POSITION SUMMARY
The Director of Cybersecurity leads the cybersecurity program — setting strategy, owning the organization’s risk posture, and delivering executive- and board-level cyber-risk reporting. The role builds and leads the internal security team, manages security vendors and their SLAs, and directs incident response and cyber resilience across a global footprint. The Director reports to the VP, IT Infrastructure & Cybersecurity, with an independent line for cyber-risk reporting.
KEY RESPONSIBILITIES
- Set and own the cybersecurity strategy, program roadmap, and risk posture across a global footprint, anchored to NIST CSF 2.0.
- Deliver executive- and board-level cyber-risk reporting.
- Manage security vendors and contracts; define and enforce SLAs and hold partners accountable to contracted obligations.
- Build and lead the internal security team and bring core security functions in-house from managed providers.
- Direct incident response and cyber resilience, including business continuity and disaster recovery.
- Establish cybersecurity governance, policy, and security-awareness programs.
- Own the cybersecurity budget and headcount plan.
FUNCTIONS OWNED
Security Leadership & Strategy · Governance, Policy & Awareness · Incident Response & Cyber Resilience (supports GRC, Risk & Compliance and AI Governance & Emerging Tech)
REQUIRED QUALIFICATIONS
- 12+ years in cybersecurity, including 5+ years leading security teams at manager/director level, ideally in a global, high-profile, or media/entertainment enterprise.
- Demonstrated ownership of an enterprise security program built on NIST CSF 2.0 (or ISO 27001) — governance, policy, control framework, and a multi-year maturity roadmap.
- Track record building and leading an internal security function — hiring, developing, and retaining architects, engineers, and analysts — including insourcing functions from a managed provider (MSSP).
- Executive- and board-level cyber-risk reporting; experience presenting to boards, audit/risk committees, and ownership or private-equity stakeholders, translating technical risk into business and financial terms.
- Enterprise risk management and multi-jurisdiction regulatory literacy across a global footprint — SOX ITGC and global privacy regimes (GDPR, CCPA/CPRA, PIPL).
- Proven vendor and contract management — negotiating and enforcing SLAs with MSSPs and holding them accountable to contracted obligations.
- Incident-response leadership — has directed the organization’s response to a material security incident and owns cyber-resilience / BCP-DR direction.
- Security-budget ownership — has built and defended a security operating budget and headcount business case.
- Working architecture fluency across identity, cloud (Azure), data protection, and SASE — enough to direct architects and challenge technical designs.
- Bachelor’s degree in a relevant field or equivalent experience; CISSP and/or CISM required.
PREFERRED QUALIFICATIONS
- Private-equity portfolio-company experience, including M&A security due diligence and post-close integration.
- Media, entertainment, talent-representation, or high-net-worth-individual environment — elevated BEC/impersonation and privacy exposure.
- Experience standing up an independent cyber-risk reporting line or remediating findings from an external security assessment or audit.
- Experience insourcing security functions from a managed provider on a phased plan.
- Advanced credentials — CRISC, CCISO, or an MBA / MS in cybersecurity.
Per local requirements and in the interest of transparency, the rate shown below reflects the prevalent current hiring range for this position. Hiring pay rates are based on a number of factors, including location and may vary depending on job-related qualifications, knowledge, skills and experience. The company strives to provide locally competitive rewards packages, which include base rate along with, as applicable, short- and long-term incentives, growth and developmental opportunities, and robust benefits, such as health care, retirement, vacation and other paid time off, and additional offerings.
Hiring Rate Minimum:
$183,750 annually (minimum will not fall below the applicable state/local minimum salary thresholds)Hiring Rate Maximum:
$245,000 annuallySkills Required
- 12+ years of cybersecurity experience
- 5+ years leading security teams at the manager or director level
- Experience owning an enterprise security program based on NIST CSF 2.0 or ISO 27001
- Experience with governance, policy, control frameworks, and multi-year security maturity roadmaps
- Experience building and leading internal security functions, including hiring, developing, and retaining security architects, engineers, and analysts
- Experience insourcing security functions from a managed security provider or MSSP
- Executive- and board-level cyber-risk reporting experience
- Experience presenting to boards, audit and risk committees, ownership groups, or private-equity stakeholders
- Enterprise risk management and multi-jurisdiction regulatory experience, including SOX ITGC, GDPR, CCPA/CPRA, and PIPL
- Vendor and contract management experience, including negotiating and enforcing MSSP SLAs
- Incident-response leadership involving a material security incident
- Experience directing cyber resilience, business continuity, and disaster recovery
- Experience building and defending security operating budgets and headcount business cases
- Architecture fluency across identity, Azure cloud, data protection, and SASE
- Bachelor's degree in a relevant field or equivalent experience
- CISSP and/or CISM certification
- Private-equity portfolio-company experience, including M&A security due diligence and post-close integration
- Media, entertainment, talent-representation, or high-net-worth-individual environment experience
- Experience establishing an independent cyber-risk reporting line or remediating external security assessment or audit findings
- Experience implementing a phased security-function insourcing plan
- CRISC, CCISO, MBA, or MS in cybersecurity
What We Do
WME (The WME Group) is a leading talent and media agency representing artists, creators and brands across film, television, music, theater, books and digital media. The company provides talent representation, content services and brand partnerships and — through its IMG and related businesses — operates major sports, events and media rights businesses globally. WME positions itself as an advocate and connector between talent and global audiences.









