Director, Cybersecurity Governance, Risk...

DIRECTV, Inc.
El Segundo, CA, United States
2 months ago
Apply on juju.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Compensation
$147,830.0 - $268,307.0
Working hours
Regular working hours
Job source

Tech stack

Testing (Software) Cyber Security PCI Data Security Standards Cyber Threat Analysis Information Technology CIS Benchmarks

Job description

The Director, Cybersecurity Governance, Risk and Compliance (GRC) is responsible for leading DIRECTV’s enterprise cybersecurity governance, risk management, compliance, policy, and security assurance programs. This role provides strategic leadership and operational oversight across cybersecurity governance functions, ensuring cybersecurity risks are effectively managed, regulatory and contractual obligations are met, and cybersecurity initiatives align with business objectives.

The Director serves as the primary leader for cybersecurity governance activities, executive cybersecurity reporting, risk management, compliance programs, security awareness initiatives, supplier security oversight, and security assurance testing programs.

This position manages a team of cybersecurity professionals and contractors and serves as a key partner to technology, business, audit, legal, procurement, privacy, and executive leadership teams.

Here’s what you’ll do:

Cybersecurity Governance

  • Lead the enterprise Cybersecurity Governance Program.

  • Develop and maintain cybersecurity KPIs, KRIs, scorecards, and executive reporting.

  • Prepare and facilitate monthly Cybersecurity Governance Reviews and executive presentations.

  • Track cybersecurity initiatives, remediation activities, and strategic priorities.

  • Drive accountability for cybersecurity performance across the organization.

Cyber Risk Management

  • Lead enterprise cyber risk identification, assessment, reporting, and remediation programs.

  • Maintain cybersecurity risk registers and risk treatment plans.

  • Facilitate risk reviews with business and technology stakeholders.

  • Present cybersecurity risk posture to senior leadership.

Policy, Standards and Governance

  • Own cybersecurity policies, standards, procedures, and governance frameworks.

  • Ensure alignment with industry standards and regulatory requirements.

  • Maintain governance processes supporting cybersecurity decision-making.

Compliance and Audit

  • Lead cybersecurity compliance activities supporting PCI DSS, SOX, regulatory, and contractual requirements.

  • Coordinate internal and external audits.

  • Manage remediation efforts resulting from audit findings and assessments.

  • Maintain cybersecurity control documentation and evidence repositories.

Third-Party and Supplier Security

  • Lead Supplier Information Security Requirement (SISR) governance and oversight.

  • Manage third-party cybersecurity risk assessments and monitoring.

  • Partner with Procurement, Legal, and Vendor Management organizations to ensure supplier security compliance., + Direct leadership responsibility for Cybersecurity Governance, Risk and Compliance functions.

  • Oversight of approximately six contractor resources and future employee growth within the GRC organization.

  • Enterprise-wide responsibility for cybersecurity governance, risk management, compliance, policy, awareness, supplier security, and security assurance oversight.

May require a background check due to job duties requiring routine access to DIRECTV and DIRECTV customer’s proprietary data. Qualified applicants with arrest and conviction will be considered for employment in accordance with local ordinances and state law.

This is a remote position that can be located anywhere in the contiguous United States. #LI-Remote

A career with us comes with big rewards:

DIRECTV’s compensation structure is designed to be market-competitive and fully supports efforts to attract and retain employees. It is the company’s policy to offer pay that is competitive with other employers in the local market. Our salary ranges are determined by role, level, and location.

Requirements

  • Bachelor’s degree in Cybersecurity, Information Technology, Business, Engineering, or related field.

  • 5 - 7 years required, 10+ years desired progressive cybersecurity experience.

  • 5+ years of leadership experience managing cybersecurity programs and teams.

  • Deep knowledge of cybersecurity governance, risk management, compliance, and security frameworks.

  • Experience with PCI DSS, NIST Cybersecurity Framework, ISO 27001, CIS Controls, and risk management methodologies.

  • Experience presenting cybersecurity metrics and risk information to executive leadership.

  • Strong written and verbal communication skills.

Preferred

  • CISSP, CISM, CRISC, CGEIT, PCI ISA, or equivalent certifications.

  • Experience leading enterprise cybersecurity governance programs.

  • Experience in telecommunications, media, technology, or highly regulated industries.

  • Experience building cybersecurity governance organizations during periods of transformation or separation activities.

Reporting Relationship

Benefits & conditions

The Base Salary range displayed below reflects the minimum and maximum target salary for each of DIRECTV’s 4 (four) US Labor Market Zones. Within the range, individual pay is determined by work location and additional factors, including job-related skills, experience, and relevant education or training.

DIRECTV WAGE ZONES: $147,830 - $268,307

Low (N1): $147,830 - $221,645

Mid (N2): $155,610 - $233,310

High (N3): $171,171 - $256,641

Top (N4): $178,952 - $268,307

Click HERE (https://tbcdn.talentbrew.com/company/390/pdf/GeoZone-by-DMA-003.pdf) to review information on some of the largest Designated Market Areas (DMAs). Your recruiter can share more about the specific salary range for your preferred location during the hiring process.

Please note that the salary ranges reflect base salary only and do not include bonus or benefits - when you consider all of these together, it represents a pretty impressive total compensation package.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on juju.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:49 min

Comparing software testing and software verification

Onur Kasimlar Onur Kasimlar · World Congress 2025

2:15 min

Auditing container configurations against CIS benchmark security standards

Madhu Akula · LIVE

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

3:02 min

Navigating DORA compliance and executive liability in security

Michele Zuccala Michele Zuccala +4 · World Congress 2026 Europe

2:56 min

Test automation strategy and following the testing pyramid

Daniel Strmečki +1 · World Congress 2022

3:39 min

Validating data queries and infrastructure security configurations

Philipp Krenn · World Congress 2023

Videos

See all

Related articles

See all