Director Information Security
Fort Mill, South Carolina, Us
- Development and execution of organization information security strategy and security roadmap- Implementation of ISO 27001/27002 security framework- SME Security Design and Architecture for migration of multiple environments to Amazon cloud- Responsible for all logical and administrative security measures of acquisitions- Responsible for writing and implementing organization wide security policies that align with business strategy, enforce compliance and satisfy partner and customer requirements.- Provide guidance and recommendations of investments and projects to maximize utility, mitigate risks and reduce vulnerabilities- Research, evaluate, design, test, recommend and plan implementation of security controls, tools, processes, software and devices- Continual assessment and research into emerging threats, risks and vulnerabilities- Ensure compliance through internal and external vulnerability scans and annual penetration testing- Responsible for all Governance, Risk Management and Compliance measures- Lead investigations and response to information security incidents (incident response)- Perform security risk assessments of vendors, contracted services and 3rd party service providers- DRI for compliance efforts (PCI, SOX, SSAE-16), security questionnaires and security audits, and assist with RFPs and contract reviews- Perform regular audits and gap analysis on environments, processes and procedures against policy standards, best practices and compliance requirements and lead remediation efforts- implementation of security solutions including data encryption/HSM, code scanning, secure email, whole disk encryption, centralized logging and event correlation, two-factor authentication, IDS, IPS Management, FIM, DLP, and MDM