
Associate Director – Cybersecurity Posture, Hygiene and AI
Posted 2 days ago

Posted 2 days ago
This is a fully remote position, open to applicants in United States.
• Develop and oversee an enterprise security posture and hygiene program that encompasses strategy, roadmap, operational cadence, governance, and direct team management.
• Manage and nurture a multidisciplinary team responsible for control assessments, configuration hygiene, remediation planning, and ongoing enhancement.
• Utilize AI to expedite continuous control monitoring and response efforts.
• Integrate posture and hygiene telemetry from AI-driven tools, custom solutions, and workflows to identify misuse, configuration drift, and critical control deviations.
• Detect both intentional and unintentional misuse of AI-driven tools and workflows, converting findings into proactive systemic control enhancements.
• Create and advance a control framework that aligns with the CIS Top 18 Controls and their corresponding safeguards.
• Develop a methodology for assessing control maturity, identifying systemic gaps, and prioritizing remediation based on risk and business impact.
• Collaborate with infrastructure, cloud, identity, network, endpoint, application, and AI engineering teams to incorporate secure-by-default configurations and robust architectures.
• Generate metrics, dashboards, and executive-level reports on posture trends, control effectiveness, and remediation progress.
• Publish standards, playbooks, and guidelines for secure design, deployment, and operational practices.
• Remain informed about emerging risks associated with AI, automation, and contemporary attack techniques.
• A Bachelor's degree with 9 years of experience, a Master's degree with 8 years of experience, or a PhD with 4 years of experience.
• Demonstrated cybersecurity leadership within complex and varied IT environments.
• Extensive background in managing security posture and hygiene strategies.
• Experience in implementing an enterprise-level AI security program.
• In-depth knowledge of operating systems, networking protocols, systems administration, X-as-a-service, applications, and security technologies.
• Proficient understanding of cybersecurity terminology, concepts, the cyber threat landscape, and attack vectors.
• Comprehensive grasp of risk management principles and their application in security practices.
• Capability to innovate and adapt within an ever-evolving environment.
• Advanced critical thinking, problem-solving, and analytical abilities.
• Strong leadership and collaboration skills with both business and technical teams.
• Excellent written and verbal communication skills, along with active listening abilities.
• Proficient in conveying technical insights to both technical and non-technical stakeholders.
• Ability to interact effectively with clients, IT management, and staff members.
• Eagerness to learn and remain updated on cybersecurity advancements.
• Relevant professional cybersecurity certifications such as CISSP, CISM, or CIS Controls are highly preferred.
• Paid time off (vacation, holidays, sick leave).
• Medical, dental, and vision insurance.
• 401(k) retirement plan.
• Short-term incentive programs.
• Opportunities for professional growth and development.
ASG Technologies
CrowdStrike
Culmen International
Threatscape
Get handpicked remote jobs straight to your inbox weekly.