Overview
In this role you will lead KBR’s global information security program, shaping the enterprise-wide cybersecurity strategy to protect systems, data, and IP while enabling secure growth. You will partner with executives and IT teams to manage cyber risk, resilience, and secure transformation across cloud, SaaS, and core enterprise apps. You will drive governance, policy, and compliance in line with global standards, and guide incident response and third-party risk. This position offers visibility across a global, matrixed organization and a clear impact on enterprise security culture.
Responsibilities
- Define and execute the organization’s information security strategy, operating model, and multi-year roadmap
- Act as the enterprise authority on cyber risk, threat posture, and resilience with executive stakeholders
- Establish and maintain security policies, standards, and governance aligned to NIST CSF, ISO 27001, SOX ITGCs, GDPR, and data protection requirements
- Oversee risk management, conduct risk assessments, and implement mitigations to reduce identified risks
- Monitor compliance with applicable laws, regulations, and contractual obligations related to information security
- Lead incident response and breach management, including regulatory coordination and remediation
- Embed secure-by-design practices in cloud adoption, enterprise apps, data platforms, and automation initiatives
- Oversee third-party and supplier cyber risk management and vendor security
- Support M&A activities and system integrations from a cybersecurity and risk perspective
- Build and develop a high-performing global information security organization and drive security awareness and accountability
Key requirements
- Bachelor in computer science, information security, engineering, or a related field
- Progressive professional experience in information security, IT risk, or technology leadership
- Proven ability to lead enterprise or cybersecurity programs in a global organization
- Expertise securing IT environments including cloud, SaaS, identity, and enterprise applications
- Executive-level communication skills translating technical risk into business impact
- Professional certifications preferably CISSP, CISM, or CRISC
- Executive communication
- Leadership
- Cross-functional collaboration
- Cloud security (AWS, Azure, or similar platforms)
- Identity and access management
- Security of ERP/HRIS/CRM and data platforms
…
