ACERTUS is looking for an experienced and forward-thinking Director, Information Security to lead and advance our enterprise information security program.
Reporting directly to the Chief Information Officer, this highly visible leadership role will serve as the single accountable owner for information security across the organization. You will have the opportunity to shape the future of cybersecurity at ACERTUS- developing our enterprise security strategy, strengthening governance and risk management, overseeing security operations and external partners, and ensuring our security capabilities continue to evolve alongside the business.
This is an opportunity for a security leader who enjoys both building strategy and making it happen. You will operate as a trusted advisor to executive leadership while remaining close enough to the work to drive implementation, solve problems, assess emerging risks, and create measurable improvements across the organization.
You will lead one direct report and oversee relationships with outsourced NOC/SOC providers and security vendors while partnering closely with leaders across Technology, Operations, Legal, Compliance, and other areas of the business.
- Develop and execute ACERTUS’ enterprise information security strategy and multi-year security roadmap.
- Establish and mature security governance, policies, standards, procedures, and enterprise risk-management practices.
- Maintain visibility into organizational cyber risk and lead decisions related to risk mitigation, transfer, and acceptance.
- Oversee outsourced NOC/SOC providers and other security partners, ensuring clear expectations, accountability, service levels, and escalation processes.
- Lead cybersecurity incident response activities across preparation, detection, containment, recovery, post-incident review, and continuous improvement.
- Advance vulnerability and patch-management capabilities and establish measurable remediation expectations and security performance metrics.
- Build and mature third-party cybersecurity risk-management practices, including vendor assessments and ongoing risk monitoring.
- Lead security compliance and audit-readiness efforts, including SOC 2 and frameworks such as NIST CSF and ISO 27001.
- Monitor emerging cybersecurity risks and technologies—including the evolving impact of artificial intelligence—and implement appropriate controls.
- Serve as the primary security advisor for customer security requirements, regulatory inquiries, and internal and external audits.
- Lead the Security Oversight Committee and provide clear, actionable reporting on cybersecurity posture, risk, and priorities to executive leadership and the Board.
- Champion a strong culture of security awareness through education, training, and phishing simulation programs.
- Lead and develop internal security talent while building scalable capabilities to support ACERTUS’ continued growth.
We’re looking for a well-rounded cybersecurity leader who can move comfortably between enterprise strategy and hands-on execution. You should bring the credibility to advise executives and present to senior leadership while also having the curiosity and practical mindset to dig into security operations, vendor performance, vulnerabilities, incidents, and risk.
Required qualifications include:
- Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or a related field, or an equivalent combination of education and experience.
- 7+ years of progressive information security experience, including experience leading or playing a significant role in an enterprise security program.
- Experience developing cybersecurity strategy, governance, risk-management programs, and security roadmaps.
- Demonstrated experience building, standing up, or significantly maturing security programs and capabilities.
- Experience communicating cybersecurity risk, strategy, and performance to executive leaders, Boards, or governance committees.
- Knowledge of SOC 2 and security frameworks such as NIST CSF and/or ISO 27001.
- Experience overseeing outsourced security providers such as NOC/SOC, MSSP, or MDR partners.
- Experience with third-party or vendor cybersecurity risk management.
- Current CISSP, CISM, or equivalent security certification.
- Strong executive presence, communication skills, and the ability to build trusted relationships across technical and non-technical teams.
- Experience with AI-related cybersecurity risks, controls, or security practices.
- Experience with SOC 2 audit readiness, vulnerability management, or enterprise patch-management programs.
- Experience supporting customer security requirements and assessments.
- Experience working within complex environments involving multiple systems, integrations, acquisitions, or legacy applications.
- Experience within transportation, logistics, automotive, or another operationally complex industry.
- Experience working in a high-growth or private equity-backed organization.
- A Master’s degree or additional certifications such as CISA, GIAC, or CCSP.
During your first several months, you’ll develop a comprehensive understanding of ACERTUS’ security environment, assess the current threat landscape and security partners, evaluate audit and SOC 2 readiness, and establish clear direction around patch management, third-party risk, and security priorities.
From there, you’ll begin putting a scalable security strategy into action- strengthening security and AI awareness, advancing remediation and third-party risk programs, optimizing external security partnerships, demonstrating measurable improvements, and preparing to communicate recommendations and progress alongside the CIO to executive leadership and the Board.
The anticipated base salary range for this position is $170,000–$180,000, depending on experience, skills, and qualifications. This position is also eligible for an annual bonus opportunity.
Equal Opportunity Employer
This employer is required to notify all applicants of their rights pursuant to federal employment laws. For further information, please review the Know Your Rights (https://www.eeoc.gov/poster) notice from the Department of Labor.