Director IT Strategy and Security
18 hours ago
Syosset
Director of IT Strategy and Security We are seeking a strategic technology leader to oversee cybersecurity governance, AI strategy, vendor risk management, and digital transformation. This role drives the organization’s compliance, security posture, and AI maturity while serving as the primary liaison to the parent organization on cybersecurity and AI programs. Reporting to the VP Finance, the Director partners closely with the Director of IT (Infrastructure) and manages the Systems Administrator & Security Analyst. Key Responsibilities Cybersecurity Governance & Compliance • Lead development and maintenance of cybersecurity frameworks, policies, and procedures, • Oversee SOX IT general controls and ISO 13485 IT-related compliance, • Manage PCI DSS compliance in partnership with payment processing teams, • Conduct risk assessments, vulnerability reviews, and drive remediation, • Maintain incident response and business continuity plans, • Develop and maintain the organization’s AI governance framework, • Translate enterprise AI protection requirements into actionable policies, • Evaluate, approve, and manage the lifecycle of AI tools and platforms, • Define secure, compliant integration architectures between AI systems, ERP, and databases, • Drive AI-enabled process improvement across operations, quality, and finance, • Lead the vendor risk assessment program for all SaaS and technology procurements, • Review and negotiate technology agreements with a focus on security and compliance, • Coordinate legal reviews for contracts with data or regulatory implications, • Drive the multi‑year digital transformation and IT strategy roadmap, • Manage the IT Strategy & Security budget, • Provide executive-level reporting on cybersecurity, AI maturity, and technology risk, • 7+ years of progressive IT leadership, including 3+ years in a security or strategic role, • Expertise in cybersecurity frameworks (NIST, ISO 27001, etc.), • SOX ITGC experience in manufacturing or regulated environments, • Hands-on AI governance, AI tool implementation, and vendor AI risk assessment, • Experience defining integrations between AI platforms, ERP, and databases, • Strong vendor risk management and SaaS contract review background, • ERP experience (NetSuite preferred), • Experience in life sciences, pharmaceutical, or regulated manufacturing industries, • Familiarity with ISO 13485, • PCI DSS experience, • Strategic thinker with the ability to translate business needs into actionable technology plans, • Excellent communication skills, able to explain risk to non‑technical leadership, • Compliance‑minded with sound judgment, • Forward‑looking on AI and emerging technologies