Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy, and consent to receive emails from Rise
Jobs / Job page
Director Of IT Cyber Security Risk & Compliance image - Rise Careers
Job details

Director Of IT Cyber Security Risk & Compliance

Grow with us...

Life at Starwood Hotels is based on a simple idea: the world is beautiful and we want to keep it that way. But we can’t do it alone. That’s why hiring thoughtful and inspiring Team Members and Leaders who understand that our people, collaboration, stellar service, and respect for nature are so important to us.

Essential Functions & Responsibilities

As a member of the Home Office IT team, and under the direction of the VP of Information Technology, this role contributes advanced skill in cyber security technology solutions/architecture, hotel operations and business knowledge. This strategic role is responsible for leading, evolving, maintaining, auditing and remediating the group & hotels’ cyber risk and compliance program.  In execution this role will ensure all cyber security and compliance reporting operations executed by internal and external resources are monitored, secure, regulated, and aligned with brand, guest regulatory entity expectations. The Director of IT Cyber Security Risk & Compliance will interface with vendors, owners, auditors, home office executives, stakeholders and team members as required to…

  • Establish and lead a mature cyber risk program aligned with industry standards such as NIST Cybersecurity Framework (CSF) or ISO 27001 and hospitality relevant regulations such as PCI-DSS, GDPR, etc.
  • Partner with IT Department leadership to develop, document, evolve, audit and enforce IT security policies including secure configuration, edge/perimeter protection, secure configuration, vulnerability management, resiliency and incident response protocols.
  • Integrate with the broader enterprise-wide risk management (ERM) strategy and set the organization’s cyber risk tolerance.
  • Lead, monitor, audit and partner with the People and Operations leadership to foster and enforce cyber awareness and embedded security best practices across all teams.
  • Drive the cultural, technical and process changes necessary to enable a secure, cyber risk aware user base.
  • Collaborate with the Corporate Director of Applications and Network Security & Compliance to design, implement cyber strategies and solutions that will ensure secure and stable connectivity for all solutions, infrastructure and platforms.
  • Effectively initiate, plan, schedule, control, and bring to closure multiple high priority projects.
  • Monitor and audit all security related SOP’s, infrastructure, network and related architectures and solutions in alignment with SH Standards and policies.
  • Work across the enterprise/organization to provide domain-based knowledge and  leadership to prioritize and track and audit risk mitigation strategies/solutions.
  • Assess, evaluate, recommend innovative technologies and best practices for adoption
  • Establish a formal cyber risk committee and lead and report on the organization’s security posture monthly with reports and quarterly Security Forum Committee meetings.
  • Drive standardization and automation into all aspects of SH’s security monitoring, detection and response capabilities.
  • Maintain and update the organization’s cyber risk register with key risk indicator (KRI’s)
  • Serve as the primary liaison for internal audits (executed quarterly) and external audits (executed annually).
  • Engage and foster relationships with peer, business counterparts, and with internal and external customers to ensure smooth operations for hotel and corporate.
  • Participate in property updates, briefings that may arise due to issue escalation

REQUIREMENTS

  • A minimum of 7 to 10 years in hospitality IT Networking/Applications and Cyber Security practices and tools.
  • Corresponding experience in project management & delivery, process development & improvement and resource management.
  • 3 to 5 years’ experience in senior or featured leadership managing risk & compliance.
  • Familiarity and active experience ensuring environments and systems are compliant with regulatory entities and internal/organizational policies.
  • Proven experience leading development and delivery of multiple complex security-related technology solutions into production that have achieved or surpassed business goals.
  • Deep knowledge of system cyber security systems architecture, technical design, and system and software development technology.
  • Knowledge of emerging trends and developments in cyber-threats and related vulnerabilities including but not limited to PaaS, SaaS, endpoint, mobile, cloud, and AI environment.
  • Experience ensuring compliance with cyber security/risk regulations and entities that enable governance, maturity and best practices (i.e. NIST, PCI-DSS, GDPR, CPP, etc)
  • Takes on other duties needed to help drive our Purpose, fulfill our Brand Principles, and abide by our Organization’s Values.

About us...

As a mission-driven company, our purpose is our true north, and our compass guides the way. The purpose we live by impacts the lives of our team members, drives the experiences for our guests, builds community with like-minded travelers and takes care of the planet we live in. Founded in 2006 by Barry Sternlicht, Starwood Hotels is a luxury hotel brand management company and affiliate of global private investment firm Starwood Capital Group.

Starwood Hotels is an Equal Opportunity Employer. We believe in a diverse, sustainable workforce with an empowered, inclusive culture. We are committed to non-discrimination on any protected basis covered under applicable law. If you require any special accommodations, please visit People Operations.

Average salary estimate

$150000 / YEARLY (est.)
min
max
$120000K
$180000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

Similar Jobs
Truelogic Hybrid No location specified
Posted 1 hour ago

An opportunity to join Truelogic as a remote PIM Administrator overseeing Syndigo operations for a major global design marketplace.

Photo of the Rise User
Inclusive & Diverse
Empathetic
Collaboration over Competition
Growth & Learning
Transparent & Candid
Medical Insurance
Dental Insurance
Mental Health Resources
Life insurance
Disability Insurance
Child Care stipend
Employee Resource Groups
Learning & Development

Lead American Express's cloud security strategy and governance efforts to secure their evolving cloud environment as Director of Cybersecurity.

Photo of the Rise User
Posted 21 hours ago

Technical Staffing requires a skilled Network Engineer with DOD SECRET clearance to develop and implement advanced NAC system functionalities in Falls Church, VA.

PSU Hybrid Penn State University Park
Posted 21 hours ago

Support academic and research missions at Penn State by administering and maintaining complex Unix/Linux systems in a dynamic higher education environment.

A seasoned IAM Senior Engineer role at Toyota focused on designing, implementing, and maintaining secure identity and access management solutions to meet compliance and security objectives.

Ovation Healthcare Hybrid Cone Health - Greensboro, NC (remote)
Posted 6 hours ago

A skilled LIS Administrator / LIS QA is needed to lead clinical lab system optimization and support in a remote role at Ovation Healthcare, a leader in rural healthcare services.

Seeking a detail-oriented Clinical Analyst I to support perioperative and procedural healthcare informatics applications and optimize clinical operations at a major healthcare campus.

Photo of the Rise User
Posted 13 hours ago

Medtronic is seeking a Senior IT Technologist to lead infrastructure and operations at their Boulder site, driving technology solutions that support the company's mission to transform healthcare.

Lead the Nuclear Technology Services Operations team at Vistra to ensure operational excellence and technology process improvement in a highly regulated nuclear environment.

Photo of the Rise User
Jobgether Hybrid No location specified
Posted 1 hour ago

Support a high-impact IT team onsite as a Desktop Support Engineer, delivering front-line technical assistance and maintenance in a dynamic semiconductor corporate environment.

Photo of the Rise User
EVERSANA Hybrid Chicago, IL, USA
Posted 12 hours ago

EVERSANA is seeking a seasoned Content Engineer to lead content lifecycle automation and digital asset management for life sciences clients.

Photo of the Rise User
Posted 23 hours ago
Inclusive & Diverse
Empathetic
Collaboration over Competition
Growth & Learning
Transparent & Candid
Medical Insurance
Dental Insurance
Mental Health Resources
Life insurance
Disability Insurance
Child Care stipend
Employee Resource Groups
Learning & Development

Lead the proactive servicing and device health initiatives at American Express, ensuring optimal colleague experience through strategic IT service management.

Photo of the Rise User
Posted 21 hours ago

Take a leading role at Crusoe in advancing security for innovative AI-driven cloud products and fostering robust product security practices.

MATCH
Calculating your matching score...
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
No info
HQ LOCATION
No info
EMPLOYMENT TYPE
Full-time, unknown
DATE POSTED
August 10, 2025
Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!