Hiring.Camp

Director of Information Security

Druryhotels

·

Yesterday

Location
US MO St. Louis STL Corporate Office, United States of America
Workplace
Onsite
Type
Full-time
Department
Security
Seniority
Director
Experience
10+ years
Visa
Not sponsored
Source
Workday

Description

This position is on-site in St. Louis, Missouri.

Candidates must be authorized to work in the United States and not require current or future employment visa sponsorship. Drury Hotels does not sponsor employment visas for this position.

Property Location:

13075 Manchester Rd - St. Louis, Missouri 63131

You belong at Drury Hotels.

Getting a job is just the beginning. Finding a place where you belong is what truly matters. Who you are and what you do makes a difference at Drury Hotels. There's a place for you here today and tomorrow.

WHAT YOU CAN EXPECT FROM US


So. Much. More.


Just as our guests deserve more, so do you deserve more. Be valued for what you do and who you are ... and well compensated for all you accomplish.

  • Work-life-balance – Flexible scheduling, paid time off, hotel discounts and free room nights

  • Career growth - Mentorship, cross-training, development plans, management training, and more-over 200 internal promotions this year

  • Health and well-being - Medical, dental, vision, prescription, life, disability and Team Member Assistance Program

  • Retirement - Company-matched 401(k)

  • Award-winning - Ranked among Newsweek's America's Greatest Workplaces 2025

  • Incentives - Quarterly bonuses (we succeed together!) based on hotel results

Summary:

Leads the company’s cybersecurity program, overseeing governance, risk, compliance, and day-to-day security operations. Responsible for information security across internal systems, cloud solution providers, vendor/third-party solutions, identity and access management, and application development.

Establishes security architecture, strategic roadmaps, and operational standards to strengthen the company’s overall security posture. Evaluates and implements technologies and processes to improve efficiency, effectiveness, and strengthen overall security posture. Oversees capabilities that enable the organization to identify, protect, detect, respond to, and recover from cyber threats and vulnerabilities.

Defines security requirements using risk assessments, threat modeling, testing, and analysis of existing systems. Ensures operational security activities (including endpoint security and patch management) are performed timely and efficiently. Oversees compliance related activities including PCI compliance and NIST alignment.

Responsibilities and Duties:

  • Provide leadership and direction for the cybersecurity program, managing a team that includes security operations and security compliance (GRC) leadership.

  • Develop, maintain, and evolve a security roadmap and annual operating plan that balances operational needs, compliance requirements, and risk reduction.

  • Stay current on industry threats, alerts, technology trends, and best practices related to cybersecurity.

  • Oversee day-to-day security operations through the Supervisor of IT Security Operations, including monitoring/SOC, endpoint security (EDR), identity, vulnerability management, and timely remediation of alerts.

  • Oversee governance, risk, and compliance through the Manager of Compliance and Security, including policy/standards management (e.g., NIST), risk assessments, audit support, and compliance obligations (e.g., PCI DSS). In a lean team environment, this role may also support operational security controls such as email security, Active Directory/Group Policy (GPOs), and network access controls (ACLs).

  • Facilitates a metrics and reporting framework to measure the efficiency and effectiveness of the program, facilitates appropriate resource allocation, and increases the maturity of the cybersecurity, and reviews it with stakeholders at the executive and board levels.

  • Directs the cybersecurity awareness training program for all team members and establishes metrics to measure the effectiveness of this security training program.

  • Establish and enforce security standards and “security by design” practices across technology platforms, application development, and vendor solutions.

  • Partner with IT operations to define, test, and oversee disaster recovery and business continuity security requirements and resilience controls.

  • Oversee third-party security partners and vendor security posture, including due diligence, contractual security requirements, and ongoing third-party risk management.

  • Hire, develop, coach, and evaluate team members; establish clear goals and metrics; and ensure appropriate training and professional development.

Basic Qualifications:

  • Strong analytical, problem-solving, and decision-making skills.

  • Ability to learn and apply new technologies and security concepts quickly.

  • Ability to communicate complex security topics to technical and non-technical stakeholders at an appropriate level of detail.

  • Strong collaboration skills; ability to work effectively with coworkers, leaders, and external partners/vendors.

  • Ability to work independently, prioritize competing demands, and lead through influence in a team environment.

  • Ability to evaluate security tools and vendors, negotiate contracts, and manage vendor relationships.

  • Demonstrated experience leading teams and influencing across IT and the business.

  • Working knowledge of incident response concepts and operational security practices (e.g., endpoint security, vulnerability management, patching).

  • Ability to apply a risk-based approach to prioritize security investments and activities.

  • Effective verbal and written communication skills.

  • Demonstrated experience and success in senior leadership roles in risk management, cybersecurity, and IT or OT security

  • Experience with contract and vendor negotiations

Required Qualifications:

  • 10+ years of experience in cybersecurity, including leadership/management experience.

  • Production/enterprise experience operating and improving security controls (e.g., EDR, vulnerability management, email security, network security).

  • Experience with security frameworks and compliance requirements (e.g., NIST, PCI DSS) and translating them into actionable controls.

  • Experience with identity and access management (IAM), privileged access, and related monitoring practices.

  • Experience with third-party/vendor risk management and security assessments.

Preferred Qualifications:

  • Experience leading large teams, including managing managers.

  • Strong knowledge of network and security fundamentals and how they apply to enterprise environments.

  • Experience with security budgeting, KPI/metrics reporting, and multi-year roadmap development.

  • Experience with Microsoft administrative controls and governance.

  • Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified Information Systems Auditor (CISA), Certified in Risk and Information Systems Control (CRISC) or other similar credentials

Rise. Shine. Work Happy. Apply Now

Skills

CybersecuritySOCRisk ManagementComplianceCISSP

Similar Jobs

30

Director of Information Services - Institutional Advancement and UW Foundation

University of Wyoming · Laramie, WY, United States, US · Onsite

Today

Senior Director of Information Security

Berklee Careers · Remote (USA), United States of America · Remote

Yesterday

DIRECTOR OF INFORMATION TECHNOLOGY

La Crosse County · 300 4th St N, La Crosse, WI 54601, USA

2 days ago

Director of Information Systems

Paradise Royale · Las Vegas, NV

2 days ago

Market Director of Information Technology & Services | Healthcare IT | $101K–$136K

Purple Cow Recruiting · Lake Havasu City, AZ · Onsite

4 days ago

Director of Information Technology

Destination Cleveland · Cleveland, OH

6 days ago

Director of Information & Academic Technology

The O'Connor Group · Philadelphia, PA

6 days ago

Director of Information Technology

Halma · Microsurgical Technology HQ, United States of America

1 week ago

Associate Director of Information Technology/Chief Information Security Officer

Career Opportunities · University of Arkansas at Little Rock, United States of America

1 week ago

Director of Information Technology

Wisconsin · Educational Sciences-0154, United States of America · Remote

1 week ago

Director of Information Technology

Hydraulic Controls · Modesto, CA

1 week ago

Director of Information Technology

Seneca Nation Health System · Irving / Salamanca, New York

1 week ago

Director of Information Technology

Bluetree · Reno, NV

1 week ago

Director of Information Technology & Business Systems

HTO EMP LLC · Fort Worth, Texas

2 weeks ago

Senior Director of Information Risk & Governance

Modernhealth · Remote - US · Remote

2 weeks ago

DIRECTOR OF INFORMATION TECHNOLOGY (PROVISIONAL)

City of Buffalo · BMHA 300 Perry Street, NY, US

2 weeks ago

Director of Information Assurance

Peraton · Reston, VA, US

3 weeks ago

Director of Information Technology

Fourseasons · Four Seasons Silicon Valley, United States of America

3 weeks ago

Director of Information Technology

HFLW · Boston, MA

3 weeks ago

Director of Information Governance

Pillsburylaw · Nashville, United States of America +3

3 weeks ago

Director of Information Security

Sorren · Corporate, United States of America · Remote

3 weeks ago

Director of Information Technology

Fourseasons · Four Seasons Costa Rica

3 weeks ago

Director of Information Technology Services

City of Chula Vista · Chula Vista, CA, CA, US

3 weeks ago

Director of Information Technology - Healthcare - Town & Country

Esse Health · St. Louis, MO

4 weeks ago

Director of Information Technology

Come Join Our Team!!!!! - CIty of San Juan, Texas · San Juan, TX

4 weeks ago

Director Of Information Security

UK Biobank · Cheadle

1 month ago

Director of Information Technology - San Francisco, CA or Bellevue, WA

Arctiq · Sacramento, California

1 month ago

Director of Information Technology

Storycannabis · Phoenix, Arizona, United States

1 month ago

Director of Information Technology

AUIB · Baghdad, Iraq, IQ

1 month ago

Director of Information Technology

Whitmanjobs · Washington, District of Columbia, US

1 month ago