情報セキュリティ担当ディレクター | 仕事の詳細 | ホテルの仕事とホスピタリティのキャリア
コンテンツにスキップ

情報セキュリティ担当ディレクター

場所:アメリカ合衆国、ジョージア州、アトランタ

住所: 1 - コープ・アトランタ・ラヴィニア、スリー・ラヴィニア・ドライブ、スイート100、30346

Job number: 167724

IHG Hotels & Resorts is hiring a Director of Information Security. In this role you will set the standards for enterprise security controls and compliance, security policy management, and AI governance programs. You’ll establish direction for regulatory compliance (PCI DSS, IT SOX, SOC 1, SOC 2, SWIFT), owns the security policy lifecycle, and establishes responsible AI guardrails. 

Drives executive accountability for control health with VPs and SVPs, represents the function in strategic governance forums (Financial Controls SteerCo, AI Responsible Use SteerCo, AI Working Group), and runs a blended onshore/offshore team through a manager-led model.

 

Your Day to Day 

  • Own enterprise regulatory compliance strategy and delivery across PCI DSS, IT SOX, SOC 1, SOC 2, and SWIFT, including scoping, audit planning, execution, and remediation.
  • Maintain a unified control framework mapped across regulations and expand the controls library as scope grows. Own auditor and assessor relationships and hold delivery to agreed milestones and quality standards.
  • Drive continuous control monitoring and evidence automation through ServiceNow GRC and control indicators to to reduce recurring findings and audit burden.
  • Define control ownership and formalize executive accountability with VPs and SVPs across P&T and corporate functions.
  • Mature the Compliance Partner model and control health dashboards, reporting posture and risk themes to executive leadership.
  • Equip control owners with training, remediation guidance, and clear expectations for sustained control performance.
  • Represent the function in the Financial Controls SteerCo, AI Responsible Use SteerCo, and VP Working Groups
  • Set enterprise AI risk tolerance, guardrails, and escalation criteria aligned to NIST AI RMF, ISO/IEC standards, and the EU AI Act.
  • Own the AI governance operating model covering intake, risk tiering, review, approval, exceptions, and ongoing monitoring. Steward AI governance forums and prepare SteerCo-level decisions, risk positions, and executive recommendations.
  • Embed responsible use guidance and role-based enablement so AI adoption scales safely across the enterprise.
  • Own the Enterprise Technology and Security policy lifecycle, including annual refresh, SteerCo review, publication and ongoing communications.
  • Keep policies current and operationally feasible through regulatory mapping, gap analysis, and business consultation.
  • Own the policy exception process and drive awareness through roadshows and role-based training.
  • Align policies, standards, and controls so requirements are measurable, testable, and auditable.
  • Lead a blended onshore and offshore team through a manager-led model, delegating delivery accountability to managers.
  • Act as an advisor to managers and team members to help meet established schedules and/or resolve technical or operational problems.
  • Own workforce planning, sourcing mix, budget input, vendor performance, and talent development across the function.
  • Partner across Security, Legal, Privacy, Internal Audit, Finance, and P&T to embed compliance and governance into the business. 

 

What We Need from You 

  • Bachelor's degree in Information Systems, Business, or related field, or equivalent experience.
  • 10+ years in security governance, risk, compliance, audit, or technology risk, including 5+ years leading teams and managing through managers.
  • Deep expertise in regulatory compliance programs (PCI DSS, SOX/SOC, SWIFT) and control frameworks (NIST CSF/AI RMF, ISO 27001, COBIT).
  • Proven ownership of enterprise policy lifecycle and governance forums with executive audiences.
  • Experience establishing AI or emerging-technology governance, including risk tiering, guardrails, and responsible use enablement.
  • Demonstrated executive communication: able to distill complex risk into crisp decisions for VPs, SVPs, and SteerCos.
  • Experience leading blended onshore/offshore and managed-service delivery models. 

 

Preferred Qualifications

  • GRC tooling depth (ServiceNow GRC/IRM, Veza, Axonius).
  • Experience in a highly regulated, global, or consumer/hospitality enterprise.
  • Certifications such as CISA, CISM, CRISC, CISSP, or AI governance credentials (e.g., AIGP).
  • Executive influence without authority; strategic thinking with operational rigor; change leadership; talent development; evidence-minded and audit-ready follow-through. 

 

 

Travel - limited 10%

Location - Our hybrid work structure is an expectation of three (3) days a week in the ATLANTA office.  This expectation may be adjusted with the changing needs of the business.

 

#LI-ZY1

すべての要件を満たしているわけではありませんが、それでもあなたはその仕事に適していると思いますか? 「適用」ボタンを押さない限り、わかりません。 今日から私たちと一緒に旅を始めましょう。

重要な情報:

  • 記載されている給与の範囲は、この投稿の時点でこの役割に対して支払うと誠意を持って信じている最低から最高までの給与スケールです。 当社は、最終的に掲載された範囲より多かれ少なかれ支払う場合があり、また、範囲は将来変更される可能性があります。 給与範囲内の従業員の給与ポジションは、関連する教育、資格、認定、経験、スキル、年功序列、地理的な場所、パフォーマンス、シフト、出張要件、売上または収益ベースの指標、ビジネスまたは組織のニーズなど、いくつかの要因に基づいています。
  • ポイントを獲得し、確定し、確定するまでは、給与の金額は賃金または報酬とみなされません。 特定の従業員に割り当てられるボーナス、コミッション、またはその他の形態の報酬の額と支給の有無は、支払われるまで当社の独自の裁量に委ねられており、法律に従って当社の独自の裁量で変更される場合があります。
  • EEOとは法律 - 詳細を見るには、ここをクリックしてください。私たちのブランド 雇用機会均等 雇用者マイノリティ/女性/保護区退役軍人/障害者/性的オリエンテーション/性別識別
  • 申請手続き中に合理的な配慮が必要な場合は、 ここをクリックしてください。
  • IHGは、人材派遣会社や人材紹介会社からの応募、問い合わせ、または未承諾の履歴書/履歴書を受け付けていません。 代理店のポリシーについては 、ここをクリックしてください
  • ワシントン州の居住者またはワシントン州の求人に応募している場合は、 ここをクリックして 該当する特典についてお読みください。
  • サンフランシスコのみの職種または応募者に関して:サンフランシスコ・フェア・チャンス禁止法に則り、解雇または有給休暇
最上部に戻る