HireFT
Browse JobsHow it worksPricingAboutSuccess Stories
    Back to jobs
    EX

    Exponent Inc.

    Engineering Consulting

    Director of Information Security

    Phoenix, United StatesOn-SiteFull-timePosted 17h ago
    All Exponent Inc. jobs

    Job description

    About Exponent

    Exponent is the only premium engineering and scientific consulting firm with the depth and breadth of expertise to solve our clients’ most profoundly unique, unprecedented, and urgent challenges.

    Our vision is to engage multidisciplinary teams of science, engineering, and regulatory experts to empower clients with solutions that create a safer, healthier, more sustainable world. For over five decades, we've connected the lessons of past failures with tomorrow's solutions to advise clients as they innovate technologically complex products and processes, ensure the safety and health of their users, and address the challenges of sustainability.

    Join our team of experts with degrees from top programs at over 500 universities and extensive experience spanning a variety of industries. At Exponent, you’ll contribute to the diverse pool of ideas, talents, backgrounds, and experiences that drives our collaborative teamwork and breakthrough insights. Plus, we help you grow your career through mentoring, sponsorship, and a culture of learning. Thanks for your interest in joining our team!

    Key statistics: 

    • 950+ Consultants
    • 640+ Ph.D.s
    • 90+ Disciplines
    • 30+ Offices globally

    Our Opportunity

    We are currently seeking a Director of Information Security residing in Phoenix, AZ. In this role you will work as part of the Information Technology Team reporting to the Vice President of Information Technology

    You will be responsible for

    ACCOUNTABILITY

    EXPECTED SCOPE

    Strategy, governance and executive advisory

    Develop and execute the multiyear security and privacy strategy, roadmap, operating model and investment priorities. Translate cyber, privacy, operational and regulatory risk into clear business, financial, client and reputational impact for executive leadership, board and governance bodies

    ISMS, PIMS and regulatory assurance

    Serve as accountable manager for ISO/IEC 27001, 42001 and ISO/IEC 27701. Chair required governance forums; maintain policies, objectives, risk treatment, management review, evidence and continual improvement. Coordinate with Legal on applicable contractual, legal and privacy obligations.

    Security risk and architecture

    Direct enterprise risk assessment, risk acceptance, control design and secure architecture across identity, cloud, network, endpoint, applications, data and AI. Embed security and privacy requirements into projects, acquisitions, vendors and technology change.

    Security operations and resilience

    Provide executive oversight for incident response, threat detection, vulnerability management, access governance, penetration testing, digital forensics and incident coordination. Ensure escalation, communications, law-enforcement and external-response decisions are documented and exercised.

    Privacy and data protection

    Act as Data Protection Officer and privacy escalation authority. Oversee privacy risk assessment, data protection requirements, information classification, data handling, transfer and disclosure decisions, and alignment with global privacy obligations.

    Client, third-party and market assurance

    Own the security assurance model for client questionnaires, contractual commitments, audits and restricted-information requirements. Direct third-party security risk management and support business development by clearly articulating Exponent’s security and privacy posture.

    Metrics, audit and continuous improvement

    Establish business-relevant metrics covering risk, incidents, vulnerabilities, audit findings, control effectiveness, awareness, third parties and program maturity. Sponsor internal and external audits, drive remediation, and report trends and investment outcomes.

    Leadership, budget and operating maturity

    Lead, develop and retain the security and privacy team; define accountability, succession, on-call coverage and service expectations. Own budget planning, vendor and contract portfolio, resource allocation, and delivery through internal teams and managed service partners.

    Leadership Outcomes

    • Maintain a defensible, audit-ready security and privacy program aligned to Exponent’s business objectives and client commitments.
    • Reduce material cyber and privacy risk through prioritized treatment plans, clear ownership, measurable controls and timely escalation.
    • Enable consulting, litigation and corporate operations to adopt technology, cloud and AI securely without unnecessary friction.
    • Provide executives with concise, decision-oriented reporting on risk posture, incidents, investment needs and program maturity.
    • Build a resilient operating model with documented authority, repeatable processes, qualified backups and effective external partners.

    You will have the following skills and qualifications

    • Progressive leadership experience directing enterprise information security, privacy, cyber risk or related programs in a distributed, regulated or client-trust-dependent environment. This experience must include building, transforming and or directing an information security program.
    • Demonstrated ownership of security strategy, governance, budget, vendors, metrics and multiyear transformation roadmaps.
    • Proven experience managing a compliance program.
    • Practical leadership of ISO/IEC 27001 programs and audits; working knowledge of privacy management and ISO/IEC 27701 strongly preferred.
    • Experience directing incident response, vulnerability management, identity and access governance, third-party risk, security architecture, MDR/MSSP services and audit remediation. This must include experience responding to a business impacting incident.
    • Ability to advise executives, clients, auditors, counsel and technical leaders, including during incidents, regulatory scrutiny and high-impact decisions.
    • Working knowledge of modern Microsoft security and identity capabilities, cloud platforms, endpoint and network security, data protection, Purview, AI security and secure software practices.
    • Bachelor’s degree in information technology, cybersecurity, risk management or a related field, or equivalent relevant experience.
    • Relevant certification such as CISSP required or expected; CISM, CRISC, PMP, ISO 27001 Lead Implementer/Lead Auditor, or privacy credentials are valued.

    Leadership Competencies

    Business and risk judgment

    Balances protection, client obligations, cost and speed; makes clear, defensible decisions under uncertainty.

    Executive communication

    Converts technical risk into concise business choices, ownership, investment and measurable outcomes.

    Incident leadership

    Provides calm, decisive authority during incidents and coordinates technical, legal, privacy and business response.

    Enterprise influence

    Builds trusted partnerships across IT, Legal, HR, Finance, Operations, consultants, clients and third parties.

    Operational discipline

    Establish durable governance, metrics, evidence, service ownership, succession and continuous improvement.

    Talent leadership

    Sets clear expectations, develops capability, delegates effectively and creates accountability without concentrating knowledge.

    Life @ Exponent

    To learn more about life at Exponent and our impact, please visit the following links:https://www.exponent.com/careers/life-exponenthttps://www.exponent.com/company/our-impact

    We value and encourage diversity, equity and inclusion across all facets of our firm. Having a team built of people with different backgrounds, skills and perspectives allows us to provide better value to our clients and enjoy an enriched work environment.

    Our firm is committed to offering a variety of programs and resources to support health and well-being. We believe that providing competitive benefits, as well as compensation and recognition programs, empowers our staff to do work that makes a difference.

    Work Environment

    At Exponent, we have found that in-person interactions deepen employee engagement and are crucial for development, for realizing the full potential of our talented and diverse teams, and for​ building a more inclusive workplace where all have a sense of belonging. In our offices, you can expect a supportive culture and a collaborative, dynamic, multi-disciplinary work environment.I-Onsite

    Compensation

    The pay rate for this position is dependent on experience and capabilities which will be assessed during the interview process.

    Benefits you will enjoy

    Access benefits information on our Life@Exponent page:  https://www.exponent.com/careers/life-exponent

     Exponent is a proud equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, veteran status, disability, sexual orientation, gender identity, or any other protected status.

     If you need assistance or accommodation due to a disability, you may email us at [email protected].

    Job Locations

    US-AZ-Phoenix

    Job details are sourced from the employer's original posting.

    Open job posting
    EX

    About the company

    Exponent Inc.

    Exponent is a leading engineering and scientific consulting firm that brings together experts from diverse fields to solve complex technical challenges.

    View all Exponent Inc. jobs
    Industry
    Engineering Consulting
    Open roles
    251

    Interested in this role?

    Apply with HireFT

    Free to start — no card required.

    Your fit

    How well do you match?

    Sign in to see how your résumé lines up with this role.