Director of Information Security

Washington, DC
Oct 10, 2019
Jan 14, 2020
Executive, Director
Full Time
Application Instructions

Please list all professional experience and explain any gaps in employment history.

Job Description

The Washington Post is in search of an individual for our Director of Information Security position located at our Washington, D.C. headquarters. The ideal candidate is an InfoSec leader who will be instrumental in building a security compliance framework that scales to The Washington Post offices worldwide. The Director will be involved in projects and issues of high complexity that require an individual who can rapidly move from concept to implementation.

Reporting to the Chief Technology Officer, the Director of Information Security will be responsible for delivering operational excellence by defending The Washington Post against global cybersecurity threats. The Director will be responsible for creating, testing, improving, and implementing cybersecurity policies. The Director of Information Security will also be responsible for training employees across the globe on best practices surrounding cybersecurity. The Director of Information Security, the most senior role within the Information Security department, will be responsible for training employees across the globe on best practices surrounding cybersecurity.

  • End-to-end ownership of information security, organization wide and across all technology platforms including print, web, mobile, video, advertising, financial systems, HR systems, and Arc Publishing (; our rapidly growing SaaS technology platform business.
  • Implement an information security risk management program to include participation in broader risk management activities across The Washington Post
  • Develop and supervise the information security policy compliance team to ensure key risk indicators are within The Washington Post's risk appetite
  • Develop a risk strategy that identifies and classifies risks, defines appropriate tolerances, prioritizes mitigation activities, and measures risk levels
  • Oversee high-risk initiatives and serve as a point of escalation for remediation and mitigation efforts
  • Drive The Washington Post's security compliance strategy by consulting with various leaders
  • Build and maintain current policy compliance tools and processes surrounding information security
  • Work with number of different leaders and departments (Engineering, Newsroom, IT, Legal, Finance, etc.) across The Washington Post's global reach

  • 10+ years of security governance, risk, vulnerability management, cloud security, and compliance management experience
  • 3+ years of management experience leading cybersecurity teams
  • Desire to work with, understand and interact with our World Class Engineer Teams
  • Bachelor's degree in Computer Science, Information Systems, or related field (or equivalent experience)
  • Strong knowledge of current and emerging cybersecurity risks and innovative risk management methods
  • Design and develop an information security road map that aligns and scales with the growth of The Washington Post
  • Lead security testing and assessment processes
  • Manage compliance activities
  • Retain, attract, and develop The Washington Post's Information Security team

Founded in 1877, the 68 Pulitzer Prize-winning Washington Post is one of the world's most storied media and media-technology companies. Our mission is to connect, inform, and enlighten those around the globe, who seek to understand our nation's capital with the highest-caliber, most trustworthy news and information. The Post continues to shine its light into the darkness - to uncover critical truths and spread knowledge to protect the pillars of liberty and democracy worldwide. Combining world-class journalism with cutting-edge engineering, The Post is defining the future of news.

In addition to being one of 2019's Top Employers in Washington, D.C. (Forbes), The Washington Post was named one of the Most Innovative Media Companies (for the third time) and the 8th Most Innovative Company in the world by Fast Company in 2018 - awards reflective of our dedication to transformation, integrity, and quality. Combining our agile, high-performing teams with over 140 years of world class journalism, The Post delivers quality content and innovative experiences all over the word. We offer a wide array of products and services including The Washington Post newspaper, The Washington Post app,, Arc Publishing, WP BrandConnect, Washington Post Live conference and event space, and Post TV; yet our approach is always the same - shape ideas, redefine speed, and take ownership. Every employee, every project, every day.