Plan, direct and manage the global information security function for both information technology and communications systems for the company; includes all software, hardware, network infrastructure, and vendors hosting or accessing data on behalf of the company
Accountable for building and maintaining a high performing team
Achieve & maintain high Employee Engagement within the Security & Compliance function
Achieve & maintain high Customer Satisfaction on services provided by the Security & Compliance function
Develop and evolve information security strategy in alignment with company direction and based on current best practices, emerging trends in our threat landscape, and customer and government requirements regarding information security and data privacy, while balancing risk with spend and our ability to operate
Implement Information Security strategy & tactics including Identification, Protection, Detection, Response, Recovery, and Measure
Plan, direct, and manage the IT general controls compliance function to ensure the security, accuracy and reliability of the systems that manage and report the company's data, including financial data
Communicate all applicable (for all countries in which we operate) government information security requirements and associated risks to business decision makers
Assess disaster recovery and business continuity plans with respect to commercially reasonable practices
Work with peers to appropriately coordinate and communicate activities in alignment with overall corporate and IT strategic intent
Requirements
Bachelor's Degree in cybersecurity, computer science, information technology, management information systems or related field
10+ years experience in security operations specifically in managing engineering teams and respective technologies
10+ years experience with cyber maturity framework, specifically NIST CSF 2.0, CIS 18, and ISO 27001:2022
10+ years in cybersecurity and related areas including knowledge and understanding of relevant legal, regulatory and privacy requirements for a global organization
Deep understanding of SOX (Sarbanes-Oxley Act) controls and audit requirements
Experience implementing and maintaining GDPR compliance programs
Familiarity with GRC (Governance, Risk, and Compliance) platforms and frameworks
Knowledge of privacy regulations for companies with a significant presence internationally (China, Brazil, Spain, EU, UK), and global data protection laws
Ability to lead cross-functional teams in privacy impact assessments and data governance
Experience working with legal and compliance teams to manage regulatory risk
Preferred: Master’s degree in Business Administration, Computer Science, or related field
Preferred: CISSP Certification
Preferred: 5+ years of management experience or demonstrated leadership acumen
Preferred: Medical Device industry experience
Relevant certifications in change management (e.g., Prosci, CCMP) and project management (e.g., PMP) are highly desirable
Fluent verbal and written communication in English
This role is not eligible for sponsorship
Benefits
CONMED offers a wide array of benefits to fit your unique needs. Visit our Benefits Page for more information.
Competitive compensation
Excellent healthcare including medical, dental, vision and prescription coverage
Short & long term disability plus life insurance -- cost paid fully by CONMED
Retirement Savings Plan (401K) -- CONMED matches your contributions dollar for dollar, with the potential for up to 7% per pay period
Employee Stock Purchase Plan -- allows stock purchases at discounted price
Tuition assistance for undergraduate and graduate level courses
Employee Referral Program incentives
ATS Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.