Director - Cyber Security
The Director of Cyber Security will report to the companies Chief Information Security Officer and is a senior level cyber role responsible for overseeing enterprise cybersecurity (IT / OT). The role manages all aspects of cyber security including, GRC, strategy, design, development, implementation, incident response, budgets, and adherence to various regulations, standards, and cyber frameworks.
The candidate will coordinate security activities across Georgia-Pacific's (GP) operating units and internal shared services providers in a complex multi-business, multi-platform IT environment. The role will assess new security solutions, determine effectiveness of existing solutions and work with internal teams to implement security. The candidate will facilitate the creation of security policies, standards & procedures across business and manufacturing environments. Additionally, provide leadership in development of security metrics, dashboards and execution of audit & assurance activities as needed.
The ideal candidate will provide strategic leadership, have extensive experience in leading cyber security functions and be well versed in cyber security technologies within both business and manufacturing environments. They must have a strong passion to work in a collaborative team environment to take a security to the next level.
Key Responsibilities :
- Lead all aspects of cyber security including GRC, strategy, design, development, implementation, incident response, budgets, and adherence to various regulations.
- Facilitate development of security roadmaps with manufacturing and business IT teams.
- Consult with business units and manufacturing teams to ensure security solutions are designed and implemented to support manufacturing, cloud, IoT strategies and mobile technologies.
- Ensure development of an ongoing security assurance program to audit, monitor and verify the effectiveness of security; analyze data, develop trend analysis, and ensure compliance to existing standards, policies, and procedures.
- Develop methodologies and perform security framework audits to identify gaps and drive implementation of security policies, standards, and best practices across the organization.
- Manage and implement strategic security projects and initiatives as required.
- Regularly communicate security strategy and posture to all levels of leadership.
- Ensure compliance to legal / audit / government regulations and policies regarding cybersecurity (CFATS, MTSA, other regulatory requirements).
Knowledge, Skills & Abilities :
Leadership, strategic thinking, ability to set a vision and gain alignment across the organization.Ability to communicate clearly, concisely and confidently (oral, written, presentation).Superior interpersonal and consultative skills with ability to manage others.Strong experience in a Microsoft centric infrastructure and clear understanding of modern security tools, networking, authentication methods and cloud security capabilities.Highly motivated and self-directed with strong organizational and project management skills.Strong knowledge in implementing and operating various security frameworks such as ISO 27001, NIST 800-53, NIST Cybersecurity Framework, C2M2, COBIT, or similar.Ability to thrive in a dynamic landscape, exhibiting flexibility and adaptability in managing workloads, navigating high-pressure scenarios, meeting deadlines, and seamlessly adapting to evolving circumstances.Experience in managing security teams in large, federated organizations.Working knowledge in Microsoft security technologies, Active Directory, domain structures, user authentication, networks, and security monitoring capabilities.Hold one or more Industry security certifications, such as Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Systems Security Certified Practitioner (SSCP) or Global Information Assurance Certification (GIAC)Proven experience in operating a cyber program within industry best practices and cyber frameworks such as ISO 27001, NIST 800-53, NIST Cybersecurity Framework, C2M2, COBIT.A track record of successfully implementing cybersecurity measures, demonstrating your ability to manage complexities and security requirements specific to this environment.As a Koch company and a leading manufacturer of bath tissue, paper towels, paper-based packaging, cellulose, specialty fibers, building products and much more, Georgia-Pacific works to meet evolving needs of customers worldwide with quality products. In addition to the products we make, we operate one of the largest recycling businesses. Our more than 30,000 employees in over 150 locations are empowered to innovate every day to make everyday products even better.
At Koch, employees are empowered to do what they do best to make life better. Learn how our business philosophy helps employees unleash their potential while creating value for themselves and the company.