Home | Links | Contact Us | Press | Post a job | Bookmark
Home Computer & IT Services Director-Information-Security-and-Compliance


 Director Information Security and Compliance

Details
Country: USA
Location: California-Ventura County Camarillo, CA 93012
Total applied: 40
Job Category:IT/Software Development
Relevant Work Experience:5+ to 7 Years
Education Level:Bachelor's Degree
Location:Camarillo, CA 93012
Status:Full Time, Employee
Occupations:Computer/Network Security;Systems Analysis - IT
Career Level:Executive (SVP, VP, Department Head, etc)
Relevant Work Experience:5+ to 7 Years
Director Information Security and Compliance

Established in 1968, Harbor Freight Tools is a fast growing, well established privately held retail company opening stores across the United States.  We currently operate over 270 stores in 44 states with plans to open over 30 stores per year. Harbor Freight Tools is seeking a Director Information Security and Compliance to join our IT Department in Camarillo, CA. 

Essential Duties and Responsibilities:

The Director of Information Security and Compliance is responsible for the overall Information Security and IT compliance activities of the Harbor Freight Tools enterprise. This position manages staff and vendors, directly and indirectly through policy, procedure, and standards regarding the implementation of, adherence to, and integrity of technical controls.  This individual’s principal goals are to develop and manage IT policy, system security and disaster recovery with a goals of managing IT related risk and ensuring compliance with mandates and laws.

 

The Director of Information Security and Compliance will plan, coordinate, direct, and design all operational activities of the IT Information Security and Compliance team. The Director of Information Security and Compliance will work closely with the CIO, IT management team and decision makers in other departments to identify, recommend, develop, implement, and support cost-effective technology solutions for all aspects of the enterprise.

 

·  Participate in IT department operational and strategic planning, including business requirements, project planning, and organizing and negotiating the allocation of resources.

·  Build, develop and communicate comprehensive policies and policy objectives and the context in which these policies were developed and how they are applied. This includes the various requirements of HFT (GCC, PCI, ITIL, Security Incident Response Team, etc). 

·  Conduct threat modeling for operational systems and new products

·  Lead technology security incident response team

·  Define security testing policies and processes for internally developed software, and advise software development team on security practices

·  Advise operations team on security practices, including hardening of systems, access controls, and monitoring

·  Participate in systems and software architecture to ensure that security is designed into products from the ground up

·  Track emerging exploits, defensive techniques, and regulations affecting HFT’s business, and advise management on security roadmap

·  Define essential security metrics, and provide tracking and reporting of those metrics to management

·  Learn detailed knowledge of existing operational processes - especially as they affect systems that are likely to be a security target and / or the source of compliance activity. 

·  Knowledge of controls and existing processes should be kept current through internal investigation and may require seeking external validation (from vendors or corporate). 

·  Must be current with and update HFT leadership with analysis of changes in regulatory risks, operating risks, and technical vulnerabilities within the existing infrastructure, applications, and process controls. 

·  Directs a staff of security specialists, and vendors who may have operational responsibility for implementing and adhering to information security and GCC standards for policy compliance.

·  Can anticipate, mitigate, and resolve situations where compliance requirements and immediate business need come into conflict by:

o Clarifying technical ambiguity with respect to physical and logical access control, data handling, and system vulnerability  

o Understanding and helping HFT IT Management understand the business exposure and technical risk so that appropriate choices can be made to satisfy both business need and compliance requirements. 

·  Manages the role responsible for primary vendor contract management including selection, negotiation, review, and renewal

·  Possesses comprehensive business and technical knowledge and organizational skills to oversee highly complex projects with high visibility and high impact on the business. 

·  May participate in committees / panels / teams regarding data protection, regulatory oversight, and audit compliance.

·  Develop business case justifications and cost/benefit analyses for IT spending and initiatives.

·  Direct research on potential technology solutions and implementations in support of new initiatives, opportunities, and procurement efforts.

·  Develop and implement IT policies and procedures, including those for security, disaster recovery, standards, purchasing, and service provision.

·  Oversee negotiation and administration of vendor, outsourcer, and consultant contracts and service agreements.

·  Manage IT staffing, including recruitment, supervision, scheduling, development, evaluation, and disciplinary actions.

·  Establish and maintain regular written and in-person communications with the organization’s executives, department heads, and end users regarding pertinent IT activities.

 

Education and/or Experience:

 

·  5+ years of industry experience in information security, including 3+ years managing security for Internet-facing applications

·  8+ years of industry experience in software development or IT operations

·  BS in Computer Science or equivalent experience (MS or PhD a plus)

·  CISSP a plus

·  Strong familiarity with the state of the art in web vulnerability attacks and defenses

·  Demonstrated ability to communicate technical and business aspects of security issues accurately and clearly to stakeholders at all levels of organization Good understanding and technical knowledge of current network and PC operating systems, hardware, protocols, and standards, including Microsoft, Oracle, Frame Relay and Cisco.

·  Good understanding and technical knowledge of ITIL best practices for IT services management.

·  Superior understanding of the organization’s goals and objectives.

·  Demonstrated ability to apply IT in solving business problems.

·  In-depth knowledge of applicable laws and regulations as they relate to IT.

·  Strong understanding of human resource management principles, practices, and procedures.

·  Strong leadership skills.

·  Excellent written, oral, and interpersonal communication skills.

·  Ability to conduct and direct research into IT issues and products.

·  Ability to present ideas in business-friendly and user-friendly language.

·  Highly self-motivated, self-directed, and attentive to detail.

·  Ability to effectively prioritize and execute tasks in a high-pressure environment.

·  Extensive experience working in a team-oriented, collaborative environment.

 Work Conditions

 

·  On-call availability for 31 days per month.

·  Sitting for extended periods of time.

·  Dexterity of hands and fingers to operate a computer keyboard, mouse, power tools, and to handle other computer components.

·  Occasional inspection of cables in floors and ceilings.

·  Lifting and transporting of moderately heavy objects, such as computers and peripherals.

 

Benefits Include:401kFull Medical Package including, heath and dentalPaid HolidaysSick LeavePaid VacationCompetitive SalaryCasual Work Environment



To apply for this great opportunity, please send your resume to jobs@harborfreight.com

 

- Apply for Director Information Security and Compliance


Related jobs
  SAS Programmer
The Computer Merchant, LTD is currently seeking an SAS Programmer to provide support for a Fortune 200 integrator in their facility in Simi Valley, California. Position:S...
  Sr. Software Engineer
  We are seeking a mid-level .NET developer to add to our employee staff. If you would enjoy a wide variety of development this position may be for you. Basic ...
  Software Engineer I
We are seeking a junior-level .NET and Java programmers to add to our employee staff. If you would enjoy a wide variety of development this position may be for ...
  HDD Device Security Software Development
COMPANY INFORMATION:Join a global leader in output and print solutions. Created in 2007, through a joint venture between two global powerhouses, Ricoh and IBM, InfoPrint ...
  Network - Remote Support and Services Software Development
COMPANY INFORMATION:Join a global leader in output and print solutions. Created in 2007, through a joint venture between two global powerhouses, Ricoh and IBM, InfoPrint ...
  Account Coordinator - 5866
Description:ResponsibilitiesThe Account Coordinator works cross-functionally with Creative, Marketing, and Operations on behalf of our clients to deliver the appropriate ...
  Unix Systems Administrator
 See all "Robert Half Technology" opportunities  ...
  ISSO Security Engineer (8907)
Founded in October 1998, SI International has become a premier professional services company, delivering information technology and network solutions that enhance our ...
  Contract-MidSr Level C#/.Net/ Visual Studio Developer
3-4 years experience with Visual Studio .NET 2005/2008 IDE- C# Development- Experience with source control programs, preferably Visual Source Safe- Familiarity with SDLC-...
  Facilities Maintenance Technician
Spherion, in partnership with a Fortune 100 Technology Industry leader, is seeking a Facilities Maintenance Technician for their Boulder, CO location.  The ...

Related press releases
Courageous reform
There can be little doubt we are making progress when it comes to improving further education. More young people and adults than ever are gaining good qualifications ever...
Half of MG Rover workers want to return
Almost a year after the collapse of MG Rover, many former workers are paid less and wish they still worked for the firm, according to a report released today. Of the nea...
Making ends meet
Earning some dosh to get through uni might seem unavoidable, but don't lose sight of the reason you are there: to get a degree. Earning shouldn't mean missing vital lectu...
Young, successful, well paid: are they killing feminism?
Chiara Cargnel wants to have it all: a high-flying career and a successful marriage. So far she is halfway there. At 26, she is an investment banker in London working ove...
The earth man cometh
I am merely the conduit,' says Patrick Holden, director of the Soil Association, when I ask him to sum up his achievement after 10 years in the job. 'The great thinkers, ...
Battle at the coalface
In his television review Rupert Smith described the NUM miners leader Arthur Scargill as "a ghastly little man who needed to be trodden on" (G2, March 23). I suppose he w...
Hutton eases small firms' pension fears
The government will not force employers to contribute to workers' pensions without making efforts to minimise the impact on firms, the work and pensions secretary, John H...
NHS hospital redundancies gather pace
A wave of redundancies across the NHS in England gathered force yesterday when a London teaching hospital announced that nearly 500 posts will be axed in an attempt to di...
Union warning over 'raw' stalls handlers
The Transport and General Workers Union (T&G) yesterday launched a fierce attack on the overall standard of the stalls handlers likely to be working at British racecourse...
Minimum wage to rise to £5.35
The minimum wage will rise by 6% in October to £5.35, the government confirmed yesterday, but it cautioned that the days of big, inflation-beating rises may be over...
©2009 UsaJobOnline - Connecting Job Seekers with Employers

Archive: All jobs