Candidates must be authorized to work in the United States and not require current or future employment visa sponsorship. Drury Hotels does not sponsor employment visas for this position.
Property Location:
13075 Manchester Rd - St. Louis, Missouri 63131You belong at Drury Hotels.Getting a job is just the beginning. Finding a place where you belong is what truly matters. Who you are and what you do makes a difference at Drury Hotels. There's a place for you here today and tomorrow.
WHAT YOU CAN EXPECT FROM US
So. Much. More.
Just as our guests deserve more, so do you deserve more. Be valued for what you do and who you are ... and well compensated for all you accomplish.
Work-life-balance – Flexible scheduling, paid time off, hotel discounts and free room nights
Career growth - Mentorship, cross-training, development plans, management training, and more-over 200 internal promotions this year
Health and well-being - Medical, dental, vision, prescription, life, disability and Team Member Assistance Program
Retirement - Company-matched 401(k)
Award-winning - Ranked among Newsweek's America's Greatest Workplaces 2025
Incentives - Quarterly bonuses (we succeed together!) based on hotel results
Summary:
Leads the company’s cybersecurity program, overseeing governance, risk, compliance, and day-to-day security operations. Responsible for information security across internal systems, cloud solution providers, vendor/third-party solutions, identity and access management, and application development.
Establishes security architecture, strategic roadmaps, and operational standards to strengthen the company’s overall security posture. Evaluates and implements technologies and processes to improve efficiency, effectiveness, and strengthen overall security posture. Oversees capabilities that enable the organization to identify, protect, detect, respond to, and recover from cyber threats and vulnerabilities.
Defines security requirements using risk assessments, threat modeling, testing, and analysis of existing systems. Ensures operational security activities (including endpoint security and patch management) are performed timely and efficiently. Oversees compliance related activities including PCI compliance and NIST alignment.
Responsibilities and Duties:
Provide leadership and direction for the cybersecurity program, managing a team that includes security operations and security compliance (GRC) leadership.
Develop, maintain, and evolve a security roadmap and annual operating plan that balances operational needs, compliance requirements, and risk reduction.
Stay current on industry threats, alerts, technology trends, and best practices related to cybersecurity.
Oversee day-to-day security operations through the Supervisor of IT Security Operations, including monitoring/SOC, endpoint security (EDR), identity, vulnerability management, and timely remediation of alerts.
Oversee governance, risk, and compliance through the Manager of Compliance and Security, including policy/standards management (e.g., NIST), risk assessments, audit support, and compliance obligations (e.g., PCI DSS). In a lean team environment, this role may also support operational security controls such as email security, Active Directory/Group Policy (GPOs), and network access controls (ACLs).
Facilitates a metrics and reporting framework to measure the efficiency and effectiveness of the program, facilitates appropriate resource allocation, and increases the maturity of the cybersecurity, and reviews it with stakeholders at the executive and board levels.
Directs the cybersecurity awareness training program for all team members and establishes metrics to measure the effectiveness of this security training program.
Establish and enforce security standards and “security by design” practices across technology platforms, application development, and vendor solutions.
Partner with IT operations to define, test, and oversee disaster recovery and business continuity security requirements and resilience controls.
Oversee third-party security partners and vendor security posture, including due diligence, contractual security requirements, and ongoing third-party risk management.
Hire, develop, coach, and evaluate team members; establish clear goals and metrics; and ensure appropriate training and professional development.
Basic Qualifications:
Strong analytical, problem-solving, and decision-making skills.
Ability to learn and apply new technologies and security concepts quickly.
Ability to communicate complex security topics to technical and non-technical stakeholders at an appropriate level of detail.
Strong collaboration skills; ability to work effectively with coworkers, leaders, and external partners/vendors.
Ability to work independently, prioritize competing demands, and lead through influence in a team environment.
Ability to evaluate security tools and vendors, negotiate contracts, and manage vendor relationships.
Demonstrated experience leading teams and influencing across IT and the business.
Working knowledge of incident response concepts and operational security practices (e.g., endpoint security, vulnerability management, patching).
Ability to apply a risk-based approach to prioritize security investments and activities.
Effective verbal and written communication skills.
Demonstrated experience and success in senior leadership roles in risk management, cybersecurity, and IT or OT security
Experience with contract and vendor negotiations
Required Qualifications:
10+ years of experience in cybersecurity, including leadership/management experience.
Production/enterprise experience operating and improving security controls (e.g., EDR, vulnerability management, email security, network security).
Experience with security frameworks and compliance requirements (e.g., NIST, PCI DSS) and translating them into actionable controls.
Experience with identity and access management (IAM), privileged access, and related monitoring practices.
Experience with third-party/vendor risk management and security assessments.
Preferred Qualifications:
Experience leading large teams, including managing managers.
Strong knowledge of network and security fundamentals and how they apply to enterprise environments.
Experience with security budgeting, KPI/metrics reporting, and multi-year roadmap development.
Experience with Microsoft administrative controls and governance.
Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified Information Systems Auditor (CISA), Certified in Risk and Information Systems Control (CRISC) or other similar credentials
Skills Required
- 10+ years of cybersecurity experience, including leadership or management experience
- Experience operating and improving enterprise security controls, including EDR, vulnerability management, email security, and network security
- Experience with security frameworks and compliance requirements such as NIST and PCI DSS
- Experience translating security frameworks and compliance requirements into actionable controls
- Experience with identity and access management, privileged access, and related monitoring practices
- Experience with third-party or vendor risk management and security assessments
- Demonstrated experience leading teams and influencing across IT and the business
- Working knowledge of incident response and operational security practices
- Ability to apply a risk-based approach to prioritize security investments and activities
- Experience with contract and vendor negotiations
- Strong analytical, problem-solving, decision-making, communication, collaboration, and prioritization skills
- Experience leading large teams, including managing managers
- Strong knowledge of enterprise network and security fundamentals
- Experience with security budgeting, KPI and metrics reporting, and multi-year roadmap development
- Experience with Microsoft administrative controls and governance
- CISSP, CISM, CISA, CRISC, or similar credential
What We Do
In this current market, jobs are abundant. Nearly everyone is hiring. But it’s finding a place where you belong that truly matters. At Drury Hotels, who you are and what you do makes a difference. We don’t see each other as colleagues; we are a family working together towards one common goal: to provide the best customer service in the hospitality industry. If you are really good at taking care of others and are looking for a career instead of a job, then Drury Hotels might be right for you. Join our team and grow happy! Drury is your place to shine, to be heard and supported, and most importantly to be appreciated for what you do. You can expect So Much More™ from Drury Hotels. We believe this is more than a paycheck. It’s: • Health & well-being benefits • Discounted and free rooms • Team member assistance programs • Bonuses for great service • Flexibility for balancing life Our Vision: Our guests experience the spirit of great hospitality. We are their first choice as their home away from home. Every member of the team feels passion for their work, takes pride in the company, and demonstrates a sense of ownership. We create opportunities and make a difference in people’s lives. Our dedicated team is committed to the pursuit of excellence in all that we do. Our Mission: Our guests are our #1 priority, and we offer them more value for the dollar than our competitors. Our success depends on these factors: · Quality that consistently exceeds guest expectations. · Service that makes our guests feel welcome and at home. · Teamwork demonstrated by team members who enjoy their jobs and are committed to the long-term success of our family-owned business. · Profitability which is the result of our mission and allows us to grow







