Job Summary:
Kilroy Realty Corporation is focused on advancing its cybersecurity strategy and is seeking a Vice President of Cybersecurity to lead this initiative. This role involves overseeing the company's cybersecurity program, managing a growing team, and ensuring alignment with business priorities while delivering measurable outcomes.
Responsibilities:
• Define and lead an enterprise cybersecurity strategy aligned to business, technology, and regulatory priorities, owning outcomes end to end.
• Establish risk-based governance frameworks that embed security into investment decisions, solution design, and operational workflows across hybrid environments.
• Serve as the company's top cybersecurity authority, aligning priorities across IT, Legal, Compliance, Risk, and business units.
• Deliver clear, actionable executive reporting on cyber risk, program maturity, investments, and readiness, ensuring no surprises for stakeholders.
• Elevate IT's business advisory capability by delivering business-focused technology assessments, options and impact analyses, and process reviews that position IT and Cybersecurity as trusted internal consultants.
• Translate complex risk into simple, decision-ready narratives; influence technology roadmaps, architecture choices, and investment trade-offs.
• Drive a metric-driven operating rhythm that connects cyber posture to business outcomes and financial discipline.
• Build and maintain a scalable, intentional cybersecurity architecture across cloud, on-premises, and operational technology (OT) environments.
• Oversee core platforms including EDR/MDR, Microsoft Defender, Azure AD / Entra ID and Azure native controls, and SIEM technologies; continuously optimize coverage, fidelity, and value realization.
• Set enterprise standards for IAM, endpoint protection, vulnerability management, network segmentation, OT/IoT security, and secure configuration baselines.
• Embed security into solution architecture, engineering, CI/CD, and service delivery through partnerships with infrastructure, networking, and application teams.
• Maintain a vendor and third-party risk management program that ensures security requirements extend to managed service providers, technology partners, and contractors with access to Kilroy systems or data.
• Own Disaster Recovery (DR) readiness across enterprise systems by establishing system-specific Recovery Time Objective (RTO) and Recovery Point Objective (RPO) targets and controls, maintaining clear and actionable DR runbooks, conducting annual DR simulations to validate recovery capabilities, and integrating DR with the enterprise Business Continuity Plan (BCP) to ensure end-to-end continuity of operations.
• Ensure cybersecurity incident response processes include appropriate regulatory and disclosure readiness, including SEC reporting obligations and audit committee communication protocols consistent with Kilroy's obligations as a publicly traded company.
• Apply preemptive leadership principles to identify emerging risks early and drive mitigation before impact.
• Build and mentor a high-performing cybersecurity team focused on ownership, transparency, collaboration, and measurable delivery.
• Own and drive enterprise security awareness as a core program — designing and delivering training, simulations, and communications that build a security-conscious culture across the organization. Measure adoption, track behavior change, and continuously improve program effectiveness to reduce human risk.
• Promote a culture of accountability and no surprises, ensuring leaders operate with clarity, accountability, and fiscal discipline.
Qualifications:
Required:
• 15+ years of progressive cybersecurity leadership experience, with 10+ years leading enterprise-scale programs at the Director/VP level.
• Proven success building or maturing security programs in complex, hybrid (cloud and on-premises) environments; experience with OT/IoT security preferred.
• Deep expertise in enterprise security architecture, cloud governance, identity frameworks, endpoint protection, and third-party risk management.
• Hands-on familiarity with enterprise EDR/MDR, email security, identity and access management, network detection, and SIEM platforms.
• Demonstrated experience leading cybersecurity incident response, including regulatory notification and executive disclosure processes.
• Proven ability to design and manage enterprise security awareness programs with measurable behavior change outcomes.
• Experience managing cybersecurity budgets, vendor contracts, and managed service relationships at enterprise scale.
• Track record of communicating cybersecurity risk and program performance to executive leadership and audit committees.
• Demonstrated ability to build trust across functions, influence without authority, and operate as a collaborative partner to IT, Legal, Compliance, Risk, and business leadership.
• Experience in regulated industries; real estate, financial services, or public company environments preferred.
• Exceptional executive communication skills.
• Strong understanding of NIST, ISO 27001, CIS Controls, and enterprise risk frameworks.
Preferred:
• Experience with OT/IoT security preferred.
• Experience in regulated industries; real estate, financial services, or public company environments preferred.
• Relevant certifications are strongly preferred (CISSP, CISM, CCSP, or equivalent).
Company:
Kilroy Realty Corporation (NYSE: KRC) is a leading U.S. Founded in 1996, the company is headquartered in Los Angeles, USA, with a team of 201-500 employees. The company is currently Growth Stage.