Sr. Director, Cybersecurity

🏢 Carhartt
📍 United States
💰 USD 201,300 - 281,750 / annual
📅 Posted Sep 16, 2026 · via Himalayas
🏷 Cybersecurity Leadership, Director Of Cybersecurity, It Security Management, Security Governance, Information Security Management, Cybersecurity Director +3 more
Apply on original site ↗

Position Details:

Title: Sr. Director, Cybersecurity Department: Information Technology Reports to: VP, IT Infrastructure and Security Location: Dearborn Job Classification: Remote FLSA Status: Exempt Job Band: Executive Job Summary The Senior Director of Cybersecurity is the enterprise leader accountable for the strategy, governance, operational effectiveness, and continual maturation of the cybersecurity program. The role leads four integrated capabilities: Security Engineering, Security Operations, Identity and Access Management, and Governance, Risk, and Compliance. This leader protects the confidentiality, integrity, and availability of information assets while enabling business objectives through risk-informed decision-making, resilient security architecture, effective operations, and clear accountability.

The position partners closely with the enterprise risk function to translate cyber threats, control gaps, and technology dependencies into business-oriented risk statements, scenarios, and reporting that can be aggregated into the overall enterprise risk program. The role regularly advises senior executives and business leaders, establishes investment priorities, and provides concise reporting on cyber risk exposure, program performance, resilience, and remediation progress.

Inspired by Hard Work At Carhartt , the values of hard work—dependability, honesty, and trust—are rooted in the legacy of our founder, Hamilton Carhartt . His commitment to serving hardworking people continues to inspire everything we do. Guided by his legacy and our mission—We serve and protect all hardworking people by building durable products—we remain dedicated to upholding these principles in every decision we make and every product we create. Associate Responsibilities

- Own and execute a multi-year enterprise cybersecurity strategy and roadmap aligned with business priorities, risk appetite, technology strategy, and regulatory obligations.

- Lead, coach, and develop leaders and teams across the four cybersecurity functions; establish clear decision rights, succession plans, talent pipelines, operating rhythms, and measurable performance expectations.

- Advise executive leadership on material cyber risks, emerging threats, major incidents, strategic tradeoffs, and investment needs using clear business and financial context.

- Own the cybersecurity operating model, annual planning, budget, workforce strategy, sourcing model, vendor portfolio, and prioritization of capabilities and initiatives.

- Establish program-level objectives, key risk indicators, key performance indicators, maturity targets, and executive reporting that demonstrate risk reduction and operational outcomes.

- Build strong partnerships across Information Technology, Enterprise Risk, Legal, Privacy, Internal Audit, Compliance, Human Resources, Finance, Supply Chain, and business functions.

- Define and maintain the enterprise cybersecurity strategy, target-state capabilities, policy architecture, control framework, and prioritized roadmap.

- Provide strategic direction for enterprise security architecture and security-by-design practices across cloud, on-premise, applications, infrastructure, data, and third-party services.

- Present cyber risk posture, incidents, trends, program performance, and investment recommendations to senior leadership and appropriate governance bodies.

- Lead annual and long-range planning, including budget development, capital and operating forecasts, resource allocation, sourcing decisions, and benefits realization.

- Oversee major cybersecurity transformation initiatives and ensure dependencies, risks, milestones, and outcomes are actively managed.

- Maintain external awareness of threat, regulatory, technology, and industry developments; translate relevant changes into program priorities.

- Establish a threat-informed operating model with clear severity criteria, escalation paths, service levels, playbooks, evidence requirements,

← All remote jobs

Get new remote jobs like this by email
Daily email, only when there's something new. One click to stop.

Get remote jobs like this by email

10 hand-picked jobs, one email a day. No spam, unsubscribe anytime.

Similar for you