- Company Name
- WHSmith North America
- Job Title
- Director of Cyber Security
- Job Description
-
**Job Title:** Director of Cyber Security
**Role Summary:**
Lead and execute the North America cybersecurity strategy, ensuring regulatory compliance, operational excellence, and incident readiness. Liaise between executive leadership, board, and operational teams while aligning regional initiatives with global WHSmith security objectives.
**Expactations:**
- Deliver a robust cybersecurity posture that meets NIST, PCI DSS, and WHSmith governance standards.
- Provide transparent risk reporting and strategic guidance to the North America Board and senior leaders.
- Drive continuous improvement of security controls, processes, and maturity across all NIST CSF domains.
- Foster a high‑performing security team and collaborate with global InfoSec peers to maintain consistent security effectiveness.
**Key Responsibilities:**
- Develop and maintain the North America cybersecurity roadmap in support of global objectives.
- Provide regular risk assessments and updates to the North America Board.
- Act as the primary link with the Group CISO for global security initiatives.
- Establish, enforce, and periodically review IT security policies, standards, and procedures.
- Lead incident response, ensuring timely detection, containment, and remediation of security events.
- Oversee vulnerability management, threat intelligence, and monitoring in partnership with the Global Security Operations Centre.
- Identify, assess, and mitigate risks within the North American IT estate, addressing gaps in coverage and manual processes.
- Manage, mentor, and develop a regional security team, ensuring succession planning and professional growth.
- Engage business sponsors across HR, Finance, Legal, and other functions to align security initiatives with organizational priorities.
**Required Skills:**
- Proven leadership in cybersecurity program management and team supervision.
- Deep knowledge of IT security architecture, incident response, vulnerability management, and threat intelligence.
- Expertise in regulatory frameworks (NIST, PCI DSS, ISO/IEC 27001, GDPR, CCPA).
- Strong communication skills to translate technical risks into business‑friendly language and secure decision‑maker buy‑in.
- Ability to collaborate with cross‑functional stakeholders and influence at all levels.
- Experience with enterprise security stacks and integration across complex IT environments.
**Required Education & Certifications:**
- Bachelor of Science in Cybersecurity, Information Technology, Computer Science, or related field.
- 5–8 years of progressive cybersecurity experience, including 3+ years in supervisory or director roles.
- Certifications such as CISSP, CISM, CISA, CEH, or equivalent (mandatory or highly preferred).
- Demonstrated experience with NIST CSF, PCI DSS, and enterprise policy development.