About the Role
This position leads the development, implementation, and ongoing enhancement of the cybersecurity governance program. The role oversees security policy lifecycle management, regulatory compliance coordination, and cybersecurity awareness initiatives while serving as a strategic bridge between technical security teams, business units, and executive leadership.
Responsibilities
- Lead the design and maintenance of the cybersecurity governance framework in alignment with enterprise risk, business goals, and regulatory standards.
- Develop, update, and review cybersecurity policies, standards, procedures, and guidelines on an ongoing basis.
- Manage a formal process for policy lifecycle activities including approvals, exceptions, waivers, and scheduled reviews.
- Ensure all policies are actionable, enforceable, and directly linked to technical controls and compliance obligations.
- Collaborate with cybersecurity engineering, operations, and risk teams to align governance with operational security practices.
- Design, deploy, and enhance an enterprise-wide cybersecurity awareness and training program.
- Oversee mandatory training, phishing exercises, role-specific education, and executive-level awareness campaigns.
- Evaluate training effectiveness using performance metrics, trend analysis, and risk-based outcomes.
- Foster a culture of security awareness that integrates education, accountability, and business support.
- Work with Legal, Privacy, Compliance, and Risk functions to build a unified regulatory compliance strategy.
- Interpret and apply cybersecurity regulations and standards such as NYDFS, GLBA, SEC, GDPR, CCPA, ISO, and NIST.
- Maintain traceable mappings between regulatory requirements, policies, controls, and audit evidence.
- Support regulatory examinations, internal and external audits, client due diligence, and third-party assessments.
- Track emerging cybersecurity laws and assess their potential impact on the organization.
- Serve as the primary governance contact for IT, Legal, Compliance, Privacy, HR, and business leadership teams.
- Convert complex regulatory and policy requirements into practical guidance for both technical and non-technical audiences.
- Deliver executive-level reporting on governance performance, compliance status, and key risk indicators.
- Support board and executive governance meetings with clear, concise, and actionable insights.
- Recruit, manage, and mentor a team of governance professionals specializing in policy, training, and compliance.
- Define team roles, organizational structure, career development paths, and performance expectations.
- Implement efficient, scalable processes, tools, and performance metrics to support governance operations.
- Advance governance maturity through automation, standardization, and data-informed improvements.