Director Information Security & Governance
EXPRESS · Ohio
📍 Columbus, OHvia icimsPosted 2024-07-25
Apply on company site ↗
CareerRiver pulls this listing straight from the employer's hiring system — no recruiter middleman, no reposts. Applying takes you directly to EXPRESS.
Overview
About PHOENIX PHOENIX Retail, LLC is a retail platform operating the Express and Bonobos brands worldwide. About Express Express is a multichannel apparel brand dedicated to a design philosophy rooted in modern, confident and effortless style whether dressing for work, everyday or special occasions. Since its launch in 1980, the brand has embraced a design philosophy rooted in modern, confident and effortless style. Express ensures you look and feel your best, wherever life takes you. The Company operates over 400 retail and outlet stores in the United States and Puerto Rico, the express.com online store and the Express mobile app. About Bonobos Our Bonobos menswear brand is known for being a style instigator and offering perfect-fit risks through our innovative retail model and personalized experience. Launched online in 2007 with its signature line of chinos, Bonobos now offers a variety of styles available to order online and to try on at any one of our 50 Guideshop locations and at www.bonobos.com. Our Guideshops are in-real-life stores that deliver one-on-one service and expert fit advice. Don't think traditional retail, Bonobos is something you haven't seen before.
Responsibilities
POSITION OVERVIEW
The Director, Information Security & Governance serves as Phoenix Retail’s senior information security leader with enterprise-wide accountability for the strategy, execution, and ongoing maturity of the company's information security, data protection, privacy controls, and AI security governance program. The role protects Phoenix Retail’s omnichannel environment, including corporate systems, e-commerce platforms, store technology, customer and payment data, AI-enabled capabilities, and supporting infrastructure. The Director provides strategic leadership for the Information Security team, fostering a high-performance culture through mentorship and talent development to ensure the sustained operational excellence of the team and the organization.
Operating with the scope and presence of a Chief Information Security Officer, the Director leads enterprise security strategy, governance, policy, architecture, operations, incident response, AI security controls, and security risk management. The role advises executive leadership and the Board on security posture, emerging threats, regulatory obligations, business risk, and investments required to protect the company. This leader partners closely with Technology, Development, Legal, Procurement, Internal Audit, Compliance, Finance, and business stakeholders to embed security across enterprise technology and vendor ecosystems. The Director is a key stakeholder in Third-Party Risk Management and owns Phoenix’s PCI-DSS program with full accountability for readiness and outcomes. This is a strategic leadership role requiring strong hands-on technical credibility. The Director must also be able to engage directly with technical matters, including SIEM activity, detection validation, threat hunting, incident investigations, and AI control monitoring when needed.
KEY RESPONSIBILITIES
Serve as enterprise owner for Phoenix Retail’s information security strategy, roadmap, governance model, security policy framework, and AI security governance, aligned to business priorities and retail operating needs.
Lead and mature a security program built against the NIST Cybersecurity Framework, including measurable controls, maturity targets, risk-based prioritization, and reporting to executive leadership and the Board.
Design, implement, and monitor controls for AI technologies and use cases, including acceptable-use standards, administrative approvals, data handling requirements, identity and access guardrails, logging, vendor risk inputs, usage monitoring, and spend/consumption oversight.
Own PCI-DSS across corporate, e-commerce, and store/cardholder data environments, including scoping, segmentation, control design, assessor coordination, remediation, evidence, and executive accountability for outcomes.
Lead application security across Phoenix Retail’s digital commerce and enterprise application portfolio, embedding secure design, code review/SAST/DAST, testing, and risk acceptance into the SDLC.
Lead network, cloud, endpoint, identity, collaboration, and infrastructure security architecture and operations, ensuring appropriate controls across corporate, e-commerce, store, GCP, Google Workspace, and other key environments.
Own security operations, 24x7 monitoring, detection engineering, escalation, and incident response; maintain enough hands-on fluency with the SIEM to validate detections, review alerts, and support active investigations when required.
Direct threat and vulnerability management, including scanning, prioritization, remediation governance, patch SLAs, penetration testing, attack surface management, and executive risk reporting.
Partner with Legal and Procurement as a key security stakeholder in Third Party Risk Management, including vendor due diligence, contract security requirements, AI and SaaS provider reviews, control assessments, ongoing monitoring, and remediation tracking.
Review and approve security designs for new technology initiatives, AI-enabled capabilities, cloud services, store technology, payment systems, and major vendor platforms before production deployment.
Lead enterprise incident response planning, crisis coordination, tabletop exercises, post-incident reviews, and communications with executive, legal, operational, and technical stakeholders.
Partner with Internal Audit on control testing, evidence, and remediation while maintaining appropriate independence and avoiding self-audit.
Recruit, lead, coach, and develop a high-performing security team; establish clear ownership, operating rhythms, performance expectations, and career paths.
Own the security budget, tooling roadmap, vendor portfolio, managed service relationships, SLAs, renewals, and investment recommendation
More Ohio jobs
Ohio jobs · Browse all locations