- Company Name
- Global Payments Inc.
- Job Title
- Senior Director, Cyber Security Enablement & Secure DevOps
- Job Description
-
**Job Title**
Senior Director, Cyber Security Enablement & Secure DevOps
**Role Summary**
Lead a global cyber‑security enablement organization that embeds security across the full software development lifecycle (SDLC) and IT build processes. Drive the design, delivery, and continuous improvement of Secure DevOps practices, including architecture, tooling, automation, and risk management. Maintain enterprise security posture, compliance, and incident response while cultivating a security‑first culture across development and operations teams.
**Expectations**
* Deliver the enterprise Secure DevOps program aligned with business and regulatory goals.
* Oversee risk assessment, mitigation, and remediation for application & infrastructure assets.
* Provide strategic guidance to senior leadership on security posture and program health.
* Foster cross‑functional collaboration to integrate security into CI/CD pipelines and IaC.
**Key Responsibilities**
* Build, oversee, and evolve the enterprise Secure DevOps program and Cyber Enablement organization.
* Design and implement processes that embed security into SDLC, CI/CD, IaC, and container workflows.
* Lead automation of security controls, including SAST, DAST, SCA, container, and cloud security checks.
* Identify, evaluate, and mitigate security risks and vulnerabilities across applications and infrastructure.
* Support end‑to‑end security incident response, post‑incident analysis, and lessons‑learned.
* Develop metrics and reporting to monitor program effectiveness and communicate status to senior leadership.
* Ensure compliance with NIST, PCI DSS, ISO 27001, SOC, and other industry standards.
* Build and maintain stakeholder relationships, promoting security awareness and best practices.
* Manage a high‑performing security team, encouraging growth, accountability, and delivery excellence.
**Required Skills**
* 10+ years of progressive enterprise information security experience, 15+ years overall.
* Deep knowledge of SDLC and CI/CD practices; experience with automation tools (e.g., Jenkins, GitHub Actions).
* Expertise in security tooling: SAST, DAST, SCA, IaC scanning, container security (Kubernetes), cloud security (AWS, Azure, GCP).
* Strong understanding of security frameworks and standards: PCI DSS, NIST, ISO 27001, SOC.
* Proven experience in risk assessment, remediation strategy, and vulnerability management.
* Leadership and people‑management skills—built and motivated global security teams.
* Analytical decision‑making in complex, fast‑paced environments.
* Excellent communication, stakeholder engagement, and executive‑level presentation skills.
**Required Education & Certifications**
* Bachelor’s degree in Computer Science, Information Systems, or related field, **or** equivalent experience.
* Minimum 15+ years industry experience in security or related roles.
* Certifications in security frameworks (e.g., PCI DSS, ISO 27001, CISSP) are preferred but not mandatory.