Sr. Director, Information Security: CloudSec & GRC (Remote)

iHerb · Remote

Company

iHerb

Location

Remote

Type

Full Time

Job Description

The Senior Director, Information Security position plays an integral role in protecting iHerb from internal and external threats and works closely with key business stakeholders and technology teams to implement and improve an efficient information security program that embeds security throughout all processes and systems. This role will also ensure that operational, legal, regulatory, and security risks related to IT are assessed and mitigated in a cost-effective manner in accordance with the business requirements.


Job Expectations:
•    This is a leadership role that has accountability for identifying, evaluating, reporting, and managing information security risks in ways that meet security, compliance, and regulatory requirements with focus on GRC and Cloud Security.
•    Develop a vision and strategy for trust, comprised of cybersecurity, compliance, and risk management, that will include measurable goals, objectives, and metrics
•    Design, develop, coordinate, and document the secure operation of information systems and develop best practices for securing enterprise-wide data and information systems
•    Ensure cloud security practices align with relevant industry standards, regulations, and compliance frameworks. Lead efforts to maintain and obtain necessary certifications.
•    Oversee the implementation of advanced security monitoring and analysis tools to detect and respond to security incidents and vulnerabilities 
•    Evaluate the security posture of third-party cloud providers and vendors. Develop and implement strategies to manage and mitigate associated risks.
•    Build, mentor, and lead a team of cloud security and GRC professionals. Foster a collaborative and innovative work environment that encourages skill development and knowledge sharing.


Knowledge, Skills and Abilities:
•    Master’s degree in an Information Technology related field of study or equivalent post-high school education and/or work-related experience 
•    Strong team leadership skills of direct teams in Cybersecurity, Security Architecture and Engineering, Education and Awareness, Governance Risk and Compliance, and Identity and Access Administration (IAM)
•    Experience leading and developing a strategic, comprehensive enterprise information security and IT risk and privacy management program
•    15+ years of experience in Cybersecurity, System security, cloud security, and risk management.
•    Knowledge and clear understanding of cloud-based infrastructures/software and how they affect security needs.
•    Experience implementing security practices in CI/CD environment, 
•    Self-motivation and the ability to work under minimal supervision are a must
•    Excellent at multitasking, and open to constant learning
•    Excellent problem solving and analytical skills; outstanding oral and written communication skills
•    Energetic and positive attitude


Cloud Security area 

Key Tasks – Establish proactive secure approach to cloud related technologies and services; standardize builds; robust monitoring; DevSecOps approach to scale; identify and mitigate security risks

-    Develop and implement comprehensive cloud security strategies, policies, and procedures to safeguard our cloud infrastructure and data assets.
-    Collaborate with DevOps and engineering teams to integrate security into the software development lifecycle (SDLC) and cloud deployment processes.
-    Implement and manage security controls and tools, including identity and access management (IAM), encryption, network security, and intrusion detection and prevention systems.
-    Monitor and analyze cloud security logs and alerts, investigate security incidents, and coordinate incident response efforts.
-    Conduct regular cloud vulnerability assessments and penetration testing and oversee the remediation of identified vulnerabilities.
-    Ensure compliance with industry standards and regulations (e.g., NIST, GDPR, PCI) by establishing and maintaining appropriate security controls.
-    Stay up to date with the latest security threats, vulnerabilities, and best practices, and recommend enhancements to our security infrastructure and processes.
-    Lead and contribute to security awareness and training initiatives for employees, supporting colleagues to build a security mindset. 


GRC area
This function is responsible for the planning, implementation and successful delivery of programs for the Governance, Risk and Controls Center of Excellence and may include leading project teams and Project Managers that are each responsible for various elements of project.
Key Tasks - Technology/Security Governance; Risk Assessment and Management; Supplier Chain/Vendor Risk; Security Awareness Training
-    This includes architecting program or project structures, plans to enable fulfillment an articulated business strategy and managing large program budgets
-    They will manage end-to-end complex crossline of business impacting change initiatives in alignment with Enterprise Change Management Framework
-    This includes all phases of program delivery from idea generation, business case development, planning, execution, transition, and operation 
-    They will challenge/review program status in partnership with business and technology stakeholders to ensure sound risk and issue management throughout the project lifecycle
-    Program elements may include areas such as organization structure, processes, operational support and technology
-    Engages and partners with Risk/Compliance to meet regulatory commitments while driving down risk to iHerb

#LI-JC1
 

The anticipated pay scale for this position can be found below, however the pay range applicable to you may vary by geographic location based on where the job is located or where you work.  The final pay offered to a successful candidate will be dependent on several factors that may include but are not limited to the type and years of experience within the job, the type of years and experience within the industry, education, etc.  iHerb, LLC is a multi-state employer and this pay scale may not reflect positions that work in other states or locations.
Employees (and their families) that meet eligibility criteria as outlined in applicable plan documents are eligible to participate in our medical, dental, vision, and basic life insurance programs and may enroll in our company’s 401(k) plan. Employees will also be eligible for Time Off and Paid Sick Leave pursuant to the company’s policies. Employees will enjoy paid holidays throughout the calendar year.  Eligibility requirements for these benefits will be controlled by applicable plan documents.

Hired applicant may be awarded Restrict Stock Units and receive annual bonuses pursuant to eligibility and performance criteria defined in the respective plan documents and policies.

 

For more information on iHerb benefits, visit us at iHerbBenefits.com.

Anticipated Pay Scale:

$220,667$386,168 USD

Staffing Agency Submission Notice
iHerb does not accept unsolicited 3rd party ("Agency") candidates. If you are an Agency, please send any requests to be considered as a supplier in our Vendor Management System to [email protected]. Do not contact iHerb employees directly. If requested to work on a role, any Agency candidates would be presented through the internal recruiting organization.

About iHerb
iHerb is on a mission to make health and wellness accessible to all. We offer Earth’s best-curated selection of health and wellness products, at the best possible value, delivered with the most convenient experience.
We’re the world’s largest eCommerce platform dedicated to vitamins, minerals, and supplements, and other health and wellness products. For more than 25 years, we’ve been making it simple for people all over the world to purchase the highest quality products. From supplements to skincare to grocery items, we ship over 30,000 products, from over 1,200 brands direct to our customers in 185+ countries.
Our vision is to become the #1 destination for health and wellness across the world.
With a passion for wellness and a mind for innovative solutions, iHerb team members share a vision for a healthier world that drives them each day. Our 5 Shared Values unite our global team:

Focus on the Customer · Empower Our People · Be Entrepreneurial & Pivot Quickly ·
Embrace Diversity & Inclusion · Strive for Simplicity

iHerb Benefits
At iHerb, we are dedicated to offering programs designed to help our employees and their families stay healthy, live well, and plan for their financial future. Built on a strong foundation, our programs provide options and upgrades with flexibility, protection, and security in mind. For the comprehensive benefits list, visit www.iHerbBenefits.com. For our international team members, you may be eligible for benefits depending on the country where you are employed. The Talent Acquisition Partner/local HR representative will go over the benefits you are eligible for. 

iHerb is an Equal Opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability or veteran status. iHerb provides equal employment opportunities to all applicants for employment and prohibits discrimination and harassment.

Apply Now

Date Posted

11/19/2023

Views

13

Back to Job Listings Add To Job List Company Profile View Company Reviews
Positive
Subjectivity Score: 0.9

Similar Jobs

Senior Product Designer - Org & Security - Typeform

Views in the last 30 days - 0

This job description outlines a role in developing an intelligent contact management system with AI capabilities The position involves designing user ...

View Details

Executive Director Patient Advocacy - Kyverna Therapeutics

Views in the last 30 days - 0

Kyverna Therapeutics is seeking an Executive Director for Patient Advocacy to lead initiatives in autoimmune disease treatment The role involves build...

View Details

Senior Design Manager (Infrastructure) - Canonical

Views in the last 30 days - 0

Canonical a leading opensource provider seeks a Senior Design Manager to drive innovation in cloud and AI technologies The role offers remote work glo...

View Details

Medical Affairs Writer Contract - Kyverna Therapeutics

Views in the last 30 days - 0

Kyverna Therapeutics seeks a Medical Affairs Writer to develop scientific publications and communications for cell therapy innovations The role requir...

View Details

Product Manager Wallet SDKs - Startale

Views in the last 30 days - 0

The text describes a job alert system where applicants must mention UNSELFISH and use a specific tag to demonstrate they read the post It explains the...

View Details

Recovery Analyst Underpayments - Trend Health Partners

Views in the last 30 days - 0

TREND Health Partners seeks an Underpayment Recovery Analyst to optimize client reimbursement through collaboration and detailed claim analysis The ro...

View Details