Director, Global Information Security

 Posted an hour ago
     
 $137K - $150K per year
  
10+ years experience
Apply Now

Please mention DailyRemote when applying

AI Summary

The Director of Global Information Security will lead the organization's cybersecurity program, overseeing policy development, risk management, and incident response across global operations. They will also manage vendor relationships and partner with internal teams to ensure security requirements are met across cloud, data, and infrastructure environments.

Position Title: Director, Global Information Security
Department: Information Technology (IT)
Location: Remote in CT, DC, FL, GA, IL, MD, MA, NC, NJ, NY, OR, PA, Puerto Rico, TN, TX, VA, or WA
Travel Required: 10%
Reports to: Vice President, Information Technology
Number of Direct Reports: 0
Assignment Type: Full-time; Exempt
Compensation: $137,319 to $150,900
Application Requirements: Resume; Completed application questions

About Americares: 
Global Health Starts with YOU!

Americares is a global health and disaster relief organization that helps people and communities around the world access health in times of disaster and every day. Each year, Americares reaches 85 countries on average, including the United States, with life-changing health programs, medicine, medical supplies and emergency aid. Americares is one of the world’s leading nonprofit providers of donated medicine and medical supplies. For more information, visit americares.org. 

Americares Values:
We create global community, treating people as they want to be treated.
We respond effectively and responsibly, putting plans into practice.
We embed ethics and equity in our work and workplace.
We are better together; partnership is at our core.
We ask and listen, to create sustainable solutions for a healthier tomorrow.
We commit to quality, growing and improving to ensure individuals and communities thrive.

About the Position:
The Director, Global Information Security will own and advance information security across our globally distributed humanitarian organization operating in high-risk environments, building and advancing our information security program, deepening partnerships, and sharpening a cybersecurity culture to keep Americares safe, resilient, and trusted.

With a technology footprint that spans country offices across multiple regions, a growing cloud and SaaS environment, and an expanding set of donor, partner, and beneficiary data obligations, Americares seeks dedicated, expert ownership of information security to operate responsibly at this scale. The Director, Global Information Security will play a critical role in leading the organization through a period of digital transformation, expanding the use of cloud platforms, data analytics, and AI-enabled tools across our global operations.

Duties and Responsibilities:

  • Own and advance Americares global information security program, including policy development, governance frameworks, security standards, and cybersecurity culture across HQ and country office operations worldwide.
  • Lead and oversee all managed security services and vendor relationships, including MDR/SOC provider performance, endpoint protection, email security, CIS membership and assessments, and cyber insurance compliance, ensuring vendors are held accountable to clear standards and delivering measurable value.
  • Conduct and manage CIS-based security assessments, produce prioritized risk registers and remediation roadmaps, oversee vulnerability management including risk ranking, remediation tracking, and exception handling, and report progress against the security roadmap to leadership.
  • Own the cybersecurity incident response plan, including maintenance, tabletop exercises, staff training, and active coordination with internal teams, including Legal, Compliance and Risk Management (LCRM), Finance, Communications, and country offices during incidents, ensuring alignment with the organization's broader crisis management and business continuity processes.
  • Partner with Technology Operations, Data Management and Enterprise Applications, Legal Compliance and Risk Management, and Global Safety and Security to define, validate, and maintain security requirements across infrastructure, applications, identity, data, and physical security.
    Oversee day-to-day security operations including SOC/MDR ticket review, escalation management, service quality oversight, identity and access control validation, and correlation of signals across endpoint, email, cloud, and network environments.
  • Represent Americares in peer security communities including NetHope and NGO-ISAC, serve as the internal subject matter expert on cybersecurity for leadership, and build a security-aware culture across a globally distributed workforce through awareness programs, policy socialization, and change management.
  • Actively model and contribute to Americares values, work culture and mission.
  • Engage in and contribute to team spaces with openness, global competencies, and a growth mindset.
  • Other duties and responsibilities as assigned.

In the first 90 days:

  • Learn and live the Americares values.
  • Complete all required new hire onboarding trainings.
  • Demonstrate an understanding of Americares programmatic work and business models.
  • Review IT policies and relevant vendor agreements.
  • Develop a deep understanding of our information security posture.
  • Document an initial understanding of Americares cybersecurity architecture, including the current state of endpoint protection, identity and access management, email security, cloud security, and SOC/MDR coverage, and identify immediate gaps requiring attention.
  • Begin to develop strong relationships towards becoming a key partner with critical stakeholders, including: Technology Operations, Legal, Compliance and Risk Management (LCRM), Global Safety and Security (physical security), Data Management & Enterprise Applications team, country office leadership, and external vendors and suppliers.
  • Establish a regular reporting cadence with the VP, Information Technology on security posture, active risks, and priority actions.
  • In close partnership with the Technology Operations team, LCRM, country office management teams and other relevant stakeholders, lead the review of the results from externally conducted CIS assessment and develop a prioritized risk register, recommended remediation roadmap, mitigation strategies, and a briefing for leadership.

In the first 6 months:

  • Develop a long-term global information security strategy and roadmap that aligns with Americares strategic objectives over the next 5 years.
  • Socialize and garner necessary buy-in and support for roadmap across the organization.
  • Identify and plan for necessary resources for roadmap in FY28.
  • Own the cybersecurity Incident Plan, making updates as needed, and train relevant stakeholders.
  • Ensure the cybersecurity Incident Plan is coordinated with the organization's crisis management and business continuity processes so the incident plan reflects operational continuity beyond the technical response.

In the first year:

  • Complete Phase I of the information security roadmap.
  • Achieve significant organization-wide understanding and adoption of IT policies and security SOPs through socialization and change management.
  • Demonstrate improvement in CIS assessment scores based on positive impact from the cybersecurity roadmap.

Degrees/Certifications that are required for the role:

  • CISM, CISSP, CySA+, Security+, or Microsoft security certifications such as SC-200 or SC-300

Competencies required for the role include:

  • Influence and Functional Authority: Achieves security outcomes through people and teams who do not report to them. Builds credibility with peers in Infrastructure, Data Management, Enterprise Applications, Legal, and country operations. Sets clear expectations and holds others accountable through relationship and expertise rather than positional authority. Knows when to escalate to the VP and when to resolve laterally.
  • Security Judgment and Risk Communication: Translates complex and evolving cybersecurity risks into clear, actionable language for non-technical audiences including leadership, Legal, country directors, and program staff. Makes sound risk prioritization decisions under uncertainty and resource constraints. Knows what to escalate, what to absorb, and what to defer.
  • Program Building in a Resource-Constrained Environment: Has built or materially advanced a security program without a large team or budget. Comfortable doing hands-on work while simultaneously designing the governance structures, policies, and processes that others will eventually operate. Does not wait for perfect conditions. Understands security and data-protection considerations for AI-enabled tools and platforms; partners with the organization's AI governance effort to define security guardrails and requirements for AI tool adoption. 
  • Vendor and Partner Oversight: Manages external security relationships (MDR, SOC, CIS, insurance company, consultants) with discipline. Knows what to expect from a managed service provider, how to hold them accountable, and when their output is insufficient. Has experience selecting and onboarding security vendors. Will demonstrate a high degree of professionalism and finesse as they work with a wide range of partner organizations who receive resources/funding on information security matters.
  • Global and Cross-Cultural Awareness: Has worked in or alongside organizations operating in multiple geographies, ideally in development, humanitarian, or health contexts. Understands that security controls that work at HQ may need to be adapted for low-bandwidth, high-risk, or resource-limited country office environments, as well as high-risk, politically sensitive, and emergency response operating environments, where practical implementation of security controls often requires additional flexibility.
  • Ownership and Resilience: Drives their focus area independently. Anticipates challenges, proposes solutions, and does not wait to be told what to do next. Approaches novel threats and organizational constraints with a growth mindset, modeling adaptability for the teams and partners they work with. Comfortable operating in ambiguity, especially during the program-building phase where not everything is defined yet.
  • Communication and Stakeholder Engagement: Communicates security posture, risks, and recommendations clearly to diverse audiences, including preparing board-level materials in partnership with the VP of IT; engages directly with senior stakeholders as needed. Facilitates alignment among stakeholders with competing priorities. Engages country office and department stakeholders in ways that build buy-in rather than resistance. Can represent Americares in peer communities like NetHope and NGO-ISAC.

US work authorization without restriction and 10% travel are required for this role.

Candidates must be currently living in and will continue to live in one of the following states/territories: CT, DC, FL, GA, IL, MD, MA, NC, NJ, NY, OR, PA, Puerto Rico, TN, TX, VA, or WA.

These competencies are preferred but not required for the role:

  • Fluency in languages that are spoken in at least one of our core locations (India, Philippines, Tanzania, El Salvador, Puerto Rico, Colombia, etc.), in addition to English

Additionally, our core competencies as an organization are:

  • Ownership and results
  • Communication
  • Problem solving
  • Equity and inclusion
  • Teamwork and conflict resolution
  • Leadership
  • Prioritization
  • Management
  • Strategy and planning
  • Decision making

Recruitment Process:

  • Completed application and resume
  • Virtual interview with People and Talent (1 hour)
  • Competency Exercise
  • Virtual Interview with Hiring Manager (1 hour)
  • Panel Interview with internal stakeholders (1 hour)
  • Virtual Interview with Chief People and Systems Officer (1 hour)

Americares complies with the EEOC: https://www.eeoc.gov/laws

 

Americares is currently authorized to support remote work employees in the following locations: CT, DC, FL, GA, IL, MD, MA, NC, NJ, NY, OR, PA, Puerto Rico, TN, TX, VA, and WA. Please note that we do not provide relocation assistance at this time. #LI-REMOTE   

 

Americares is committed to ensuring safe and accountable workplaces and programs. Our code of conduct, organizational values, and policies and procedures help to safeguard the welfare of everyone working for and participating in Americares programs. Americares is committed to the prevention of all types of abuse, discrimination, harassment, and exploitation. Employment with Americares will be subject to appropriate screening, reference, credentials, and background checks. By applying to our organization, job applicants confirm their understanding of and consent to our procedures during recruitment, and to adhering to our values and commitment to safe and accountable workplaces and programs as an employee.

 

This job description may not be inclusive of all assigned duties, responsibilities, or aspects of the job described, and may be amended at any time at the sole discretion of Americares. At any point in the recruitment process, we may request additional information to confirm qualifications. Any misrepresentation of qualifications in any stage of the process will prevent the applicant from moving forward in the process.    

 

If you have a specific request or need assistance to fully participate in the application or recruitment process, please email us at talentcenter@americares.org.

Similar Jobs

See all Remote Software Development jobs →

Personalize your Remote Job Search in 3 Easy Steps!

Discover remote opportunities in Software Development

Answer easy questions

Answer easy questions

200,000+ jobs across 15+ categories

Get your best job matches

Get your best job matches

Only hand-screened, legit jobs

Find a remote job faster

Find a remote job faster

No ads, scams, or junk

I was the first applicant for a remote marketing position that got listed on the company website the same day I applied. Had an interview within 48 hours!

Sarah J. — Sarah J. · Marketing Manager ★★★★★ Verified