Posted on: February 18, 2019 | Job#: 269385

Director of Information Security - Data and Infrastructure Protection

Full-time | One Harrison Street, San Francisco, CA, US 94105


We’ll send you to our application portal to get started

About Gap Inc.

Our past is full of iconic moments — but our future is going to spark many more. Our brands — Gap, Banana Republic, Old Navy, Athleta, INTERMIX and Hill City — have dressed people from all walks of life and all kinds of families, all over the world, for every occasion for more than 50 years.

But we’re more than the clothes that we make. We know that business can and should be a force for good, and it’s why we work hard to make product that makes people feel good, inside and out. It’s why we’re committed to giving back to the communities where we live and work. If you're one of the super-talented who thrive on change, aren't afraid to take risks and love to make a difference, come grow with us. 

About the role

As a part of our technology organization, GapTech, you will have the opportunity to support the teams that are building the next generation solutions that will transform the way our customers interact with our family of iconic brands. Our team is on the path towards a DevOps model, allowing our product teams to have full ownership of design, build and operate with immense scale. You will have the opportunity to build a career that allows you to make an impact all while learning new technical and leadership skills. We are inspired by new challenges and push ourselves to create what’s next in this dynamic industry. Come join this diverse team and grow with us. Our past is full of iconic moments — but our future is going to spark many more. We're looking for the people who'll help make our next decade just as revolutionary as our first five. If you're one of the super-talented who thrive on change, aren't afraid to take risks and love to make a difference, you're the right fit. Come grow with us.
GapTech Information Security (InfoSec) is the global cybersecurity division of Gap Inc. inclusive of, and across, all our brands. As the Director of Data and Infrastructure Protection, you will be responsible for building and leading a world-class technical team with deep security experience. You will help internal and external business partners define technical and business requirements for data protection solutions as well as develop business processes and policies related to controlling access to data. The mission of your team is to protect the sensitive data that powers our systems and applications.
We are looking for a leader with deep experience in data and infrastructure security, e.g. database and operating system security, database activity monitoring, vulnerability scanning, patch management, endpoint protection, data loss prevention, and tokenization and encryption technology.
In this role, you and your team of security engineers will develop, deploy, operate and enhance data security tools, solutions, capabilities and services that ensure the protection of Gap Inc. information assets while ensuring compliance with legal and regulatory requirements such as PCI DSS, GDPR and internal security policies and standards.

What you'll do

  • Develops, maintains, and communicates the data protection vision and strategy in partnership with InfoSec and DevOps leaders
  • Provides security thought leadership using business communications, active collaboration, and leading across functions to deliver data protection goals
  • Secures enterprise information assets by identifying data security requirements and developing, deploying, operating and enhancing data protection tools, technologies and capabilities to meet requirements
  • Develops and enhances data and infrastructure security policies, standards, processes and procedures
  • Directs team work plans and manages their personal and technical development
  • Develops partnerships with product and services vendors and outside entities as appropriate
  • Takes ownership of key data security initiatives, coordinating strategies with other InfoSec teams and GapTech business leaders to execute
  • Conducts Monthly Business Reviews of team performance; presents business updates, recommendations, strategic opportunities and assessments to senior leadership
  • Hires and develops outstanding information security talent
  • Directs operational strategies by analyzing trends; developing and measuring key performance indicators; implementing production, productivity, quality, and customer-service strategies
  • Validates data protection tools by monitoring performance; developing and implementing tests and audits; monitoring and ensuring compliance to standards, policies, and procedures
  • Understands emerging data security best practices and standards; participates in educational opportunities; maintains a professional network of peers; participates in professional organizations
  • Assists in response to internal and external compliance audits, data loss prevention or insider threat alerts, and corporate investigations
  • Monitors current and proposed data privacy and protection regulations, industry standards, and ethical requirements

Who you are

  • Bachelor’s degree in computer science, Information Technology or a related technical discipline
  • Possesses strong technical expertise in information security, data protection and data governance
  • 10+ years of progressively increasingly responsibility and experience working in Information Security, 5 years minimum experience managing and developing technical teams
  • Experience in data security, data governance, security design and implementation, technical project management, technical standards development, process management, process improvement, people management, budget management
  • Experience managing within Agile/Scrum environment
  • Experience working with information security laws, regulations and standards, accepted information security principles, and accepted industry best practices for protection of information assets
  • Experience working in a risk-based environment including risk mitigation and risk remediation
  • Operational flexibility in modifying business and operating practices to adapt to a changing environment
  • Demonstrated ability to innovate and operate outside the comfort zone of established methods and procedures
  • Leadership characteristics as shown by a history of inspiring and motivating people to a common purpose
  • Demonstrated ability to gain credibility at all levels both inside and outside the organization and develop lasting, productive and collaborative relationships
  • Excellent communication and influencing skills including the ability to simplify key messages, present compelling stories and promote technical and personal credibility with internal and external executives, and both technical and non-technical audiences
  • Proven success working across organizational and geographic boundaries
  • Contract and vendor negotiation experience
  • Experience with forecasting and financial management
  • Preferred Certifications - CISSP, CISA, CISM, CRISC, CGEIT, ISO 27001

Benefits at Gap Inc.

  • Merchandise discount for our brands: 50% off regular-priced merchandise at Gap, Banana Republic and Old Navy, 30% off at Outlet and 25% off at Athleta for all employees.
  • One of the most competitive Paid Time Off plans in the industry.*
  • Employees can take up to five “on the clock” hours each month to volunteer at a charity of their choice.*
  • Extensive 401(k) plan with company matching for contributions up to four percent of an employee’s base pay.*
  • Employee stock purchase plan.*
  • Medical, dental, vision and life insurance.*
  • See more of the benefits we offer.

*For eligible employees

Gap Inc. is an equal-opportunity employer and is committed to providing a workplace free from harassment and discrimination. We are committed to recruiting, hiring, training and promoting qualified people of all backgrounds, and make all employment decisions without regard to any protected status. In 2016, Gap Inc. was named one of the Best Places to Work by the Human Rights Campaign for the thirteeth consecutive year and was the sole winner of the Catalyst award for equality in the workplace in 2016.


We’ll send you to our application portal to get started

Browse all jobs

Recently Viewed