← All roles
VP

Vice President, IT Cyber Security

Academy Sports + Outdoors · Retail · 10,000+ employees

Katy, TX · Onsite · full_time

Listed by the employer as “VP IT Cyber Security”. Title normalized for comparability.

CLI Career Level

SVP-equivalent

Moderate confidence

Opportunity Score

89/100

Strong

High confidence

Executive Fit

Sign in

Add your background to score this role against you

Career Level and Opportunity Score describe the role itself. Executive Fit is the only figure that depends on your profile.

First seen Sep 24, 2026 · Last verified yesterday · Sourced from LinkedIn — VP / Head of Security (US)

CLI Take

Broader than the title suggests

This role reads SVP-equivalent despite being advertised as “VP IT Cyber Security” — the stated scope is wider than the employer's title implies. CLI's analysis of the posting describes a strategic build or transformation mandate, and it reports to CIO or SVP level (implied) and carries board-level exposure. Total compensation and team size are not disclosed and remain the main open questions before pursuing it.

Why this role scores the way it does

89/100 — strong opportunity quality. CLI reads this as a SVP-equivalent mandate. Strongest signal: CLI's analysis of the posting describes a strategic build or transformation mandate. 3 of 10 dimensions are not disclosed, which lowers confidence rather than the score.

Career level read

SVP-equivalent — The employer lists this as “VP IT Cyber Security”. CLI reads it as SVP-equivalent because the role shows reports to a C-level executive, board or committee interaction; executive committee exposure, board-level exposure expected.

Moderate confidence

What makes it attractive

  • CLI's analysis of the posting describes a strategic build or transformation mandate.
  • Board-level exposure is expected in the role.
  • The role carries more scope than the employer's title suggests.
  • Employer profile: 10,000+ employee organization, publicly traded, revenue 1b 10b.
  • The role reports to a C-level executive.

What to probe before applying

  • No material concerns identified in the posting.

Scoring components · Strong

Compensation versus comparable rolesNot disclosed · excluded from the score

Compensation is not disclosed and there is no comparable set to place it against.

Reporting level71 · weight 12%

The role reports to a C-level executive.

Functional and geographic scope64 · weight 12%

Scope language covers board or committee interaction; executive committee exposure.

Quality of the mandate100 · weight 12%

CLI's analysis of the posting describes a strategic build or transformation mandate.

Executive and board exposure100 · weight 10%

Board-level exposure is expected in the role.

Role authority versus title100 · weight 10%

The role carries more scope than the employer's title suggests.

Company scale and trajectory100 · weight 10%

Employer profile: 10,000+ employee organization, publicly traded, revenue 1b 10b.

Team ownershipNot disclosed · excluded from the score

Team size: not disclosed.

Budget ownershipNot disclosed · excluded from the score

Budget ownership: not disclosed.

Risk signals100 · weight 5%

No adverse signals identified in the posting.

Dimensions the employer does not disclose are excluded and the remaining weights are rebalanced, so missing information lowers confidence rather than the score.

Sign in to see how this role scores against your background, and add your career goal to evaluate career value.

Compensation

No compensation disclosed and insufficient comparable data to estimate.

Sample size not yet sufficient for a market comparison

See the full benchmark bands by level and region

The mandate

The VP IT Cyber Security is responsible for protecting systems, data, and digital capabilities across a large retail enterprise. The leader will develop multi-year security strategies, oversee a broad range of cyber defense functions, and serve as a trusted advisor to the Board and Audit Committee on risk posture and investment decisions.

This role functions as a senior IT leader and peer to other IT VPs, reporting to an executive IT leader and overseeing the organization through a Director of IT Security and Compliance. The remit covers the entire enterprise including stores, distribution centers, and digital channels across security operations, GRC, and resilience.

Scope

  • Reports to CIO or SVP level (implied)
  • Board-level exposure expected

Domains and regulation

  • Enterprise Security
  • Cyber Defense
  • Identity
  • GRC
  • Incident Response
  • Cloud Security
  • Third-Party Risk
  • Resilience
  • Threat Intelligence

Requirements

Must have

  • Bachelor's degree in Information Security, Computer Science, IT, or related field
  • 15+ years of progressive cybersecurity leadership
  • 7+ years leading enterprise security organizations
  • Prior service as a VP Cybersecurity, CISO, or equivalent executive role
  • Background supporting a large retailer, consumer-facing company, or similarly complex enterprise

Preferred / bonus

  • Preferred: Retail or large consumer-focused business background strongly preferred

Only must-have items are scored as hard constraints in Executive Fit.

Likely challenges

Not stated in the posting: Compensation range not disclosed; Specific reporting line title (e.g., CIO or CTO) not explicitly named beyond peer status to other IT VPs; Direct budget figures not provided.

About Academy Sports + Outdoors

Academy Sports + Outdoors is a large-scale sporting goods and outdoor recreation retailer operating over 280 stores across the United States. The company provides a wide range of athletic equipment, apparel, and hunting/fishing gear to a broad consumer base. For a security leader, the environment involves protecting a large retail footprint, significant e-commerce operations, and high volumes of consumer financial data.

Industry
Retail
Headcount
10,000+ employees
Headquarters
Katy, Texas
Founded
1938
Ownership
Public company · NASDAQ:ASO
Funding
Publicly traded
Revenue
$1B – $10B

Full company profile for Academy Sports + Outdoors →

View original job description
Who We AreAt Academy Sports + Outdoors our vision is to be the best sports + outdoors retailer in the country — but what truly sets us apart is our people. We’re a passionate, purpose-driven team that’s as committed to each other as we are to our customers.We’ve spent over 80 years building a culture that puts people first. We believe in creating opportunities for growth, fostering meaningful connections, and supporting every Team Member’s journey. What fuels us? Our belief in the power of fun.Here, you won’t just help customers gear up for their next adventure — you’ll launch one of your own. Whether you're starting out or leveling up, Academy is a place where fun can’t lose!What You Will Work OnIn this role, you protect the systems, data, and digital capabilities that keep Academy Sports + Outdoors operating and growing. Your leadership helps ensure the technology supporting stores, distribution centers, corporate teams, and digital channels is secure, reliable, and resilient. By connecting cybersecurity decisions to business strategy and enterprise risk, you help the company pursue innovation while maintaining strong protection and operational continuity.Working across the enterprise, you develop and execute multi-year cybersecurity and information security strategies, establish practical policies and governance, and prioritize investments based on business impact and risk. You lead cyber risk management, regulatory readiness, security compliance, identity security, threat detection, vulnerability management, threat intelligence, cyber defense, and Security Operations Center capabilities. You also maintain and test incident response, ransomware response, crisis management, disaster recovery, and business continuity programs, lead executive response during significant incidents, manage security budgets and operating plans, evaluate security technologies, and build a leadership team focused on execution and continuous improvement.Who You Will Work WithAs a senior IT leader and peer to other IT Vice Presidents, you partner closely with Technology and business leaders to embed security into how work gets done without slowing the business down. You lead the cybersecurity organization through the Director, IT Security and Compliance, setting direction, priorities, expectations, and accountability while developing leadership talent and organizational readiness.You collaborate with Internal Audit, Legal, Compliance, Privacy, Enterprise Risk Management, Digital, Infrastructure and Operations, Enterprise Architecture, Applications, and EPMO leaders. You also serve as a trusted advisor to executive leadership, the Audit Committee, and the Board, presenting cyber risk posture, metrics, trends, regulatory matters, resilience priorities, emerging threats, and investment decisions in clear business terms.What You BringBring your energy, your ideas, and your love for sports and the outdoors.Bachelor's degree in Information Security, Computer Science, Information Technology, or a related field requiredAdvanced degree preferred15+ years of progressive cybersecurity leadership7+ years leading enterprise security organizationsPrior service as a VP Cybersecurity, CISO, or in an equivalent executive roleBackground supporting a large retailer, consumer-facing company, or similarly complex enterpriseProven ability to partner with executive leaders and cross-functional teamsRetail or large consumer-focused business background strongly preferredProfessional certifications such as CISSP, CISM, or CISA strongly preferredStrong understanding of cybersecurity, IT controls, and governanceExecutive presence with the ability to influence senior leadersAbility to connect security decisions to business outcomesStrategic and practical decision-making that balances protection and performanceStrong communication, leadership, and organizational skillsA team-first attitude; while your core duties are your priority, you're happy to step in wherever you're neededWork Style & Physical RequirementsAbility to work flexible hours as needed to support critical business or security eventsRegular in-office attendance is requiredAcceptable level of hearing and vision to perform job dutiesAbility to adhere to company policies and professional standardsKey SkillsSecurity Policy Development, Security Operations Management, Business Continuity Crisis Management, Identity Systems, Budgeting and Forecasting, Executive Level Presentations, Strategy and ExecutionEqual Employment OpportunityAcademy is an Equal Opportunity Employer and does not discriminate with regard to employment opportunities or practices on the basis of race, religion, national origin, sex, age, disability, gender identity, sexual orientation, or any other category protected by law.

Cyber Leadership Index is not the employer and does not represent candidates for these roles. Verify all details with the employer before acting.