Director Information Security
Location: United States, Georgia, Atlanta
Address: 1 - Corp Atlanta Ravinia, Three Ravinia Drive, Suite 100, 30346
Job number: 167724
IHG Hotels & Resorts is hiring a Director of Information Security. In this role you will set the standards for enterprise security controls and compliance, security policy management, and AI governance programs. You’ll establish direction for regulatory compliance (PCI DSS, IT SOX, SOC 1, SOC 2, SWIFT), owns the security policy lifecycle, and establishes responsible AI guardrails.
Drives executive accountability for control health with VPs and SVPs, represents the function in strategic governance forums (Financial Controls SteerCo, AI Responsible Use SteerCo, AI Working Group), and runs a blended onshore/offshore team through a manager-led model.
Your Day to Day
- Own enterprise regulatory compliance strategy and delivery across PCI DSS, IT SOX, SOC 1, SOC 2, and SWIFT, including scoping, audit planning, execution, and remediation.
- Maintain a unified control framework mapped across regulations and expand the controls library as scope grows. Own auditor and assessor relationships and hold delivery to agreed milestones and quality standards.
- Drive continuous control monitoring and evidence automation through ServiceNow GRC and control indicators to to reduce recurring findings and audit burden.
- Define control ownership and formalize executive accountability with VPs and SVPs across P&T and corporate functions.
- Mature the Compliance Partner model and control health dashboards, reporting posture and risk themes to executive leadership.
- Equip control owners with training, remediation guidance, and clear expectations for sustained control performance.
- Represent the function in the Financial Controls SteerCo, AI Responsible Use SteerCo, and VP Working Groups
- Set enterprise AI risk tolerance, guardrails, and escalation criteria aligned to NIST AI RMF, ISO/IEC standards, and the EU AI Act.
- Own the AI governance operating model covering intake, risk tiering, review, approval, exceptions, and ongoing monitoring. Steward AI governance forums and prepare SteerCo-level decisions, risk positions, and executive recommendations.
- Embed responsible use guidance and role-based enablement so AI adoption scales safely across the enterprise.
- Own the Enterprise Technology and Security policy lifecycle, including annual refresh, SteerCo review, publication and ongoing communications.
- Keep policies current and operationally feasible through regulatory mapping, gap analysis, and business consultation.
- Own the policy exception process and drive awareness through roadshows and role-based training.
- Align policies, standards, and controls so requirements are measurable, testable, and auditable.
- Lead a blended onshore and offshore team through a manager-led model, delegating delivery accountability to managers.
- Act as an advisor to managers and team members to help meet established schedules and/or resolve technical or operational problems.
- Own workforce planning, sourcing mix, budget input, vendor performance, and talent development across the function.
- Partner across Security, Legal, Privacy, Internal Audit, Finance, and P&T to embed compliance and governance into the business.
What We Need from You
- Bachelor's degree in Information Systems, Business, or related field, or equivalent experience.
- 10+ years in security governance, risk, compliance, audit, or technology risk, including 5+ years leading teams and managing through managers.
- Deep expertise in regulatory compliance programs (PCI DSS, SOX/SOC, SWIFT) and control frameworks (NIST CSF/AI RMF, ISO 27001, COBIT).
- Proven ownership of enterprise policy lifecycle and governance forums with executive audiences.
- Experience establishing AI or emerging-technology governance, including risk tiering, guardrails, and responsible use enablement.
- Demonstrated executive communication: able to distill complex risk into crisp decisions for VPs, SVPs, and SteerCos.
- Experience leading blended onshore/offshore and managed-service delivery models.
Preferred Qualifications
- GRC tooling depth (ServiceNow GRC/IRM, Veza, Axonius).
- Experience in a highly regulated, global, or consumer/hospitality enterprise.
- Certifications such as CISA, CISM, CRISC, CISSP, or AI governance credentials (e.g., AIGP).
- Executive influence without authority; strategic thinking with operational rigor; change leadership; talent development; evidence-minded and audit-ready follow-through.
Travel - limited 10%
Location - Our hybrid work structure is an expectation of three (3) days a week in the ATLANTA office. This expectation may be adjusted with the changing needs of the business.
#LI-ZY1
Vous ne répondez pas tout à fait à toutes les exigences, mais croyez quand même que vous seriez le candidat idéal pour le poste ? Nous ne le saurons jamais à moins que vous n'ayez appuyé sur le bouton « Appliquer ». Commencez votre voyage avec nous dès aujourd'hui.
Informations importantes:
- La fourchette salariale indiquée est la plus basse à la plus élevée que nous croyons, de bonne foi, que nous paierions pour ce poste au moment de cette publication. Nous pourrions finalement payer plus ou moins que la fourchette affichée, et la fourchette pourrait être modifiée à l’avenir. Le niveau de rémunération d'un employé au sein de la grille salariale sera déterminé en fonction de plusieurs facteurs, notamment la formation pertinente, les qualifications, les certifications, l'expérience, les compétences, l'ancienneté, les destinations géographiques, le rendement, les horaires de travail, les exigences de voyage, les indicateurs de vente ou de revenus, et les besoins de l'entreprise ou de l'organisation.
- Aucun montant de rémunération n'est considéré comme un salaire ou une compensation tant qu'il n'est pas gagné, acquis et déterminable. Le montant et la disponibilité de toute prime, commission ou autre forme de compensation attribuable à un employé particulier demeurent à la seule discrétion de la Société, sauf et jusqu’à ce qu’il soit payé, et peuvent être modifiés à la discrétion exclusive de la Société, conformément à la loi.
- L’EEO est la loi – cliquez ici pour plus d’informations sur l’égalité des chances pour les employeurs des minorités/femmes/anciens combattants protégés/personnes handicapées/orientation sexuelle/identité de genre.
- Si vous avez besoin d’un aménagement raisonnable pendant le processus de demande, veuillez cliquer ici.
- IHG n’accepte pas les candidatures, demandes de renseignements ni CV/CV non sollicités provenant d’agences de recrutement ou de placement. Veuillez cliquer ici pour connaître notre politique d’agence.
- Si vous résidez ou postulez à un poste dans l’État de Washington, veuillez cliquer ici pour lire les avantages applicables.
- Pour les postes ou candidats à San Francisco seulement : conformément à l’Ordonnance sur la chance équitable de San Francisco, nous considérerons pour l’emploi des candidats qualifiés ayant un casier judiciaire d’arrestation et de condamnation.