Cummins
Cybersecurity Director
Remote, United States · Remote · Posted today
Opens fa-espx-saasfaprod1.fa.ocs.oraclecloud.com
Get a version of your resume written for this job.
- Salary
- Not listed
- Job type
- Full-time
- Work mode
- Remote
- Source
- Oracle (employer's hiring system)
Skills mentioned
Cybersecurity, Penetration Testing, Cloud Security, SIEM
About the role
We are seeking an experienced Cybersecurity Director to be responsible for the global strategy, leadership, and maturity of Application Security, Vulnerability Management, Cloud Security, and Penetration Testing. The role identifies and evaluates cybersecurity exposures across applications, infrastructure, cloud environments, products, and technology platforms and partners with the organizations responsible for mitigating those risks. This role is offsite remote.
The Director works closely with Global Cyber Security Governance, Risk & Compliance (GRC) and other stakeholders to enable the communication and prioritization of technical security findings into business risk, influence enterprise risk prioritization, strengthen compliance and control frameworks, and provide measurable evidence of risk reduction.
The role also maintains a strong understanding of Frontier AI and emerging technologies, helping the organization securely adopt AI capabilities while identifying opportunities to use AI to improve cybersecurity effectiveness, automation, and risk management.
In this role, you will make an impact in the following ways:
Application Security
- Champion the global Application Security oversight program and security-by-design practices.
- Partner with stakeholder to integrate security into product development, SDLC, DevSecOps, and application processes.
- Oversee the analysis of application security finding and vulnerability identification and prioritization.
- Partner with Product, Engineering, Platform teams to prioritize and remediate application risk.
Vulnerability Management
- Lead enterprise vulnerability identification, prioritization, remediation, and validation.
- Establish risk-based prioritization using exploitability, threat intelligence, and exposure.
- Provide vulnerability intelligence to GRC to support enterprise cyber risk decisions.
- Identify systemic and recurring vulnerabilities requiring broader corrective action.
Cloud Security
- Lead the global Cloud Security strategy and security requirements.
- Identify and manage risks across cloud infrastructure, workloads, identities, configurations, applications, and data.
- Partner with Cloud, Infrastructure, Architecture, Product, and Engineering organizations to reduce cloud risk.
- Integrate cloud security risk into enterprise cyber risk management and prioritization processes and platforms.
Penetration Testing & Offensive Security
- Develop the penetration testing service offering in cooperation with Internal Audit and other stakeholders.
- Validate vulnerabilities and security controls through penetration testing and red team exercises,
- Identify exploitable attack paths and systemic security weaknesses by partnering with purple team partners.
- Provide evidence-based assessments and validate remediation through oversight of Pen Test reporting.
Cyber Risk & GRC Partnership
- Partner with Cyber GRC to translate technical security findings into business risk.
- Develop methodologies, metrics, and indicators that improve cyber risk prioritization.
- Provide technical input into risk assessments, policies, controls, compliance, and risk acceptance decisions.
- Support identification and escalation of material cyber risks.
- Ensure remediation accountability remains with the appropriate Product, Technology, or Business owner.
Frontier AI & Emerging Technology
- Maintain a working understanding of Frontier AI, AI agents, emerging AI architectures, and associated cybersecurity risks.
- Partner with AI, Product, Data, Engineering, and GRC organizations to support secure AI adoption.
- Identify opportunities to leverage AI for vulnerability prioritization, security testing, risk analysis, automation, and cyber defense.
- Help incorporate emerging AI risks into cybersecurity and enterprise risk frameworks.
Leadership & Influence
- The Director will lead globally through influence, partnership, and accountability, working across Cyber Security, GRC, Product, Engineering, Cloud, Infrastructure, IT, and business organizations.
- The role must effectively translate technical cybersecurity issues into business risk and actionable decisions, balancing security requirements with business priorities, operational needs, cost, and innovation.
Measures of Success
- Success will be measured by:
- Reduction in material cybersecurity risk.
- Improved visibility and prioritization of application, cloud, and infrastructure vulnerabilities.
- Faster remediation of material security exposures.
- Increased adoption of secure-by-design practices.
- Improved effectiveness of penetration testing and security validation.
- Stronger integration between Cyber Security and the enterprise risk and compliance frameworks.
- Improved executive visibility into cyber risk.
- Increased automation and use of AI to improve cybersecurity outcomes.
- Secure and effective adoption of Frontier AI and emerging technologies.
To be successful in this role you will need the following:
- Action oriented - Taking on new opportunities and tough challenges with a sense of urgency, high energy, and enthusiasm.
- Business insight - Applying knowledge of business and the marketplace to advance the organization’s goals.
- Communicates effectively - Developing and delivering multi-mode communications that convey a clear understanding of the unique needs of different audiences.
- Customer focus - Building strong customer relationships and delivering customer-centric solutions.
- Drives results - Consistently achieving results, even under tough circumstances.
- Drives vision and purpose - Painting a compelling picture of the vision and strategy that motivates others to action.
- Global perspective - Taking a broad view when approaching issues, using a global lens.
- Manages complexity - Making sense of complex, high quantity, and sometimes contradictory information to effectively solve problems.
- Tech savvy - Anticipating and adopting innovations in business-building digital and technology applications.
- Regulatory Risk Compliance Management - Evaluates the design and effectiveness of controls against established industry frameworks and regulations to assess adherence with legal/regulatory requirements.
Education/Experience
- College, university, or equivalent degree in Computer Science, Information Technology, Engineering, or related subject, or relevant equivalent experience required.
- Global Information Assurance Certification (GIAC) Security Essentials Certification, GIAC Security Leadership Certification, Information Systems Audit and Control Association (ISACA) Certified Information Security Manager, Microsoft Certified Systems Engineer: Security, or Certified Information Systems Security Professional (CISSP) certification preferred.
- Understanding of the capabilities and configuration of industrial cybersecurity controls and solutions across multiple facets; for example: asset management, vulnerability management, anomaly detection, identity and access management, network security, endpoint security, application security, IDS/IPS, deep packet inspection, SIEM, data analytics, security and/or risk management and product development.
- This position may require licensing for compliance with export controls or sanctions regulations.
Job ID or-fa-espx-saasfaprod1-fa-ocs-oraclecloud-com-cx-1-2438893 · Original posting ↗
Visa sponsorship history
- 245 H-1B petitions approved for CUMMINS INC in fiscal year 2023 (USCIS).
From public government data. It shows this employer has sponsored workers before, not that this job offers sponsorship: check the job ad or ask the employer. More visa-friendly jobs