Data Security Director
Sign up free to see how well your resume matches this role.
About this role
About Us:
Job Description:
The Data Security Director will:
- Serve as the subject matter expert responsible for building good governance systems and controls to ensure the protection of BW’s unstructured data (including documents, email, chat and Teams content, file shares, endpoint and cloud-stored files, and engineering and design files such as CAD drawings). Note: protection of structured data is the responsibility of BW’s Business Insights team.
- Ensure that Barry-Wehmiller has a well-defined strategy to protect the company’s data assets on an ongoing basis.
- Advise the BW Board of Directors, BW Senior Leadership Team, the IT Leadership Team, and other colleagues on data security matters, inclusive of emerging threats, vulnerabilities, risks, and regulatory requirements, ensuring that timely and appropriate mitigations take place.
- Engage with data owners and data processors to operationalize controls and promote good data protection practice across Barry-Wehmiller.
Duties and Responsibilities:
- Develop, implement, and maintain BW’s Data Security program coordinating across all IT and business functions to ensure BW has a robust approach to securing our data and ensuring business continuity.
- Collaborate with other functional areas, departments, platforms, and divisions of the business to maintain records of all data assets, storage, access, exports, etc., and maintain a data security incident management plan to ensure timely remediation of incidents impacting critical data including impact assessments, breach response, complaints, claims or notifications.
- Define, set, and oversee the implementation of the BW data loss prevention strategy, actively manage Barry-Wehmiller’s policies, implement data privacy and loss controls, and supporting standards to ensure compliance with requirements under data privacy laws in all relevant jurisdictions, working in close coordination with the BW Group Data Protection Officer.
- Support investigations into data breaches and monitor any remedial actions and lessons learned to ensure future breaches are avoided and business risks are mitigated.
- Ensure appropriate governance, business processes and controls are in place to manage data security in alignment with BW’s risk appetite.
- Establish metrics and periodic control testing to evaluate the effectiveness of BW’s data security program, and report results, exceptions, and risk trends to the Chief Information Security Officer and the IT Leadership Team.
- Partner with the BW Group Data Protection Officer on employee training and awareness programs covering the importance of protecting sensitive data and compliance with BW’s data protection policies and procedures, and support the Group Data Protection Officer in responding to external authorities and regulatory bodies on data protection matters.
- Engage with the Business Insights (structured data) team to ensure consistent development and application of policies as well as regulatory compliance.
- Establish and maintain governance for the use of BW data in artificial intelligence and generative AI tools, including Microsoft 365 Copilot and Claude Enterprise— covering content oversharing and permission hygiene, sensitivity labeling, acceptable-use standards, and the identification and control of unsanctioned (“shadow”) AI use.
- Lead the identification, classification, and protection of BW’s intellectual property and trade secrets held as unstructured content — including engineering drawings, CAD and design files, process documentation, and proprietary machine designs — with particular attention to content shared externally with customers, suppliers, and partners.
- Design and operate BW’s insider risk program for unstructured data, including monitoring for anomalous data movement, departing-employee data exfiltration, and misuse of privileged access, working in coordination with the People Team, Legal, and the Group Data Protection Officer.
- Assess the data security posture of acquired companies during due diligence and integration, and bring their unstructured data estates under BW’s classification, retention, and data loss prevention controls.
- Lead, coach, and develop the data security team, setting clear priorities and growing the team’s capability in keeping with BW’s Truly Human Leadership philosophy.
Job Specifications:
Required:
- Minimum of 10 years of progressive experience in data security, information security, or data protection, including at least 3 years leading and developing a team.
- Expert level experience and knowledge of data loss prevention and protection technologies, including experience designing, deploying, and tuning DLP policies in a large enterprise environment.
- Working knowledge of Microsoft Purview data security and governance capabilities (sensitivity labels, data loss prevention, insider risk management, and data lifecycle management), and with Entra ID and conditional access as they apply to protecting content.
- Working knowledge of the practical application of privacy and data protection regulations, including the GDPR (General Data Protection Regulation) and the CCPA (California Consumer Privacy Act), and familiarity with the broader landscape of international and US state privacy laws.
- Experience in developing policy and compliance training.
- Experience with and knowledge of data governance.
- Strong knowledge of information technology and data management systems.
- Well-developed and professional interpersonal skills; ability to interact effectively with people at all organizational levels of the business and external bodies.
- Strong change and project management skills, including the ability to manage time well, prioritize effectively and manage multiple competing deadlines.
- Ability to manage confidential and sensitive information with the appropriate discretion.
- Ability to translate technical data security risk into business terms, and the credibility to advise senior leadership and the Board of Directors.
Preferred:
- One or more information security certifications, such as CISSP, CISM, CCSP, or the Microsoft Information Security Administrator certification (SC-401).
- A data protection or privacy certification, such as CIPP, CIPT, or CIPM.
- Experience in global manufacturing and in cross-border data protection issues.
- Experience within a compliance, audit and/or risk function, with recent experience in privacy compliance and wider broad-spectrum compliance programs.
- Experience protecting data across a decentralized, multi-company environment, including integrating newly acquired businesses.
Education:
Bachelor’s degree in computer science, information systems, cybersecurity, or a related field; an equivalent combination of education and relevant experience will be considered.
Business Systems Knowledge:
- Conceptual knowledge of business systems as ERP, PLM, CRM, CPQ, and Service Desk Management.
- Conceptual knowledge of Security Service Edge systems (SSE)
- Working knowledge of the M365 environment (SharePoint, Teams, OneDrive) and how content is stored, shared, and permissioned within it
- Microsoft Office applications (Word, Excel, PowerPoint, Outlook, Power BI)
Measures of Success in the First 12 Months:
- A validated inventory of BW’s highest-value unstructured data assets — what they are, where they reside, and who has access to them.
- Data loss prevention policies advanced from monitoring to enforcement on the highest-risk data flows, with a measurable reduction in policy violations.
- Governance in place for AI and Copilot access to BW content, with identified oversharing remediated.
- A documented data security incident response playbook, exercised at least once with IT, Legal, and the Group Data Protection Officer.
- An established reporting cadence to the Chief Information Security Officer and the IT Leadership Team on data security risk and control effectiveness.
Work Environment:
This position is based in St. Louis, Missouri in the United States. Work is typically performed in a home office or standard office setting, working at a desk or table on a level surface, with extended computer use and regular video conferencing.
Supervisory/Responsibility:
Direct supervisory responsibility for a small team of data security specialists (currently 1 direct report). Accountable for hiring, coaching, performance development, and leading the team in keeping with BW’s Truly Human Leadership philosophy.
Travel:
Anticipated travel for this position is between 10-15%, including travel to BW divisions and manufacturing sites in the United States and internationally.
Disclaimer:
The above information on this description has been designed to indicate the general nature and level of work performed by employees within this classification. It’s not intended to be construed as an exhaustive list of all responsibilities, duties and skills required of employees assigned to this job. This job description is subject to change at any time.
#LI-AL1
At Barry-Wehmiller we recognize that people come with a wealth of experience and talent beyond just the technical requirements of a job. If your experience is close to what you see listed here, please still consider applying. We know that our differences often can bring about innovation, excellence and meaningful work—therefore, people from all backgrounds are encouraged to apply to our positions. Please let us know if you require reasonable accommodations during the interview process.
Barry-Wehmiller is an equal opportunity employer. M/F/D/V This organization uses E-Verify.
Company:
BW Corporate USCompany
Company facts come from this company's own listings. We only show what the postings themselves carry.