We are seeking an experienced Cybersecurity Director to be responsible for the global strategy, leadership, and maturity of Application Security, Vulnerability Management, Cloud Security, and Penetration Testing. The role identifies and evaluates cybersecurity exposures across applications, infrastructure, cloud environments, products, and technology platforms and partners with the organizations responsible for mitigating those risks. This role is offsite remote.
The Director works closely with Global Cyber Security Governance, Risk & Compliance (GRC) and other stakeholders to enable the communication and prioritization of technical security findings into business risk, influence enterprise risk prioritization, strengthen compliance and control frameworks, and provide measurable evidence of risk reduction.
The role also maintains a strong understanding of Frontier AI and emerging technologies, helping the organization securely adopt AI capabilities while identifying opportunities to use AI to improve cybersecurity effectiveness, automation, and risk management.
In this role, you will make an impact in the following ways:
Application Security
Champion the global Application Security oversight program and security-by-design practices.
Partner with stakeholder to integrate security into product development, SDLC, DevSecOps, and application processes.
Oversee the analysis of application security finding and vulnerability identification and prioritization.
Partner with Product, Engineering, Platform teams to prioritize and remediate application risk.
Vulnerability Management
Lead enterprise vulnerability identification, prioritization, remediation, and validation.
Establish risk-based prioritization using exploitability, threat intelligence, and exposure.
Provide vulnerability intelligence to GRC to support enterprise cyber risk decisions.
Identify systemic and recurring vulnerabilities requiring broader corrective action.
Cloud Security
Lead the global Cloud Security strategy and security requirements.
Identify and manage risks across cloud infrastructure, workloads, identities, configurations, applications, and data.
Partner with Cloud, Infrastructure, Architecture, Product, and Engineering organizations to reduce cloud risk.
Integrate cloud security risk into enterprise cyber risk management and prioritization processes and platforms.
Penetration Testing & Offensive Security
Develop the penetration testing service offering in cooperation with Internal Audit and other stakeholders.
Validate vulnerabilities and security controls through penetration testing and red team exercises,
Identify exploitable attack paths and systemic security weaknesses by partnering with purple team partners.
Provide evidence-based assessments and validate remediation through oversight of Pen Test reporting.
Cyber Risk & GRC Partnership
Partner with Cyber GRC to translate technical security findings into business risk.
Develop methodologies, metrics, and indicators that improve cyber risk prioritization.
Provide technical input into risk assessments, policies, controls, compliance, and risk acceptance decisions.
Support identification and escalation of material cyber risks.
Ensure remediation accountability remains with the appropriate Product, Technology, or Business owner.
Frontier AI & Emerging Technology
Maintain a working understanding of Frontier AI, AI agents, emerging AI architectures, and associated cybersecurity risks.
Partner with AI, Product, Data, Engineering, and GRC organizations to support secure AI adoption.
Identify opportunities to leverage AI for vulnerability prioritization, security testing, risk analysis, automation, and cyber defense.
Help incorporate emerging AI risks into cybersecurity and enterprise risk frameworks.
Leadership & Influence
The Director will lead globally through influence, partnership, and accountability, working across Cyber Security, GRC, Product, Engineering, Cloud, Infrastructure, IT, and business organizations.
The role must effectively translate technical cybersecurity issues into business risk and actionable decisions, balancing security requirements with business priorities, operational needs, cost, and innovation.
Measures of Success
Success will be measured by:
Reduction in material cybersecurity risk.
Improved visibility and prioritization of application, cloud, and infrastructure vulnerabilities.
Faster remediation of material security exposures.
Increased adoption of secure-by-design practices.
Improved effectiveness of penetration testing and security validation.
Stronger integration between Cyber Security and the enterprise risk and compliance frameworks.
Improved executive visibility into cyber risk.
Increased automation and use of AI to improve cybersecurity outcomes.
Secure and effective adoption of Frontier AI and emerging technologies.
To be successful in this role you will need the following:
Action oriented - Taking on new opportunities and tough challenges with a sense of urgency, high energy, and enthusiasm.
Business insight - Applying knowledge of business and the marketplace to advance the organization’s goals.
Communicates effectively - Developing and delivering multi-mode communications that convey a clear understanding of the unique needs of different audiences.
Customer focus - Building strong customer relationships and delivering customer-centric solutions.
Drives results - Consistently achieving results, even under tough circumstances.
Drives vision and purpose - Painting a compelling picture of the vision and strategy that motivates others to action.
Global perspective - Taking a broad view when approaching issues, using a global lens.
Manages complexity - Making sense of complex, high quantity, and sometimes contradictory information to effectively solve problems.
Tech savvy - Anticipating and adopting innovations in business-building digital and technology applications.
Regulatory Risk Compliance Management - Evaluates the design and effectiveness of controls against established industry frameworks and regulations to assess adherence with legal/regulatory requirements.
Education/Experience
College, university, or equivalent degree in Computer Science, Information Technology, Engineering, or related subject, or relevant equivalent experience required.
Global Information Assurance Certification (GIAC) Security Essentials Certification, GIAC Security Leadership Certification, Information Systems Audit and Control Association (ISACA) Certified Information Security Manager, Microsoft Certified Systems Engineer: Security, or Certified Information Systems Security Professional (CISSP) certification preferred.
Understanding of the capabilities and configuration of industrial cybersecurity controls and solutions across multiple facets; for example: asset management, vulnerability management, anomaly detection, identity and access management, network security, endpoint security, application security, IDS/IPS, deep packet inspection, SIEM, data analytics, security and/or risk management and product development.
This position may require licensing for compliance with export controls or sanctions regulations.
Job Systems/Information Technology
Organization Cummins Inc.
Role Category Off-site Remote
Job Type Exempt - Experienced
Min Salary $180600
Max Salary $265000
ReqID 2438893
Relocation Package No
100% On-Site No
Cummins and E-Verify
At Cummins, we are an equal opportunity and affirmative action employer dedicated to diversity in the workplace. Our policy is to provide equal employment opportunities to all qualified persons without regard to race, gender, color, disability, national origin, age, religion, union affiliation, sexual orientation, veteran status, citizenship, gender identity and/or expression, or other status protected by law. Cummins validates the right to work using E-Verify and will provide the Social Security Administration (SSA) and, if necessary, the Department of Homeland Security (DHS), with information from each new employee’s Form I-9 to confirm work authorization. Visit http://EEOC.gov to know your rights on workplace discrimination.
