We use cookies. Find out more about it here. By continuing to browse this site you are agreeing to our use of cookies.
#alert
Back to search results
New

Director of Information Security

Exponent
United States, Arizona, Phoenix
23445 North 19th Avenue (Show on map)
Oct 01, 2026

Director of Information Security


ID

2026-2621





Location

US-AZ-Phoenix

Practice
Information Security

Position Type
Full-time

Workplace Type
On-Site



About Exponent

Exponent is the only premium engineering and scientific consulting firm with the depth and breadth of expertise to solve our clients' most profoundly unique, unprecedented, and urgent challenges.

Our vision is to engage multidisciplinary teams of science, engineering, and regulatory experts to empower clients with solutions that create a safer, healthier, more sustainable world. For over five decades, we've connected the lessons of past failures with tomorrow's solutions to advise clients as they innovate technologically complex products and processes, ensure the safety and health of their users, and address the challenges of sustainability.

Join our team of experts with degrees from top programs at over 500 universities and extensive experience spanning a variety of industries. At Exponent, you'll contribute to the diverse pool of ideas, talents, backgrounds, and experiences that drives our collaborative teamwork and breakthrough insights. Plus, we help you grow your career through mentoring, sponsorship, and a culture of learning. Thanks for your interest in joining our team!

Key statistics:

    950+ Consultants
  • 640+ Ph.D.s
  • 90+ Disciplines
  • 30+ Offices globally


Our Opportunity

We are currently seeking a Director of Information Security residing in Phoenix, AZ. In this role you will work as part of the Information Technology Team reporting to the Vice President of Information Technology



You will be responsible for

ACCOUNTABILITY

EXPECTED SCOPE

Strategy, governance and executive advisory

Develop and execute the multiyear security and privacy strategy, roadmap, operating model and investment priorities. Translate cyber, privacy, operational and regulatory risk into clear business, financial, client and reputational impact for executive leadership, board and governance bodies

ISMS, PIMS and regulatory assurance

Serve as accountable manager for ISO/IEC 27001, 42001 and ISO/IEC 27701. Chair required governance forums; maintain policies, objectives, risk treatment, management review, evidence and continual improvement. Coordinate with Legal on applicable contractual, legal and privacy obligations.

Security risk and architecture

Direct enterprise risk assessment, risk acceptance, control design and secure architecture across identity, cloud, network, endpoint, applications, data and AI. Embed security and privacy requirements into projects, acquisitions, vendors and technology change.

Security operations and resilience

Provide executive oversight for incident response, threat detection, vulnerability management, access governance, penetration testing, digital forensics and incident coordination. Ensure escalation, communications, law-enforcement and external-response decisions are documented and exercised.

Privacy and data protection

Act as Data Protection Officer and privacy escalation authority. Oversee privacy risk assessment, data protection requirements, information classification, data handling, transfer and disclosure decisions, and alignment with global privacy obligations.

Client, third-party and market assurance

Own the security assurance model for client questionnaires, contractual commitments, audits and restricted-information requirements. Direct third-party security risk management and support business development by clearly articulating Exponent's security and privacy posture.

Metrics, audit and continuous improvement

Establish business-relevant metrics covering risk, incidents, vulnerabilities, audit findings, control effectiveness, awareness, third parties and program maturity. Sponsor internal and external audits, drive remediation, and report trends and investment outcomes.

Leadership, budget and operating maturity

Lead, develop and retain the security and privacy team; define accountability, succession, on-call coverage and service expectations. Own budget planning, vendor and contract portfolio, resource allocation, and delivery through internal teams and managed service partners.

Leadership Outcomes
  • Maintain a defensible, audit-ready security and privacy program aligned to Exponent's business objectives and client commitments.
  • Reduce material cyber and privacy risk through prioritized treatment plans, clear ownership, measurable controls and timely escalation.
  • Enable consulting, litigation and corporate operations to adopt technology, cloud and AI securely without unnecessary friction.
  • Provide executives with concise, decision-oriented reporting on risk posture, incidents, investment needs and program maturity.
  • Build a resilient operating model with documented authority, repeatable processes, qualified backups and effective external partners.


You will have the following skills and qualifications

  • Progressive leadership experience directing enterprise information security, privacy, cyber risk or related programs in a distributed, regulated or client-trust-dependent environment. This experience must include building, transforming and or directing an information security program.
  • Demonstrated ownership of security strategy, governance, budget, vendors, metrics and multiyear transformation roadmaps.
  • Proven experience managing a compliance program.
  • Practical leadership of ISO/IEC 27001 programs and audits; working knowledge of privacy management and ISO/IEC 27701 strongly preferred.
  • Experience directing incident response, vulnerability management, identity and access governance, third-party risk, security architecture, MDR/MSSP services and audit remediation. This must include experience responding to a business impacting incident.
  • Ability to advise executives, clients, auditors, counsel and technical leaders, including during incidents, regulatory scrutiny and high-impact decisions.
  • Working knowledge of modern Microsoft security and identity capabilities, cloud platforms, endpoint and network security, data protection, Purview, AI security and secure software practices.
  • Bachelor's degree in information technology, cybersecurity, risk management or a related field, or equivalent relevant experience.
  • Relevant certification such as CISSP required or expected; CISM, CRISC, PMP, ISO 27001 Lead Implementer/Lead Auditor, or privacy credentials are valued.
Leadership Competencies

Business and risk judgment

Balances protection, client obligations, cost and speed; makes clear, defensible decisions under uncertainty.

Executive communication

Converts technical risk into concise business choices, ownership, investment and measurable outcomes.

Incident leadership

Provides calm, decisive authority during incidents and coordinates technical, legal, privacy and business response.

Enterprise influence

Builds trusted partnerships across IT, Legal, HR, Finance, Operations, consultants, clients and third parties.

Operational discipline

Establish durable governance, metrics, evidence, service ownership, succession and continuous improvement.

Talent leadership

Sets clear expectations, develops capability, delegates effectively and creates accountability without concentrating knowledge.



Life @ Exponent

To learn more about life at Exponent and our impact, please visit the following links:
https://www.exponent.com/careers/life-exponent
https://www.exponent.com/company/our-impact

We value and encourage diversity, equity and inclusion across all facets of our firm. Having a team built of people with different backgrounds, skills and perspectives allows us to provide better value to our clients and enjoy an enriched work environment.

Our firm is committed to offering a variety of programs and resources to support health and well-being. We believe that providing competitive benefits, as well as compensation and recognition programs, empowers our staff to do work that makes a difference.



Work Environment

At Exponent, we have found that in-person interactions deepen employee engagement and are crucial for development, for realizing the full potential of our talented and diverse teams, and for building a more inclusive workplace where all have a sense of belonging. In our offices, you can expect a supportive culture and a collaborative, dynamic, multi-disciplinary work environment.I-Onsite



Compensation

The pay rate for this position is dependent on experience and capabilities which will be assessed during the interview process.



Benefits you will enjoy

Access benefits information on our Life@Exponent page: https://www.exponent.com/careers/life-exponent

Exponent is a proud equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, veteran status, disability, sexual orientation, gender identity, or any other protected status.

If you need assistance or accommodation due to a disability, you may email us at HR-Accommodations@exponent.com.



Job Locations

US-AZ-Phoenix
Applied = 0

(web-9db6c7984-m8w6w)