Vice President IT Security and CISO
| Requisition ID |
2025-72320
|
Category |
Information Technology
|
Job Location
|
US-TX-Irving
|
Property
|
Highgate Hotels Corporate Office TX
|
Compensation Type
Highgate Hotels
Highgate is a leading real estate investment and hospitality management company with over $15 billion of assets under management and a global portfolio of more than 400 hotels spanning North America, Europe, the Caribbean, and Latin America. With a 30-year track record as an innovator in the hospitality industry, this forward-thinking company provides expert guidance through all stages of the property cycle, from planning and development through recapitalization or disposition. Highgate continues to demonstrate success in developing a diverse portfolio of bespoke lifestyle hotel brands, legacy brands, and independent hotels and resorts, featuring contemporary programming and digital acumen. The company utilizes industry-leading revenue management tools that efficiently identify and predict evolving market dynamics to drive outperformance and maximize asset value. With an executive team of seasoned hospitality leaders and corporate offices worldwide, Highgate is a trusted partner for top ownership groups and major hotel brands. www.highgate.com
Location
Highgate Corporate Offices Irving, TX
Overview
The Vice President IT Security and CISO will oversee all security responsibilities for all Highgate global operations and subsidiaries. The position will require a technical understanding and a comprehension of modern security practices that involve both threat intelligence as well as credit card payment industry standards (PCI). Activities would include executive level security briefings, control of security training programs, governance of our PCI control program and developing and implementing best practices across all companies.
Responsibilities
Strategic Leadership
- Develop and execute a comprehensive cybersecurity strategy aligned with business goals.
- Lead enterprise-wide risk assessments and mitigation planning.
- Serve as the primary liaison for executive leadership on all matters related to IT security.
- Governance & Compliance
- Ensure compliance with regulatory requirements including PCI, GDPR, and other applicable frameworks.
- Must have PCI control and framework experience
- Oversee internal audits and external assessments related to information security.
- Security Operations
- Manage the Security Operations Center (SOC) and incident response protocols with our MSSP
- Monitor and respond to security threats, vulnerabilities, and breaches.
- Lead forensic investigations and root cause analysis.
- Provide KPIs on performance of MSSP and internal controls
- Technology Oversight
- Evaluate and implement security technologies including Microsoft Defender stack, Azure security tools, and M365 compliance features.
- Collaborate with infrastructure and application teams to embed security into system design and deployment.
- Team Development
- Build and mentor a high-performing security team.
- Set and measure performance objectives and provide regular feedback.
- Foster a culture of continuous improvement and security awareness across the organization.
Qualifications
- BS in Computer Science, Information Technology, Engineering, or related field.
- 10+ years of security experience with 4+ years of senior leadership experience at the executive level.
- Previous experience with a multi-unit franchise model in either food service, hospitality, or retail strongly preferred.
- Demonstrated ability in a combination of risk management, information security, and engineering roles.
- Ability to identify, attract, hire, develop, and retain the best security professionals needed to staff a world class organization and ensure they have the vision, plan, support, and culture in place to deliver impact.
- Domain expert on the threat landscape and innovative security strategies and products.
- "Hands-on" operating style and approach but a view towards the future and willingness to invest in people development and in developing an organization that will support a large company.
- Proven experience as a business-focused, change-driven, credible leader in a fast-growing business.
- Expertise in understanding sophisticated technology & applying it in a practical way to build solutions.
- Must have experience and knowledge of working with current PCI standards.
- Knowledge of IT control frameworks with experience in implementation of the following examples (ISO, NIST, PCI, ITIL).
- QSA experience required
- Current CISSP required
- International Experience preferred
|