Cybersecurity Director, GRC & Cloud Security
Overview
As Cybersecurity Director at Business Wire, you will lead the global cybersecurity function, shaping strategy and protecting market-moving news distribution infrastructure. You will own the GRC program, direct cloud security for AWS and Azure, and guide Zero Trust architecture. Collaborating with executive leadership and external cyber defense partners, you will embed security across all operations. This role stands out for its dual focus on strategic leadership and hands-on technical oversight, including incident response and emerging tech risks like AI.
What You'll Do10
- 1Develop and maintain the cybersecurity and GRC strategy and long-term roadmap, aligning with business objectives.
- 2Drive continuous improvements to security strategies to protect critical assets and data.
- 3Oversee the comprehensive GRC program, ensuring compliance with PCI DSS, SOC 2, and ISO 27001, and meeting audit requirements.
- 4Conduct regular risk assessments, penetration testing, and vulnerability assessments to identify and mitigate threats.
- 5Manage security communications, including awareness training, policy updates, and incident alerts.
- 6Direct the external cyber defense partner, evaluating service performance and alignment with cybersecurity priorities.
- 7Lead cybersecurity incident response, coordinating with IT, Legal, HR, and Communications, serving as executive point of contact.
- 8Establish secure architecture guidelines and governance frameworks, integrating risk management across business operations.
- 9Use security metrics to track and report effectiveness of security, governance, and compliance initiatives.
- 10Mentor cybersecurity and GRC team members, fostering strong performance and professional growth.
Requirements10
- 110+ years in information security, with 5+ years in managerial and strategic leadership.
- 2Bachelor's or Master's degree in Computer Science, Information Security, or related field.
- 3Expertise in cloud security with AWS and Azure, including architecture and Zero Trust.
- 4Strong knowledge of data encryption, access controls, and secure coding practices.
- 5Proven experience building and implementing GRC frameworks and risk management processes.
- 6Familiarity with regulatory compliance: PCI DSS, SOC 2, and ISO 27001.
- 7CISSP or equivalent certification preferred.
- 8Experience managing external security service providers or technology partners.
- 9Excellent communication skills to translate technical requirements into business solutions.
- 10Ability to work in the San Francisco office an average of twice a week.
Salary Insight
$230 - $245k per year
Location
Required Skills
Similar open positions
Explore active roles that match your skills and interests.

Mergen IT LLC
VerifiedCybersecurity GRC Consultant NIST CSF 2.0
Lead end to end engagement governance project planning milestones risks oversee Cybersecurity GRC Consultant NIST CSF 2.0 San Francisco CA (Onsite) drive practical improvement roadmap deliver results within 90 days

Belcan, LLC
VerifiedCybersecurity Operations & Communications Lead
Own the security operations and communications strategy for a global enterprise, coordinating incident response across SIEM, SOAR, and EDR platforms. You lead a team of analysts, manage threat intelligence feeds, and craft executive-level briefings. This role sits at the intersection of technical operations and stakeholder communication, reporting directly to the CISO. You will drive the adoption of MITRE ATT&CK framework and NIST guidelines, shaping the organization's cyber resilience.

Visionaire Partners
VerifiedSenior Cybersecurity Engineer, Cloud Security
You will spearhead defensive operations, threat detection, and risk mitigation across complex enterprise networks, AWS and Azure, and endpoint environments. You will design security tool architecture to harden system baselines and drive security posture across cloud and containerized infrastructure. Your stack includes SIEM, EDR, CSPM, and IaC tools. You will partner with DevOps and network teams to embed security into the build pipeline. This role puts you at the center of security strategy for a critical infrastructure provider.
Rack Room Shoes, Inc.
VerifiedSr. Director of Cybersecurity, Retail & PCI DSS
Sr. Director of Cybersecurity owns the enterprise cybersecurity program for Rack Room Shoes, a 515-store footwear retailer. You define strategy, governance, and risk posture, aligning security with business priorities and regulatory demands. Lead a team of security engineers, operations, and governance professionals, partnering with the CIO and executive leadership. This role drives PCI DSS compliance, cyber resilience, and security architecture across retail, eCommerce, and cloud environments. Join a 100-year-old company modernizing its security maturity.

Saicon Consultants Inc.
VerifiedCyber Security Analyst - Saicon Consultants Inc.
Lead ownership of GRC Risk Management Analyst duties supporting information security and third-party risk management at a fast-paced environment. This role blends structured governance with hands-on technical expertise to evaluate vendor security postures across the entire relationship lifecycle. You will drive continuous monitoring and offboarding processes while delivering actionable insights that enhance organizational resilience. What sets this position apart is the emphasis on proactive threat scenario modeling and deep architectural analysis.
Tier4 Group
VerifiedSenior Cybersecurity Project Manager - IT Security
The role involves owning enterprise cybersecurity initiatives at scale. The ideal candidate leads complex technology projects from conception to delivery while aligning with organizational security goals. This position offers a strong potential to convert into full-time employment.