← All roles
Director

Director of Information Security

DBM Global Inc. · Manufacturing · 1,001-5,000 employees

Phoenix, AZ · Onsite · full_time

CLI Career Level

VP-equivalent

Moderate confidence

Opportunity Score

80/100

Strong

High confidence

Executive Fit

Sign in

Add your background to score this role against you

Career Level and Opportunity Score describe the role itself. Executive Fit is the only figure that depends on your profile.

First seen Sep 23, 2026 · Last verified 2 hours ago · Sourced from LinkedIn — Director of Security (US)

CLI Take

Broader than the title suggests

This role reads VP-equivalent despite being advertised as “Director of Information Security” — the stated scope is wider than the employer's title implies. CLI's analysis of the posting describes a strategic build or transformation mandate, and it reports to Chief Information Officer and carries SOX accountability. Position requires as many hours needed to fulfill the daily and weekly obligations required... Working long days including evenings and weekends can be required for this position. Total compensation and team size are not disclosed and remain the main open questions before pursuing it.

Why this role scores the way it does

80/100 — strong opportunity quality. CLI reads this as a VP-equivalent mandate. Strongest signal: CLI's analysis of the posting describes a strategic build or transformation mandate. 3 of 10 dimensions are not disclosed, which lowers confidence rather than the score.

Career level read

VP-equivalent — The employer lists this as “Director of Information Security”. CLI reads it as VP-equivalent because the role shows reports to a C-level executive, global responsibility; executive committee exposure, 1,001-5,000 employee organization.

Moderate confidence

What makes it attractive

  • CLI's analysis of the posting describes a strategic build or transformation mandate.
  • The role carries more scope than the employer's title suggests.
  • The role reports to a C-level executive.
  • Employer profile: 1,001-5,000 employee organization, publicly traded, revenue 1b 10b.
  • Signals worth probing: Position requires as many hours needed to fulfill the daily and weekly obligations required... Working long days including evenings and weekends can be required for this position..

What to probe before applying

  • No material concerns identified in the posting.

Scoring components · Strong

Compensation versus comparable rolesNot disclosed · excluded from the score

Compensation is not disclosed and there is no comparable set to place it against.

Reporting level71 · weight 12%

The role reports to a C-level executive.

Functional and geographic scope64 · weight 12%

Scope language covers global responsibility; executive committee exposure.

Quality of the mandate100 · weight 12%

CLI's analysis of the posting describes a strategic build or transformation mandate.

Executive and board exposure65 · weight 10%

The posting references executive or committee-level interaction.

Role authority versus title100 · weight 10%

The role carries more scope than the employer's title suggests.

Company scale and trajectory83 · weight 10%

Employer profile: 1,001-5,000 employee organization, publicly traded, revenue 1b 10b.

Team ownershipNot disclosed · excluded from the score

Team size: not disclosed.

Budget ownershipNot disclosed · excluded from the score

Budget ownership: not disclosed.

Risk signals75 · weight 5%

Signals worth probing: Position requires as many hours needed to fulfill the daily and weekly obligations required... Working long days including evenings and weekends can be required for this position..

Dimensions the employer does not disclose are excluded and the remaining weights are rebalanced, so missing information lowers confidence rather than the score.

Sign in to see how this role scores against your background, and add your career goal to evaluate career value.

Compensation

No compensation disclosed and insufficient comparable data to estimate.

Sample size not yet sufficient for a market comparison

See the full benchmark bands by level and region

The mandate

The Director of Information Security is tasked with leading and advancing DBM Global's cybersecurity program across risk management, security operations, and architecture. The leader is responsible for developing the enterprise security strategy, roadmap, and policies while overseeing incident response and identity security.

Reporting to the CIO, this leader owns the technical and operational cybersecurity program including SecOps, IR, and architecture. The remit excludes independent IT compliance and SOX testing, which are managed by a separate IT Compliance Manager.

Scope

  • Reports to Chief Information Officer

Domains and regulation

  • Enterprise Security
  • Cloud Security
  • Infrastructure Security
  • Cyber Defense
  • Incident Response
  • Identity
  • Application Security
  • DevSecOps
  • SOX

Requirements

Must have

  • Bachelor’s degree in Cybersecurity, Information Security, Computer Science, or related field
  • Certified Information Systems Security Professional (CISSP) certification required within 12 months of hire
  • 8+ years of progressive experience in cybersecurity, information security, security engineering, or security operations
  • 3+ years of cybersecurity leadership experience
  • Strong knowledge of cybersecurity risk management, security architecture, and cloud security
  • Demonstrated ability to communicate cybersecurity risk and business impact to executive stakeholders

Preferred / bonus

  • Nothing listed as optional.

Only must-have items are scored as hard constraints in Executive Fit.

Likely challenges

Signals worth probing

Not stated in the posting: Compensation range not disclosed; Team size not specified; Specific industry not stated (though DBM Global is a steel/construction conglomerate, the JD is industry-agnostic).

About DBM Global Inc.

DBM Global Inc. is a provider of complex structural steel and facility delivery solutions for major commercial, industrial, and infrastructure projects. The company operates through several subsidiaries, including Schuff Steel, to provide integrated design, fabrication, and erection services. It is a majority-owned subsidiary of Enterprise Diversified, Inc. and manages a large workforce across multiple North American locations.

Industry
Manufacturing
Headcount
1,001-5,000 employees
Headquarters
Chandler, Arizona
Founded
1958
Ownership
Public company · OTC:DBMG
Funding
Publicly traded
Revenue
$1B – $10B

Full company profile for DBM Global Inc. →

View original job description
Position Value PropositionAs the Director of Information Security at DBMG, you are responsible for leading and advancing the organization’s cybersecurity program to protect information assets, technology, systems, infrastructure, and business operations. This role provides strategic and operational leadership across cybersecurity risk management, security operations, architecture, vulnerability management, incident response, identity and access security, data protection, third-party cybersecurity risk, and security awareness.Core ResponsibilitiesDevelop and execute the enterprise cybersecurity strategy, roadmap, policies, standards, and security priorities aligned with business objectives and enterprise risk.Identify, assess, prioritize, and communicate cybersecurity risks across infrastructure, applications, cloud environments, identities, data, and third parties.Oversee security operations, including threat monitoring, detection, vulnerability management, incident response, and continuous improvement of security capabilitiesEstablish and maintain enterprise security architecture and ensure secure-by-design principles are incorporated into infrastructure, cloud, applications, DevSecOps, and technology initiativesLead cybersecurity incident response and preparedness, including incident playbooks, tabletop exercises, containment, recovery, and post-incident improvementProvide leadership for identity and access security, privileged access, endpoint protection, network and cloud security, and data protection capabilitiesDevelop and maintain cybersecurity awareness and training programs that strengthen employee security behaviors and organizational readinessEstablish cybersecurity metrics and reporting that provide the CIO and executive leadership with visibility into security posture, material risks, incidents, vulnerabilities, and risk-reduction initiativesPartner with Infrastructure, DevSecOps, applications, and other technology teams to ensure cybersecurity controls are implemented, operated effectively, and remediated when deficiencies are identified.Key Performance IndicatorsSuccess in this role may be measured through:Reduction in material cybersecurity risk exposureCritical and high-risk vulnerability remediation performanceSecurity incident frequency, severity, and response effectivenessSecurity control and tooling coverageIdentity and privileged-access risk reductionCybersecurity awareness and phishing-resilience metricsProgress against the approved cybersecurity roadmapTimely remediation of identified cybersecurity deficienciesRequired QualificationsBachelor’s degree in Cybersecurity, Information Security, Computer Science, Information Technology, or a related field.Certified Information Systems Security Professional (CISSP) certification required within 12 months of hire. 8+ years of progressive experience in cybersecurity, information security, security engineering, or security operations.3+ years of cybersecurity leadership experience.Strong knowledge of cybersecurity risk management, security architecture, threat detection, vulnerability management, incident response, identity and access management, cloud security, endpoint security, and data protection.Demonstrated ability to communicate cybersecurity risk and business impact to executive and non-technical stakeholders.Strong leadership, collaboration, analytical, and decision-making skills.Preferred QualificationsExperience working in complex, distributed, multi-business-unit environments.Experience securing Microsoft Azure, Microsoft 365, hybrid infrastructure, and enterprise applications.Additional relevant cybersecurity certifications such as CISM, CCSP, GIAC, or cloud security certifications.Core CompetenciesCybersecurity Leadership Risk Management Security Architecture Security Operations Incident Response Vulnerability Management Identity & Access Security Executive Communication Business Acumen Cross-Functional Leadership AccountabilityRole BoundaryThe Director of Information Security owns the technical and operational cybersecurity program, including cybersecurity architecture, security operations, incident response, vulnerability remediation, identity security, security tooling, and related technical controlsIndependent IT compliance assurance, SOX and regulatory control testing, audit coordination, compliance evidence management, and compliance framework readiness are owned by the IT Compliance Manager and the appropriate Compliance/Internal Audit organization.Additional Duties & ResponsibilitiesThis job description is not an exclusive or exhaustive list of all responsibilities and functions that an employee in this position may be asked to perform. Duties and responsibilities may be changed, expanded, reduced, or delegated by management to meet the business needs of the company.Work EnvironmentPosition requires as many hours needed to fulfill the daily and weekly obligations required to carry out the functions. Working long days including evenings and weekends can be required for this position. This position is generally indoors in a climate controlled office environment. Reasonable accommodations will be made upon request for those who have disabilities that qualify under the American with Disabilities Act.DBM Global Inc is an Equal Opportunity Employer

Cyber Leadership Index is not the employer and does not represent candidates for these roles. Verify all details with the employer before acting.