← All roles
Director

Director of Information Security

RPL International · Financial Services · 1-50 employees

Miami, FL · Onsite · full_time

CLI Career Level

Senior Director-equivalent

Moderate confidence

Opportunity Score

57/100

Mixed

High confidence

Executive Fit

Sign in

Add your background to score this role against you

Career Level and Opportunity Score describe the role itself. Executive Fit is the only figure that depends on your profile.

First seen Sep 7, 2026 · Last verified 2 days ago · Sourced from LinkedIn — Director of Security (US)

CLI Take

Broader than the title suggests

This role reads Senior Director-equivalent despite being advertised as “Director of Information Security” — the stated scope is wider than the employer's title implies. CLI's analysis of the posting describes a strategic build or transformation mandate, and it carries PCI DSS and SOX accountability. The reporting line sits below the executive team — the role reports to Executive Leadership. Total compensation and team size are not disclosed and remain the main open questions before pursuing it.

Why this role scores the way it does

57/100 — mixed opportunity quality. CLI reads this as a Senior Director-equivalent mandate. Strongest signal: CLI's analysis of the posting describes a strategic build or transformation mandate. Main drag on the score: The reporting line sits below the executive team — the role reports to Executive Leadership. 3 of 10 dimensions are not disclosed, which lowers confidence rather than the score.

Career level read

Senior Director-equivalent — The employer lists this as “Director of Information Security”. CLI reads it as Senior Director-equivalent because the role shows board or committee interaction; executive committee exposure.

Moderate confidence

What makes it attractive

  • CLI's analysis of the posting describes a strategic build or transformation mandate.
  • Title and described scope are broadly consistent.

What to probe before applying

  • The reporting line sits below the executive team — the role reports to Executive Leadership.
  • Employer profile: 1-50 employee organization, privately held, not applicable, revenue under 10m.

Scoring components · Mixed

Compensation versus comparable rolesNot disclosed · excluded from the score

Compensation is not disclosed and there is no comparable set to place it against.

Reporting level0 · weight 12%

The reporting line sits below the executive team — the role reports to Executive Leadership.

Functional and geographic scope64 · weight 12%

Scope language covers board or committee interaction; executive committee exposure.

Quality of the mandate100 · weight 12%

CLI's analysis of the posting describes a strategic build or transformation mandate.

Executive and board exposure65 · weight 10%

The posting references executive or committee-level interaction.

Role authority versus title70 · weight 10%

Title and described scope are broadly consistent.

Company scale and trajectory25 · weight 10%

Employer profile: 1-50 employee organization, privately held, not applicable, revenue under 10m.

Team ownershipNot disclosed · excluded from the score

Team size: not disclosed.

Budget ownershipNot disclosed · excluded from the score

Budget ownership: not disclosed.

Risk signals100 · weight 5%

No adverse signals identified in the posting.

Dimensions the employer does not disclose are excluded and the remaining weights are rebalanced, so missing information lowers confidence rather than the score.

Sign in to see how this role scores against your background, and add your career goal to evaluate career value.

Compensation

No compensation disclosed and insufficient comparable data to estimate.

Sample size not yet sufficient for a market comparison

See the full benchmark bands by level and region

The mandate

Establish and lead the organization's enterprise cybersecurity program, providing strategic and operational leadership across security operations, GRC, data protection, and DevSecOps. The leader will develop the security roadmap, establish policies, oversee enterprise risk, and ensure protection of systems and sensitive information.

Reporting to executive leadership, this role oversees the entire security remit including GRC, SecOps, DevSecOps, and network security. The Director is responsible for the enterprise security roadmap and serves as a senior escalation point for incidents.

Scope

  • Reports to Executive Leadership

Domains and regulation

  • Enterprise Security
  • GRC
  • Cyber Defense
  • DevSecOps
  • Incident Response
  • Identity
  • Cloud Security
  • Third-Party Risk
  • PCI DSS
  • SOX

Requirements

Must have

  • Bachelor's degree in Cybersecurity, IT, or related discipline (or equivalent experience).
  • At least 10 years of progressive cybersecurity or information security experience.
  • At least 5 years of experience managing and developing technical security teams.
  • Demonstrated leadership across multiple disciplines including SecOps, GRC, Data Security, DevSecOps, and network security.
  • Experience managing security budgets, technology investments, licensing, and vendors.
  • Demonstrated experience directing enterprise incident response through recovery and post-incident review.

Preferred / bonus

  • Nothing listed as optional.

Only must-have items are scored as hard constraints in Executive Fit.

Likely challenges

Not stated in the posting: Compensation range not disclosed.; Specific reporting line title (e.g., CIO vs CEO) not explicitly stated beyond 'executive leadership'.; Team size not specified.; Budget size not specified..

About RPL International

RPL International is a specialized professional recruitment and executive search firm. They provide talent acquisition and management consulting services to mid-market and Fortune 500 companies, primarily within accounting, finance, and human resources. For a security leader, this represents a small professional services firm focused on high-touch executive placement and human capital strategy.

Industry
Financial Services
Headcount
1-50 employees
Headquarters
Miami, Florida Beach
Founded
2010
Ownership
Privately held
Funding
Not applicable
Revenue
Under $10M

Full company profile for RPL International →

View original job description
Director of Information SecurityThe Director of Information Security is responsible for establishing and leading the organization's enterprise cybersecurity program. This position provides strategic and operational leadership across security operations, governance and compliance, data protection, DevSecOps, incident response, and network security.The Director will develop the security roadmap, establish policies and controls, oversee enterprise risk, and ensure appropriate protection of systems, applications, networks, and sensitive information. The role works closely with executive leadership, IT, network engineering, legal, audit, HR, and business stakeholders to ensure cybersecurity initiatives support organizational priorities and regulatory obligations.This position also serves as a senior escalation point for significant security events and is responsible for communicating cybersecurity risks, program performance, and remediation priorities to executive leadership.RequiredBachelor's degree in Cybersecurity, Information Technology, Computer Science, Information Systems, or a related discipline, with at least 10 years of progressive cybersecurity or information security experience. Equivalent experience may be considered in lieu of a degree.At least 5 years of experience managing and developing technical security teams.Demonstrated leadership across multiple cybersecurity disciplines, including Security Operations, GRC, Data Security/Governance, DevSecOps, and network security.Strong understanding of established cybersecurity frameworks and regulatory standards, including NIST, ISO 27001, CIS Controls, PCI-DSS, SOX, and applicable privacy requirements.Strong knowledge of enterprise security architecture and technologies, including firewalls, IDS/IPS, VPN, network segmentation, Zero Trust, SIEM, EDR/XDR, and identity and access management.Experience managing security budgets, technology investments, licensing, contracts, vendors, and third-party service providers.Demonstrated experience directing enterprise incident response from initial investigation through containment, remediation, recovery, and post-incident review.Experience working with internal audit teams, external auditors, regulators, customers, and third-party security assessors.Ability to evaluate complex cybersecurity risks and communicate their business impact to executives and other non-technical stakeholders.Excellent written and verbal communication skills in English.Strong analytical and problem-solving capabilities, including the ability to evaluate information, identify root causes, and make sound decisions.Ability to remain effective in high-pressure situations, including during cybersecurity incidents and other critical events.Strong interpersonal and relationship-building skills with executives, employees, vendors, auditors, and external partners.Ability to manage multiple priorities while balancing long-term strategic initiatives with day-to-day security operations.Willingness to work outside standard business hours when required, including evenings, weekends, holidays, and on-call rotations for critical security matters.PreferredMaster's degree in Cybersecurity, Information Systems, Business Administration, or a related field.Professional certifications such as CISSP, CISM, CISA, CRISC, CCSP, or comparable credentials.Experience working within a highly regulated environment such as financial services, healthcare, energy, or another compliance-driven industry.Familiarity with regulatory requirements including SOX, HIPAA, GLBA, NERC-CIP, or similar standards.Experience presenting cybersecurity strategy, risk, and program performance to executive leadership, audit committees, or boards.Experience developing enterprise security programs during periods of organizational growth, transformation, or technology modernization.

Cyber Leadership Index is not the employer and does not represent candidates for these roles. Verify all details with the employer before acting.