Job Summary
The SVP, Global Chief Information Security Officer (CISO) & IT Governance is responsible for leading the organization’s global cybersecurity strategy, governance model, risk management program, and cyber resilience capabilities. This executive provides strategic oversight of security operations, architecture, governance, compliance, regulatory readiness, audit coordination, incident response, and recovery. The role ensures cybersecurity is embedded into enterprise strategy, technology transformation, digital innovation, third-party relationships, and day-to-day operations, while serving as a trusted advisor to senior leadership, Board-level stakeholders, Legal, Compliance, Privacy, Internal Audit, regulators, auditors, customers, and external partners.
Job Description
Key Responsibilities
- Set and execute the enterprise cybersecurity strategy and multi-year roadmap aligned with business priorities, risk appetite, regulatory expectations, technology transformation, and enterprise growth.
- Analyze emerging cybersecurity and governance threats (including AI) and create remediation recommendations.
- Establish and mature the cyber governance model, including policies, standards, decision rights, executive reporting, escalation protocols, and accountability mechanisms.
- Lead global security operations, including threat monitoring, intelligence, incident detection, vulnerability management, identity and access management, endpoint security, cloud security, encryption, data protection, analytics, response, and recovery.
- Oversee security architecture and control design to embed security into technology platforms, cloud environments, data ecosystems, business applications, digital products, privileged access management, and Zero Trust initiatives.
- Lead Governance, Risk & Compliance (GRC) programs, including risk identification, assessment, prioritization, mitigation, acceptance, monitoring, reporting, policy governance, and compliance oversight.
- Integrate cybersecurity risk management into enterprise risk management, business planning, technology governance, third-party oversight, customer assurance, and major transformation initiatives.
- Oversee readiness for applicable laws, regulations, contractual obligations, supervisory expectations, industry standards, and frameworks such as NIST, ISO 27001, CIS Controls, GDPR, HIPAA, PCI DSS, HITRUST, SOX / ITGC, or other relevant requirements.
- Serve as the primary technology liaison to Legal, Compliance, Privacy, and Internal Audit on cybersecurity, regulatory, privacy, audit, contractual, and customer assurance matters.
- Lead cyber resilience planning, including incident response strategy, crisis escalation, executive communications, tabletop exercises, ransomware preparedness, recovery coordination, recovery validation, and lessons-learned governance.
- Advise executive leadership and Board-level stakeholders on cyber risk exposure, emerging threats, program maturity, investment priorities, strategic trade-offs, incident readiness, and regulatory disclosure considerations.
- Build, lead, and develop a high-performing global cybersecurity and IT governance organization with clear accountability, succession planning, talent development, operating rhythms, and measurable maturity improvements.
- Champion an enterprise culture in which cybersecurity is understood as a shared leadership responsibility and embedded into business decision-making.
Scope of Accountability
- Global Cybersecurity Program
- Security Operations, Threat Intelligence & Incident Response
- Security Architecture & Engineering
- Identity & Access Management Governance
- Privileged Access Management Governance
- Governance, Risk & Compliance (GRC)
- HITRUST Certification Program
- PCI Compliance Program
- SOX / IT General Controls (ITGC)
- Technology Change Management Governance
- Cyber Resilience & Recovery Readiness
- Third-Party Security Assurance
- Legal, Compliance & Privacy Technology Coordination
- Executive, Audit Committee, and Board Cybersecurity Reporting
- Cybersecurity Strategy, Governance, Maturity Roadmap, Investment Prioritization & Enterprise Risk Reporting
- AI Security Risk Analysis / Threat Mitigation
- AI Risk Governance
Leadership Expectations
- Operate as a strategic business executive balancing cybersecurity risk, compliance, privacy, technology governance, resilience, and operational priorities.
- Translate complex cyber, technology, and operational risks into business impact, financial exposure, regulatory implications, and strategic choices.
- Lead through ambiguity, manage high-pressure incidents, and communicate clearly with senior stakeholders during crisis situations.
- Influence without direct authority, drive cross-functional alignment, and enable pragmatic, risk-informed decisions.
- Promote a culture of accountability, resilience, cybersecurity awareness, and continuous improvement.
- Enable business growth through security leadership that supports innovation, operational resilience, and regulatory readiness.
- Maintain a mature global security and governance program that supports evolving business, technology, regulatory, customer, and audit requirements.
Our benefit package includes health insurance, life and disability, 401(k) contributions, paid time off, etc., for employees working 30 or more hours per week on average. For a more comprehensive list of our benefits please click here. For roles where employees work less than 30 hours per week, benefits include 401(k) contributions as well as access to the Employee Assistance Program, Employee Resource Groups and the Employee Service Corp.
We’re dedicated to creating a Medline where everyone feels they belong and can grow their career. We strive to do this by seeking diversity in all forms, acting inclusively, and ensuring that people have tools and resources to perform at their best. Explore our Belonging page here.
Medline Industries, LP is an equal opportunity employer. Medline evaluates qualified individuals without regard to race, color, religion, gender, gender identity or expression, sexual orientation, national origin, age, disability, neurodivergence, protected veteran status, marital or family status, caregiver responsibilities, genetic information, or any other characteristic protected by applicable federal, state, or local laws.