We are looking for an experienced Director of Cyber Security to lead a comprehensive, enterprise-wide security program in Utah. This leader will work closely with executives and cross-functional teams to strengthen risk management, protect critical systems, and advance a resilient security posture that supports business growth. The role requires a strategic thinker who can also guide operational execution across governance, architecture, incident response, and identity security.
Responsibilities:
• Shape and oversee the organization’s cybersecurity strategy, long-term roadmap, and policy framework to align security priorities with business objectives.
• Collaborate with executive leaders, legal, compliance, privacy, and technical teams to evaluate cyber risk and drive practical mitigation plans.
• Direct security operations across monitoring, detection, response, and recovery activities to improve readiness against evolving threats.
• Lead the design and maturity of incident response plans, investigation procedures, and post-event improvement efforts.
• Manage enterprise vulnerability and exposure management programs, including prioritization, remediation tracking, and risk reporting.
• Provide leadership for security architecture and engineering to ensure infrastructure, cloud platforms, applications, and business systems are designed with appropriate protections.
• Oversee identity and access management practices, including access controls, authentication standards, and related governance measures.
• Supervise internal security team members, contractors, and external partners while setting performance expectations and encouraging focused growth.
• Establish cybersecurity metrics, dashboards, and reporting for senior leadership to communicate program effectiveness, risk posture, and vendor performance.• 10+ years of progressive experience in cybersecurity leadership, including responsibility for enterprise security programs.
• Strong expertise in cybersecurity operations, vulnerability analysis, and security architecture within complex business environments.
• Demonstrated knowledge of identity and access management principles, governance frameworks, and risk and compliance practices.
• Experience leading incident response efforts, threat detection capabilities, and cross-functional security investigations.
• Ability to engage effectively with executive leadership and translate technical risk into business-focused recommendations.
• Proven success leading and mentoring security professionals, contractors, and third-party service providers.
• Familiarity with security technologies and controls used to protect endpoints, cloud environments, and enterprise access systems.