Cybersecurity Director
Posted 23hrs ago
Employment Information
Report this job
Job expired or something wrong with this job?
Job Description
Cybersecurity Director leading Cummins’ global application, cloud, vulnerability, and penetration-testing security strategy. Translating technical findings into enterprise risk decisions and enabling secure Frontier AI adoption.
Responsibilities:
- Own the global strategy, leadership, and maturity of Application Security, Vulnerability Management, Cloud Security, and Penetration Testing
- Identify and evaluate cybersecurity exposures across applications, infrastructure, cloud environments, products, and technology platforms
- Partner with risk owners to mitigate cybersecurity risks
- Translate technical security findings into business risk and influence enterprise risk prioritization
- Strengthen compliance and control frameworks and provide measurable evidence of risk reduction
- Champion Application Security oversight and security-by-design practices across product development, SDLC, DevSecOps, and application processes
- Lead enterprise vulnerability identification, prioritization, remediation, and validation
- Establish risk-based prioritization using exploitability, threat intelligence, and exposure
- Lead global Cloud Security strategy and requirements and manage risks across cloud infrastructure, workloads, identities, configurations, applications, and data
- Develop the penetration testing service offering with Internal Audit and stakeholders
- Validate vulnerabilities and controls through penetration testing and red team exercises
- Identify exploitable attack paths and systemic weaknesses with purple team partners
- Partner with Cyber GRC on risk methodologies, metrics, assessments, policies, controls, compliance, risk acceptance, and material risk escalation
- Support secure adoption of Frontier AI and emerging technologies
- Identify opportunities to use AI for vulnerability prioritization, security testing, risk analysis, automation, and cyber defense
- Lead globally through influence, partnership, and accountability across Cyber Security, GRC, Product, Engineering, Cloud, Infrastructure, IT, and business organizations
- Balance security requirements with business priorities, operational needs, cost, and innovation
- Drive reduced material cybersecurity risk, faster remediation, secure-by-design adoption, effective security validation, executive cyber-risk visibility, and increased automation
Requirements:
- College, university, or equivalent degree in Computer Science, Information Technology, Engineering, or related subject, or relevant equivalent experience required
- GIAC Security Essentials Certification, GIAC Security Leadership Certification, ISACA Certified Information Security Manager, Microsoft Certified Systems Engineer: Security, or CISSP certification preferred
- Understanding of industrial cybersecurity controls and solutions, including asset management, vulnerability management, anomaly detection, identity and access management, network security, endpoint security, application security, IDS/IPS, deep packet inspection, SIEM, data analytics, security and/or risk management, and product development
- Position may require licensing for compliance with export controls or sanctions regulations
- Must be based in one of the allowable U.S. states or Washington, D.C.
Benefits:
- Off-site remote work
- Equal employment opportunities
- No relocation required/relocation not eligible



















