Loading jobs…
Loading jobs…
Eyecare Partners — St. Louis, Missouri
Role Overview The Head of Cybersecurity Governance is a senior leadership role responsible for establishing, operating, and continuously improving the firm’s cybersecurity governance program. This role owns cybersecurity awareness and training, the development and lifecycle management of all security policies and standards, and the coordination of cybersecurity regulatory compliance efforts in partnership with Legal, Privacy, Compliance, Risk, IT, and business teams. This leader will build and manage a high‑performing cybersecurity governance team and serve as a key connector between security strategy, regulatory obligations, and business execution.
The role reports to the Chief Information Security Officer (CISO) and plays a critical role in enabling a strong, scalable, and compliant cybersecurity posture across the organization. This role is hybrid with 3 days per week onsite in St.
Key Responsibilities
Cybersecurity Governance Policy Management Own the cybersecurity governance framework, ensuring alignment with enterprise risk management, business objectives, and regulatory
Requirements
Lead the creation, maintenance, and periodic review of all cybersecurity policies, standards, procedures, and guidelines. Establish and manage a formal policy lifecycle process, including approvals, exceptions, waivers, and annual reviews. Ensure policies are practical, enforceable, and clearly mapped to security controls and regulatory obligations.
Partner closely with Cybersecurity Engineering, Operations, and Risk Management teams to ensure governance is aligned with real‑world controls and practices. Cybersecurity Awareness Training Program Design, implement, and continuously improve the enterprise cybersecurity awareness and training program. Own mandatory security training, phishing simulations, role‑based training, and executive‑level awareness initiatives.
Measure training effectiveness through metrics, trends, and risk‑based outcomes. Promote a strong security culture across the organization, balancing education, accountability, and business enablement. Regulatory Compliance Program Leadership Partner with Legal, Privacy, Compliance, and Risk teams to design and operate a cohesive cybersecurity regulatory compliance program.
, NYDFS, GLBA, SEC, GDPR/CCPA, ISO, NIST).
, policies, controls, and evidence. Support regulatory exams, audits, client due diligence, and third‑party assessments related to cybersecurity governance. Monitor emerging cyber regulations and assess their impact on the organization.
Cross‑Functional Partnership Stakeholder Engagement Act as the primary cybersecurity governance partner for IT, Legal, Compliance, Privacy, HR, and business leaders.
into actionable guidance for technical and non‑technical teams. Provide clear, executive‑ready reporting on governance posture, compliance status, and key risk themes. Support board‑level and executive governance forums with clear, concise insights.
Team Leadership Program Management Build, lead, and mentor a cybersecurity governance team, including policy, training, and compliance specialists. Define team structure, roles, career paths, and performance expectations. Establish scalable processes, tooling, and metrics to support governance operations.
Drive continuous improvement through automation, standardization, and data‑driven decision‑making.
Qualifications
Experience 10+ years of experience in cybersecurity, governance, risk, or compliance roles, with increasing leadership responsibility. Proven experience building and running cybersecurity governance, policy, and awareness programs in a regulated environment.
Requirements (E.G., NIST CSF, ISO 27001, NYDFS, GLBA, SEC)
. Demonstrated a