) - [Fault Tolerance and Consistency at Scale: Harnessing the Power of Distributed SQL Databases](https://www.wearedevelopers.com/videos/1146-fault-tolerance-and-consistency-at-scale-harnessing-the-power-of-distributed-sql-databases) - [Organizational Change Through The Power Of Why - DevSecOps Enablement](https://www.wearedevelopers.com/videos/478-organizational-change-through-the-power-of-why-devsecops-enablement) ## Related Articles - [Dev Digest 234: How X's Feed Works, Top 10 CI/CD Risks & Meat Proxies](https://www.wearedevelopers.com/magazine/755-dev-digest-234-how-x-s-feed-works-top-10-ci-cd-risks-meat-proxies) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Now is the time for industrialized software development](https://www.wearedevelopers.com/magazine/601-now-is-the-time-for-industrialized-software-development) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)