Director, Solution Security and Compliance in Phoenix, Arizona at Bosch Building Technologies North America
Explore Related Opportunities
Job Description
We are seeking a Director, Solution Security and Compliance to own the strategy, governance, and delivery of our customer-facing cybersecurity and compliance programs. This role serves as the designated Cybersecurity Partner (CSP) for North America, ensuring our customers' systems are robustly architected, implemented, and maintained in a secure manner.
This leadership role has a core mandate to establish a proactive cybersecurity program that strikes a balance between operational agility and rigorous corporate compliance. The leader will ensure the organization remains agile during pre-sales quoting and engineering cycles, while fully meeting the governance requirements outlined in our internal corporate cybersecurity policy framework. Operating adjacent to the leaders of Central Technical Services and Central Engineering and Design, this role works deeply cross-functionally across all branch offices and operational layers in North America.
Key Responsibilities
1. Cyber Program and Secure Architectures
- Develop and operationalize a comprehensive, customer facing Cyber Program tailored to building technology solutions, including but not limited to Physical Security, Building Automation, AV systems and the underlying IT/OT infrastructure.
- Establish an architectural evaluation framework to review every proposed customer solution during the presales phase, enforcing robust security by design principles prior to client submission.
- Implement automation and AI solutions within the design and security review workflow to minimize administrative friction, preserving our ability to deliver proposals under time constraints and maintaining our bidding agility.
- Define and enforce standard installation practices and secure baseline configurations to guide field resources and systems integration teams.
- Develop and distribute repeatable hardening checklists for site implementation to guarantee deployed systems are properly secured against common exploit vectors.
- Lead security verification, validation, and comprehensive quality assurance routines across finished installations to confirm alignment with requirements.
2. Compliance, Governance and Reporting
- Monitor, audit, and enforce North American compliance with internal security requirements across all our customers systems.
- Act as the primary governance bridge between the Bosch Building Technologies North America business entity and the parent organization's corporate cybersecurity function.
- Own risk reporting, manage regional control gap analyses, and execute management status briefings to executive leadership.
- Maintain strategic veto authority over high-risk technical architectures or deployment models failing to meet acceptable security thresholds.
3. Third-Party Compliance and Risk
- Develop and oversee vendor cybersecurity compliance evaluations to ensure third-party products, firmware, and commercial software packages that we resell meet the minimum requirements to be compliant with our policies.
- Identify and track cybersecurity related risks from the vendor cybersecurity compliance evaluations and provide recommendations to manage the risks that may be introduced into our customers infrastructure.
4. Client Assessments
- Build and manage a highly efficient operational function tasked with evaluating, processing, and responding to complex cybersecurity questionnaires requested by customers.
- Collaborate with customer information security (InfoSec) and internal IT teams to navigate security requirements and validate the organization's systemic compliance.
- Support the negotiation of Customer Cybersecurity Agreements, detailing clear delineations of security boundaries, lifecycle patching, and data privacy limits.
5. Leadership and People Management
- Recruit, lead, and mentor a team of cybersecurity architects and program managers.
- Foster a cultural mindset of risk awareness and secure execution across all levels, regions, and functional branches of the organization.
- Establish clear professional development pathways, training regimens, and technical qualification curricula for all roles in the organization responsible for implementing and maintaining systems.
6. Cross-Functional Integration and Stakeholder Alignment
- Work closely alongside the Sales, Design, Engineering, Estimating and Branch leader to embed threat modeling into presales and estimating pipelines without introducing proposal delays.
- Partner with the Central Technical Services and Project Operations to smoothly hand over architecture approved plans and hardening checklists to deployment teams responsible for complex IT implementations.
- Coordinate with central corporate infrastructure, legal compliance, and regional branch management to manage vulnerability management timelines and guide local incident response scenarios.
Required Qualifications:
- 10+ years of dedicated professional experience in enterprise cybersecurity, secure systems engineering, or information risk management, with a clear history of technical mastery.
- Direct experience within the physical security systems, building automation, OR equivalent operational technology (OT) sectors.
- At least 5 years operating in a high-level organizational leadership role (Director or Senior Manager) directly guiding security or compliance programs.
- Solid academic and technical background, preferably rooted in computer engineering, computer science, or an equivalent technical engineering discipline.
- Deep working familiarity with rigorous international security standards and control frameworks (e.g., ISO/IEC 27001/27002, NIST, or equivalent corporate policy suites).
- Extensive experience interpreting secure infrastructure layouts, network segmentation models, identity/access controls, and cryptographic mechanisms.
- Superior communication and diplomatic skills, capable of maintaining high authority while building productive bridges across branches, corporate functions, and customer InfoSec leaders.
Preferred Qualifications:
- A business management degree or advanced technical degree.
- Advanced experience with physical security systems or building automation systems.
- Recognized executive security credentials such as Certified Information Security Manager (CISM), Certified Information Systems Security Professional (CISSP), or Certified Protection Professional (CPP).
Key Competencies
- Strategic and Systems Thinking able to design end to end architectures that span customer sites, cloud, and managed services.
- Execution and Delivery strong program and project delivery discipline for complex, multi-site infrastructure deployments.
- Security and Risk Mindset designs with resilience, security, and lifecycle in mind.
- Customer Orientation balances engineering purity with practical, value focused customer outcomes.
- Leadership builds high performing teams and creates clarity in complex environments.
Physical Demands:
In general, the following physical demands are representative of those that must be met by an employee to successfully perform the essential functions of the job.
- Must be able to effectively communicate in English, (ie see, hear, speak and write clearly) in order to communicate with colleagues and/or customers
- Manual dexterity required for occasional reaching, lifting of light office objects, and operating office equipment
- Sitting, standing, walking in office environments and construction sites
- The employee must occasionally lift and/or move up to 50 pounds and may be required to work at heights over 1.8m (6 feet)
Working Conditions:
In general, the following conditions of the work environment are representative of those that an employee encounters while performing the essential functions of this job.
- The office is clean, orderly, properly lighted and ventilated. Noise levels are considered low to moderate
- Will be required to be on site with customers or contractors, with or without Bosch colleagues to manage the expectations and deliverables. Sites range from general office environments to new construction.
- Driving to customer sites is required
- Limited travel may be required
Additional Information:
- Compensation:$135,000 - $200,000 (DOE)
- Working Hours:This position generally works Monday- Friday, overtime and on call when necessary
- Travel Requirements:Occasional Travel Required
- Benefits:
- Medical
- Dental
- Vision
- Flexible Spending Accounts
- 401K w/ company match
- Life/AD&D/LTD
- Paid Vacation/Sick/Holidays
- Employee Assistance Program
- Pet Insurance