Description:
At Ally, you get a startup feel, but experience the benefits of a company that has worked out the kinks and is fulfilling its purpose. We are always evolving and see that as a good thing. From owning our work to seeing its impact in the real world, our team is relentless in finding new ways technology can help make experiences better and help people. We are problem solvers, we value diverse thinking, we support one another, and we challenge ourselves to think bigger in the journey to deliver customer-obsessed tech solutions. To read more about what our tech team does, be sure to visit our tech blog at ally.tech
The Director of Cyber Security position at Ally is a member of the Information Protection and Risk Management (IPRM) team and reports directly to the Sr. Director of Technology Data Protection and drives collaboration across business units to protect Ally’s data and reputation. Ally is seeking a visionary leader to serve as Director, Cyber Security, accountable for Cyber Insider Threat (CIT) and Data Loss Prevention (DLP) programs. This role will drive the full lifecycle management of the CIT/DLP, Cryptographic Services and Database Activity Management programs, including the transition from traditional DLP to an automated DLP as a Service (DaaS).
At this time, Ally will not sponsor a new applicant for employment authorization for this position.
The Work Itself
Strategy Execution
- Develop and execute enterprise-wide CIT and DLP strategies aligned with business objectives and risk priorities.
- Drive the continued transformation of DLP from traditional models to DLP as a Service.
- Establish and maintain controls for data classification, loss prevention, and encryption of data at rest, data in use, and data in transit across the enterprise.
- Serve as a thought leader and partner to senior leaders, guiding the adoption of best practices for insider threat and data protection.
- Lead the execution of Ally’s Post-Quantum Cryptography (PQC) readiness strategy, collaborating with cross-functional teams to ensure data protection measures are robust and future-ready against emerging quantum threats.
Program Execution & Governance
- Oversee governance of CIT and DLP controls, partner with engineering teams to create and deploy policies based on company standards.
- Lead initiatives to discover, classify, and monitor sensitive data and develop insider threat indicators.
- Design and tune monitoring solutions to detect anomalies, unauthorized access, and data misuse.
- Translate findings into prioritized remediation actions and risk-reduction plans.
- Review and approve changes to policies and procedures to ensure efficiency and regulatory compliance.
- Responsible for the development and management of CIT and DLP metrics.
Collaboration
- Interface with cyber security technology, HR, enterprise fraud, compliance, privacy, and risk partners to ensure alignment and effective program delivery.
- Influence and enable data owners, technology teams, and business units to adopt security practices.
- Deliver clear communications and training to improve awareness and accountability.
- Participate in steering committees or working groups on enterprise security initiatives.
- Regulatory & Policy Compliance
- Interpret privacy and compliance laws and industry regulations into actionable security controls.
- Align security efforts to frameworks such as NIST CSF, ISO 27001, and CIS.
- Support internal and external audits by maintaining evidence of effectiveness of the control.
Skills
The Skills You Bring
Required:
- 7+ years of Information Security experience.
- Bachelor’s degree in information systems or a relevant field preferred.
- Proven ability to lead and manage teams specializing in insider threat, data discovery, classification, DLP, cryptographic services, and database activity monitoring.
- Proven experience with multi-cloud platforms (AWS, Azure, GCP) and data security solutions (such as ALTR, Broadcom, Microsoft, Palo Alto Prism, Thales etc.).
- Familiarity with tools such as BigID, Microsoft Purview, Splunk, or ALTR.
- Excellent communication, analysis, and stakeholder engagement skills.
- Ability to interact with personnel at all levels and comprehend business imperatives.
- Strong customer/client focus and relationship-building skills.