-
Head of Information Security
- Sportsman's Warehouse (UT)
-
Head of Information Security Corporate , UT
Details ID: 24179
Posted: 10/22/2025
Expires: 11/21/2025
Department: IT
Shift Info Type: Full-time
Shift(s): Varies
Hours: N/A
Wage Info Wage/Salary:N/A
Wage/Hourly: N/A
Description
Mission Statement: At Sportsman's Warehouse, we provide outstanding gear and exceptional service to inspire outdoor memories.
Since 1986, when we opened our very first store in Midvale, UT, Sportsman's Warehouse has been on a remarkable journey. Today, we're proud to have grown to over 140+ locations across the United States and we're still expanding.
But our journey doesn't stop there. We're also committed to helping you craft your career path. At Sportsman's Warehouse, we believe in creating opportunities for individuals who are eager to begin their employment with us. We don't just offer jobs; we offer fulfilling careers with room to grow.
Benefits and Perks:
+ Health, Dental & Vision Insurance
+ Paid Time Off
+ Industry Leading Employee Discounts
+ Life Insurance
+ 401K with Employer Match
+ Employee Stock Purchase Plan
+ Supplemental Insurance - STD, Critical Illness, Hospital Indemnification & Volunteer Life Insurance
+ Employee Assistance Program
+ On-site Gym Facility
+ Employee Appreciation Activities
Wage & Compensation:
$180K+ Bonus/Comp Structure & Full Beneftis Job Summary:
Sportsman’s Warehouse, a Utah-based omni-channel retailer, is seeking a Head of Information Security to lead our enterprise cybersecurity and information risk program. This Director-level role is responsible for developing and executing a comprehensive security strategy that protects the company’s data, systems, and customer information across all retail and e-commerce operations. Reporting to the Chief Information Officer (CIO), the Head of Information Security focuses on cybersecurity (not physical security) and serves as the organization’s top advisor on information protection and compliance matters. Key priorities for the coming year include strengthening security compliance (e.g. SOX, PCI-DSS), enhancing Governance, Risk, and Compliance (GRC) processes, improving intrusion detection and incident response capabilities, and advancing business continuity and disaster recovery readiness. The successful candidate will combine strategic leadership with hands-on expertise to embed security throughout the business in a cost-effective, business-aligned manner, ensuring that legal, regulatory, and operational risks are properly identified and mitigated in line with corporate objectives.
Key Responsibilities
+ Security Strategy & Governance: Improve and evolve an organization-wide information security strategy and roadmap aligned with business goals and evolving threats. Establish and maintain security policies, standards, and procedures, and define multi-year plans to mature the company’s security posture.
+ Regulatory Compliance & Risk Management: Lead the enterprise GRC program, ensuring security controls and processes meet all relevant regulatory and industry standards (such as PCI-DSS for payment security and SOX for financial controls). Oversee regular security risk assessments across all business units and compliance audits, driving prompt remediation of findings to maintain a high compliance rate and minimize audit issues (e.g. reducing PCI or SOX findings).
+ Security Operations & Intrusion Detection: Oversee day-to-day security operations, including management of Security Information and Event Management (SIEM) tools and intrusion detection/prevention systems, to continuously monitor the environment for threats. Lead the incident response process for cybersecurity events – promptly investigating alerts, coordinating response efforts, performing forensic root cause analysis, and implementing remedial actions to prevent recurrence. Continuously refine intrusion detection efficiency and reduce security incident frequency through proactive threat hunting and monitoring.
+ Business Continuity & Disaster Recovery: Develop, implement, and routinely update comprehensive business continuity and disaster recovery (BCDR) plans covering all critical systems and business functions. Coordinate regular BCDR drills, scenario tests, and backup recovery tests to ensure rapid recovery capabilities and successful restoration of services with minimal downtime in the event of a disruption.
+ Identity & Access Management: Ensure effective identity and access management processes are in place to safeguard systems and data. Enforce the principle of least privilege through strict access controls and periodic access reviews, and oversee identity governance to maintain high access control effectiveness.
+ Security Risk Assessment & Testing: Conduct and coordinate regular security assessments and testing to uncover vulnerabilities. This includes managing periodic vulnerability scans, penetration tests, and security audits of applications and infrastructure, then driving the timely remediation of any identified risks or weaknesses. Track and improve metrics such as penetration test success rates and risk assessment coverage across business units as measures of program effectiveness.
+ Policy Development & Awareness: Develop and update information security policies and guidelines in accordance with industry best practices and emerging threats. Lead organization-wide security awareness and training initiatives to foster a culture of security, ensuring employees at all levels understand and follow safe practices (recognizing that human factors are critical to reducing incidents).
+ Cross-Functional Collaboration: Work closely with other departments and senior leadership to embed security into all business processes and technology projects. Liaise with IT, engineering, Product, Finance, and Loss Prevention teams to ensure secure system and software design, with Legal/Compliance on contracts and data protection initiatives, and with business units to advise on risk management in new project. Serve as the subject matter expert on cybersecurity for internal stakeholders, ensuring security requirements are integrated without impeding business operations.
+ Team Leadership & Performance: Lead, mentor, and develop the internal information security team (security analysts, engineers, GRC specialists, etc.) and manage relationships with any external security service providers. Plan and oversee the security program budget and resources, ensuring cost-efficient security investments and compliance efforts. Establish key security metrics (e.g. incident response times, compliance rates, audit remediation time) and regularly report on the security program’s performance and risks to the CIO and executive leadership. Prepare quarterly briefings for the Board of Directors. Champion a culture of accountability and continuous improvement within the security team.
Working Conditions:
+ Full-time position based at Company Headquarters in South Jordan, UT. Regular visits within the Salt Lake valley to stores, distribution center / call center.
+ Occasional overnight travel may be required.
Why Join Us:
+ Opportunity to build and shape Security in a dynamic omnichannel enterprise.
+ Fast paced environment with immediate opportunities to personally make a difference.
+ Competitive salary and benefits package.
If you are passionate about personally driving transformation, following the data wherever it leads, and have a strong bias toward action, we would love to hear from you. Apply now to join our team and make a significant impact on our product strategy and execution.
Sportsman’s Warehouse is an Equal Opportunity Employer.
Requirements
Qualifications:
+ 10+ years of InfoSec experience across retail, eCommerce, or similar industries with at least 3 years Director+
+ Bachelor’s degree in Computer Science, Information Systems, Cybersecurity or a related field (or equivalent additional years of experience). CISSP, CISM, CISA preferred.
+ Retail and eCommerce experience strongly preferred.
Skills and Competencies:
+ Experience: Extensive professional experience in information security and IT risk management, including demonstrated success in leading cybersecurity teams or programs at the enterprise level
+ Security Knowledge: Strong understanding of information security principles, practices, and frameworks (e.g. NIST Cybersecurity Framework, ISO/IEC 27001) as well as applicable regulatory standards and laws (such as PCI-DSS and Sarbanes-Oxley). In-depth knowledge of governance, risk, and compliance processes and the ability to interpret and apply security policies and controls to meet these standards.
+ Technical Expertise: Demonstrated expertise in key security domains and technologies – including risk assessment, incident response, security operations (SIEM/SOC monitoring, intrusion detection systems), identity and access management, and cloud security controls. Broad familiarity with enterprise IT infrastructure and security tools (firewalls, anti-malware, encryption, identity management systems, etc.), across on-premises and cloud environments.
+ Leadership & Communication: Excellent leadership, communication, and interpersonal skills, with the ability to articulate cybersecurity risks, requirements, and strategies in clear business terms to both technical and non-technical audiences (including executives and board members). Proven ability to collaborate across teams and influence stakeholders to achieve security objectives.
+ Analytical Skills: Strong analytical and problem-solving abilities with keen attention to detail, capable of evaluating complex security issues to identify root causes and effective solutions. Solid project management skills to oversee multiple security initiatives and drive them to completion in a fast-paced environment.
+ Results Orientation: Track record of executing security improvements and effectively mitigating risks. Ability to define and monitor relevant security KPIs (e.g. incident rates, compliance metrics, mean time to resolution) and use data to inform decision-making and continuous improvement.
Sportsman's Warehouse is proud to be an Equal Employment Opportunity Employer. We do not discriminate based upon race, religion, color, national origin, gender (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender identity, gender expression, age, status as a protected veteran, status as an individual with a disability, or other applicable legally protected characteristics.
-