資訊安全主任 | 工作細節 | 酒店工作&招待職業
跳到內容

資訊安全主任

地點:美國,喬治亞州,亞特蘭大

地址: 1 - Corp Atlanta Ravinia, Three Ravinia Drive, 套房 100, 30346

Job number: 167724

IHG Hotels & Resorts is hiring a Director of Information Security. In this role you will set the standards for enterprise security controls and compliance, security policy management, and AI governance programs. You’ll establish direction for regulatory compliance (PCI DSS, IT SOX, SOC 1, SOC 2, SWIFT), owns the security policy lifecycle, and establishes responsible AI guardrails. 

Drives executive accountability for control health with VPs and SVPs, represents the function in strategic governance forums (Financial Controls SteerCo, AI Responsible Use SteerCo, AI Working Group), and runs a blended onshore/offshore team through a manager-led model.

 

Your Day to Day 

  • Own enterprise regulatory compliance strategy and delivery across PCI DSS, IT SOX, SOC 1, SOC 2, and SWIFT, including scoping, audit planning, execution, and remediation.
  • Maintain a unified control framework mapped across regulations and expand the controls library as scope grows. Own auditor and assessor relationships and hold delivery to agreed milestones and quality standards.
  • Drive continuous control monitoring and evidence automation through ServiceNow GRC and control indicators to to reduce recurring findings and audit burden.
  • Define control ownership and formalize executive accountability with VPs and SVPs across P&T and corporate functions.
  • Mature the Compliance Partner model and control health dashboards, reporting posture and risk themes to executive leadership.
  • Equip control owners with training, remediation guidance, and clear expectations for sustained control performance.
  • Represent the function in the Financial Controls SteerCo, AI Responsible Use SteerCo, and VP Working Groups
  • Set enterprise AI risk tolerance, guardrails, and escalation criteria aligned to NIST AI RMF, ISO/IEC standards, and the EU AI Act.
  • Own the AI governance operating model covering intake, risk tiering, review, approval, exceptions, and ongoing monitoring. Steward AI governance forums and prepare SteerCo-level decisions, risk positions, and executive recommendations.
  • Embed responsible use guidance and role-based enablement so AI adoption scales safely across the enterprise.
  • Own the Enterprise Technology and Security policy lifecycle, including annual refresh, SteerCo review, publication and ongoing communications.
  • Keep policies current and operationally feasible through regulatory mapping, gap analysis, and business consultation.
  • Own the policy exception process and drive awareness through roadshows and role-based training.
  • Align policies, standards, and controls so requirements are measurable, testable, and auditable.
  • Lead a blended onshore and offshore team through a manager-led model, delegating delivery accountability to managers.
  • Act as an advisor to managers and team members to help meet established schedules and/or resolve technical or operational problems.
  • Own workforce planning, sourcing mix, budget input, vendor performance, and talent development across the function.
  • Partner across Security, Legal, Privacy, Internal Audit, Finance, and P&T to embed compliance and governance into the business. 

 

What We Need from You 

  • Bachelor's degree in Information Systems, Business, or related field, or equivalent experience.
  • 10+ years in security governance, risk, compliance, audit, or technology risk, including 5+ years leading teams and managing through managers.
  • Deep expertise in regulatory compliance programs (PCI DSS, SOX/SOC, SWIFT) and control frameworks (NIST CSF/AI RMF, ISO 27001, COBIT).
  • Proven ownership of enterprise policy lifecycle and governance forums with executive audiences.
  • Experience establishing AI or emerging-technology governance, including risk tiering, guardrails, and responsible use enablement.
  • Demonstrated executive communication: able to distill complex risk into crisp decisions for VPs, SVPs, and SteerCos.
  • Experience leading blended onshore/offshore and managed-service delivery models. 

 

Preferred Qualifications

  • GRC tooling depth (ServiceNow GRC/IRM, Veza, Axonius).
  • Experience in a highly regulated, global, or consumer/hospitality enterprise.
  • Certifications such as CISA, CISM, CRISC, CISSP, or AI governance credentials (e.g., AIGP).
  • Executive influence without authority; strategic thinking with operational rigor; change leadership; talent development; evidence-minded and audit-ready follow-through. 

 

 

Travel - limited 10%

Location - Our hybrid work structure is an expectation of three (3) days a week in the ATLANTA office.  This expectation may be adjusted with the changing needs of the business.

 

#LI-ZY1

不太滿足每一項要求,但仍然相信您非常適合這份工作? 除非您點擊“應用”按鈕,否則我們永遠不會知道。 今天就和我們一起開始您的旅程。

重要資訊

  • 列出的薪酬範圍是從最低到最高的薪酬表,我們誠信我們會在發布時為此職位支付。 我們最終可能會支付比發佈範圍更多或少,並且範圍可能在將來會被修改。 僱員在薪酬範圍內的薪酬位置將取決於多個因素,包括相關的教育、資格、認證、經驗、技能、資深、地理位置、績效、輪班、旅行要求、銷售或收入為基礎的指標,以及業務或組織需求。
  • 在賺取積分、歸屬和可確定之前,任何薪資都不被視為工資或報酬。 可分配給特定員工的任何獎金、佣金或其他形式的報酬的金額和可用性仍由公司全權決定,除非及直至支付為止,且公司可在符合法律的情況下全權決定修改。
  • 平等就業機會即法律 - 請按一下此處以了解有關平等機會雇主少數群體/女性/受保護的退伍軍人/殘疾人/性取向/性別認同的更多資訊。
  • 如果您在申請過程中需要合理的調整,請按此
  • IHG 不接受人員或招聘機構的申請,查詢或未經請求的 CV/簡歷。 請點擊此處了解我們的代理政策。
  • 如果您是華盛頓州居民或正在申請華盛頓州的職缺,請點擊此處閱讀適用的禮遇。
  • 僅針對位於三藩市的職位或應聘者:根據《舊金山公平機會條例》,我們會考慮有僱用資格且有拘捕和定罪紀錄的應聘者。
返回頁首