Gathering your results ...
6 days
Not Specified
Not Specified
$40.99/hr - $66.28/hr (Estimated)
<p>The Director, Information Security provides information security leadership for Regal Entertainment Group and is responsible for the oversight and management of Regal's information security program. This position works closely with senior management, ensures compliance requirements are assessed, remediation actions are executed to maintain Regal Cineworld's overall regulatory and legislative directives, as well as information security requirements from external partners and other agents. The incumbent communicates performance through status reports to IT Management, business unit executives and senior management.</p> <p>Essential Duties and Responsibilities include the following. Other duties may be assigned.</p> <ul> <li> <p>Manage Information Security program for Regal Cineworld; specific duties include:</p> </li><li> <p>Develop policy, process, and procedure documentation to support compliance and information security initiatives; identify mitigating controls as needed</p> </li><li> <p>Publish and disseminate critical security information to appropriate audiences</p> </li><li> <p>Perform threat / risk assessments and provide security reporting to executive management where appropriate</p> </li><li> <p>Manage IT department compliance with respect to PCI, GDPR, Sarbanes-Oxley and other external requirements. Specific duties include:</p> </li><li> <p>Maintain awareness of external requirements, standards and best practices to recommend action for Regal to remain in compliance or to attain compliance</p> </li><li> <p>Develop action plans based on annual or preventative audits and that Regal Cineworld remains in compliance</p> </li><li> <p>Coordinate design and testing of all IT components that are subject to PCI, GDPR, SOX, and other requirements to ensure compliance</p> </li><li> <p>Oversight of all security monitoring process documentation to ensure that documentation is current, exceptions are approved and that processes are followed</p> </li><li> <p>Manage internal and external scans of the environment to ensure that risks are identified and remediated; maintain records of actions to remediate risks</p> </li><li> <p>Ensures external validation processes are defined, scheduled, executed and disseminated as needed to comply with regulatory requirements as approved by Regal management</p> </li><li> <p>Assist with annual penetration testing in support of PCI-DSS compliance</p> </li><li> <p>Assist with the completion of the annual PCI Report on Compliance</p> </li><li> <p>Alert IT Management and the VP, Compliance regarding emerging issues or matters regarding compliance that require senior management action; recommend course of action and policies as appropriate</p> </li><li> <p>Manage the Enterprise Incident Response process. Specific responsibilities include:</p> </li><li> <p>Develop processes and procedures for Enterprise Incident Response Management team</p> </li><li> <p>Conduct annual review</p> </li><li> <p>Develop and maintain documentation for Enterprise Incident Response Management policies, processes and procedures as well as documentation for incidents as they are identified or occur for audit review and root cause analysis</p> </li><li> <p>Lead the Enterprise Incident Response Management team in identifying incident causes, remediation, repair and prevention</p> </li><li> <p>Participates as required with Human Resources in legal processes and enforcement actions</p> </li><li> <p>Supports the Disaster Recovery plan to ensure that applications can be recovered to meet the Recovery Time Objectives (RTO) as defined and approved by Management:</p> </li><li> <p>Monitors data backup processes: server state backup processes to ensure that recovery is possible</p> </li><li> <p>Participates with on-site Recovery Center team in the event of a disaster</p> </li><li> <p>Participates in drills to ensure recovery plans are viable and will meet RTO</p> </li><li> <p>Identifies opportunities to reduce risk and mitigate potential threats; proposes solutions as necessary</p> </li><li> <p>Manage relationships with key vendors to ensure conformance with Service Level Agreements, contract terms, and coordinates or negotiates review and revision of contracts with vendors</p> </li><li> <p>Monitors new developments in security technology and environmental risks and develops plans to strengthen and improve the security systems of the company</p> </li><li> <p>Provide oversight of the IT environment in collaboration with other IT Management to ensure access to information systems is appropriate and authorized.</p> </li><li> <p>Establish security parameters for all IT components and monitor implementation of parameters for equipment and installations. Manages process to obtain management approval for exceptions per procedures and policies.</p> </li><li> <p>Budget development, management and control for assigned projects and support processes</p> </li><li> <p>Perform oversight of the AD account management and provisioning process</p> </li><li> <p>Perform oversight of the vendor access account management and provisioning process</p> </li><li> <p>Other duties as assigned</p> </li></ul> <p>Qualifications:</p> <p>To perform this job successfully, an individual must be able to perform each essential duty satisfactorily. The requirements listed below are representative of the knowledge, skill, and/or ability required. Reasonable accommodation may be made to enable individuals with disabilities to perform the essential functions.</p> <p>Professional Skills:</p> <ul> <li>Must have tactical / working knowledge of all technologies currently in-use and / or planned </li><li>Must demonstrate the ability to learn quickly and apply knowledge in a timely manner and for the appropriate task. </li><li>Experience with formal project management techniques, process design and management (metrics) is desired </li><li>Demonstrated skills to communicate difficult technical concepts clearly to a variety of individuals of varying technical expertise and understanding. </li><li>Demonstrated effective decision-making skills, even under pressure and while lacking all of the desired information detail. </li><li>Strong written and verbal communication skills to deal effectively with the business unit executives, management and staff, as well as IT management and staff. </li><li>Should possess management development skills and experience to coach, guide and develop IT staff as part of the Regal Performance Management and Appraisal Process. </li><li>Must be a disciplined process-oriented manager able to lead the implementation of best practice controls and processes. </li><li>Possess superior problem-solving skills for a complex network topology, being able to assemble a team as needed to identify issues, root causes and solutions. </li><li>Must have proven ability to work successfully in a high volume, technically demanding job, providing leadership and customer service while utilizing excellent judgment </li><li>Must be flexible and willing to travel to other locations </li><li>Must be proactive in identifying and correcting infrastructure deficiencies. </li><li>Must be a team player, excellent collaborator and leader. </li><li>Must be mature, poised, and confident in the face of adversity. </li><li>Must be highly organized and capable of providing technical leadership while requiring minimal day-to-day guidance. </li></ul> <p>Education/Experience:</p> <p>Minimum of five years of experience in Information Security & Compliance management supporting a complex business and systems environment. Minimum of a Bachelor's Degree, equivalent experience with specialization in information security is required, or industry relevant certifications is required. Comprehensive knowledge of effective supervisory/management practices and techniques. Proven track record effectively managing or designing IT security architecture and implementing IT Security controls. Experience is preferred in Theatre Information Technology; alternatively, experience in a retail global environment is highly desired. Detailed knowledge of the PCI DSS process and standards is highly desirable.</p> <p>Language Ability:</p> <p>Demonstrated skills to communicate difficult technical concepts clearly to a variety of individuals of varying technical expertise and understanding. Demonstrate effective decision-making skills, even under pressure and while lacking all of the desired information detail. Good written and verbal communication skills to deal effectively with the business unit executives, management and staff, as well as IT management and staff.</p> <p>Math Ability:</p> <p>Ability to work with mathematical concepts such as probability and statistical inference, and fundamentals of plane and solid geometry and trigonometry. Ability to apply concepts such as fractions, percentages, ratios, and proportions to practical situations.</p> <p>Reasoning Ability:</p> <p>Perform under pressure and/or opposition at times relying on your own independent judgment and knowledge to decide the best directions and solutions.</p> <p>Computer Skills:</p> <p>Word processing, Spreadsheets, E-mail, Database software, Networks, ability to write computer scripts and macros.</p> <p>Supervisory Responsibilities:</p> <p>The Director, Information Security & Compliance manages the activities of the Information Security & Compliance team and external resources. The primary role will be to coordinate Information Security activities with others within the IT Department to achieve Information Security objectives. Daily operational activities will be performed by Information Security & Compliance team members, IT, and / or external vendors performing a contracted service. Staff responsibilities include interviewing, hiring, and training employees; planning, assigning, and directing work; appraising performance; rewarding and disciplining employees; addressing complaints and resolving problems.</p> <p>Work Environment:</p> <p>The work environment characteristics described here are representative of those an employee encounters while performing the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform essential functions.</p> <p>Physical Demands:</p> <p>The physical demands described here are representative of those that must be met by an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform essential functions.</p> <p>While performing the duties of this job the employee is frequently required to stand, walk, sit, and use hands to finger, handle, or feel; reach with hands and arms; climb or balance; stoop, kneel, crouch, or crawl and talk or hear. The vision requirements include close vision, distance vision, peripheral vision, depth perception, and the ability to adjust focus. The employee is occasionally required to lift up to 50 pounds.</p>
POST A JOB
It's completely FREE to post your jobs on ZiNG! There's no catch, no credit card needed, and no limits to number of job posts.
The first step is to SIGN UP so that you can manage all your job postings under your profile.
If you already have an account, you can LOGIN to post a job or manage your other postings.
Thank you for helping us get Americans back to work!
It's completely FREE to post your jobs on ZiNG! There's no catch, no credit card needed, and no limits to number of job posts.
The first step is to SIGN UP so that you can manage all your job postings under your profile.
If you already have an account, you can LOGIN to post a job or manage your other postings.
Thank you for helping us get Americans back to work!