Talent.com
Costco
Director - Threat Exposure ManagementCostco • Issaquah, WA, United States
Director - Threat Exposure Management

Director - Threat Exposure Management

Costco • Issaquah, WA, United States
30+ days ago
Salary
$160,000.00 yearly
Job type
  • Full-time
Job description

Director Of Threat Exposure Management

Costco IT is responsible for the technical future of Costco Wholesale, the third largest retailer in the world with wholesale operations in fourteen countries. Despite our size and explosive international expansion, we continue to provide a family, employee centric atmosphere in which our employees thrive and succeed.

This is an environment unlike anything in the high-tech world and the secret of Costco's success is its culture. The value Costco puts on its employees is well documented in articles from a variety of publishers including Bloomberg and Forbes. Our employees and our members come FIRST. Costco is well known for its generosity and community service and has won many awards for its philanthropy. The company joins with its employees to take an active role in volunteering by sponsoring many opportunities to help others.

Come join the Costco Wholesale IT family. Costco IT is a dynamic, fast-paced environment, working through exciting transformation efforts. We are building the next generation retail environment where you will be surrounded by dedicated and highly professional employees.

As a member of the IT Management Team, you are responsible for managing, developing, and leading a team of employees. Your role includes leading the specific functional responsibilities of your team, which involves overseeing team performance and deliverables. However, your role as a leader within our organization requires more than the management of resources and day-to-day operations. As a steward of the company, you are charged with the development and execution of your team's strategic vision and plan and ensuring that your team's actions align with the larger goals of the company and the IT Division.

The Director of Threat Exposure Management holds a crucial leadership role, driving a proactive program to identify, assess, and manage security risks and vulnerabilities across the technology landscape. This role is built upon four core functions: overseeing the Penetration Testing Program, including managing internal/external teams and tracking remediation; establishing and running Red Team Operations, which involves advanced adversary emulation and Purple Teaming for defense improvement; owning the full Vulnerability Management lifecycle, from continuous scanning and automation to enforcing remediation SLAs; and managing the Attack Surface Management by continuously mapping the digital footprint, classifying assets, and reducing risk through segmentation. This role is also responsible for the Application Security function, ensuring security is 'shifted left' through secure development lifecycle integration, application scanning (SAST/DAST/IAST), and managing application-specific risks.

Additionally, the Director is responsible for critical cross-functional duties, focusing heavily on data-driven risk prioritization. This includes implementing platforms, such as Risk-Based Vulnerability Management (RBVM) to normalize security findings and developing advanced risk scoring models (combining CVSS, exploitability, context, and threat intelligence) to efficiently prioritize and triage issues. Discover, correlate, prioritize, and triage all findings, vulnerabilities, and misconfiguration; report to the technology owners and track actions and mitigation. The Director must clearly communicate findings to technology owners, rigorously track mitigation progress, ensure accountability, escalate risks, and provide executive-level reports detailing overall exposure reduction. The incumbent must build strong cross-functional relationships and systematically drive the implementation, execution, metrication, and long-term sustainability of program objectives to continuously enhance the security operations' capacity to protect against and proactively respond to vulnerabilities and threats worldwide.

As the primary conduit between your employees and upper leadership, your role in communicating and modeling the values and guiding principles of our company culture is of vital importance. All members of IT Management should strive to consciously and consistently foster a culture of engagement, trust, and "open door" communication.

If you want to be a part of one of the worldwide BEST companies "to work for", simply apply and let your career be reimagined.

Role

  • Integrity: When achieving benchmarks and goals, use methods/strategies that are consistent with the Code of Ethics and the Standard of Ethics for Managers and Supervisors. Always leads by example. Appropriately handles employee concerns and follows through to resolution.
  • Member Service: Provides and ensures staff provides an exceptional member experience.
  • Administration: Ensures proper department coverage (writing schedule and break aids if needed). Understands department budget, able to research and explain budget variances.
  • Managing Performance: Coaches and mentors employees to provide support and guidance. Has regular open and honest conversations with employees to discuss work performance and career development. Identifies learning opportunities to strengthen employee knowledge, skill and ability.
  • Communication: Regularly shares information with employees via meetings and one-on-one conversations. Successfully navigates difficult conversations with employees, members, and suppliers. Listens, expresses empathy and adapts to get points across. Addresses issues immediately to ensure a timely resolution and to avoid escalating the situation. Consistently demonstrates business knowledge during interactions with senior management. Create clear and concise communications/recommendations for senior leadership review related to strategic business plans and initiatives
  • Self-Management: Demonstrates sound judgment, taking a partner when necessary.
  • Inclusion: Encourages different approaches and ideas to work and to accomplish goals. Seeks employee input. Take the time to get to know or reach out to candidates who show potential that may not come forward on their own.
  • Compliance and Safety: Takes measures to ensure employee and member information is kept confidential and adheres to IS security policy.
  • Works directly with the Senior Executive team to design, develop, and assist in the implementation of InfoSec strategies, ensuring alignment to corporate vision/goals.
  • This is a full-time management/leadership position (45+ hours per week).

Required

  • 5+ years' of experience in leading penetration testing teams, red teams, and vulnerability management organizations in a global security organization.
  • A history of defining and enforcing remediation timelines based on risk levels, including managing the friction that arises with DevOps and Engineering teams.
  • Experience facilitating collaboration between offensive (Red) and defensive (Blue) teams to ensure that findings actually result in better detection logic.
  • Experience negotiating with CTOs and VPs of Engineering to balance security patches with product feature velocity.
  • Deep understanding of the OWASP Top 10 and CWE Top 25.
  • Experience working within CI/CD pipelines (GitHub Actions, GitLab CI, Jenkins) and understanding how to inject security without breaking the build.
  • Knowledge of modern stacksmicroservices, Kubernetes, serverless, and cloud-native security (AWS, Azure, GCP).
  • Experience with frameworks, such as STRIDE, PASTA, or LINDDUN.
  • Ability to translate a theoretical threat into a business risk.
  • Experience taking Red Team findings and translating them into "Engineering Requirements." For example, if a Red Team exercise repeatedly bypasses authentication, the Director doesn't just ask for a patch; they work with Engineering to implement a standardized identity service across the org.
  • Ability to move away from being a "bottleneck" that blocks releases, and move toward providing "paved roads" (pre-approved, secure configurations) for developers.
  • Experience integrating vulnerability and misconfiguration checks directly into CI/CD pipelines (e.g., using Terraform, CloudFormation, or Kubernetes security tools).
  • HIPAA Training and Supervisors Orientation (within 30 days of hire); Leadership Development 101 (within one year); Costco Pay Policies (within 90 days of promotion).

Recommended

  • Master's Degree in a relevant technology field or equivalent experience.
  • Certified Information Security Manager (CISM) or Certified Information Systems Security Professional (CISSP).
  • Demonstrate a logical and structured approach to time management and task prioritization.
  • Proficient in Google Workspace applications, including Sheets, Docs, Slides, and Gmail.

Required Documents

Cover Letter

Resume

Pay Range: $160,000 - $230,000, Bonus and Restricted Stock Unit (RSU) eligible

We offer a comprehensive package of benefits including paid time off, health benefits - medical/dental/vision/hearing aid/pharmacy/behavioral health/employee assistance, health care reimbursement account, dependent care assistance plan, short-term disability and long-term disability insurance, AD&D insurance, life insurance, 401(k), stock purchase plan to eligible employees.

Costco is committed to a diverse and inclusive workplace. Costco is an equal opportunity employer. Qualified applicants will receive consideration for employment without regard of race, national origin, gender, gender identity, sexual orientation, protected veteran status, disability, age, or any other legally protected status. If you need assistance and/or a reasonable accommodation due to a disability during the application or the recruiting process, please send a request to IT-Recruiting@costco.com

If hired, you will be

Create a job alert for this search

Director - Threat Exposure Management • Issaquah, WA, United States

Similar jobs

Senior Director, Manufacturing Operations - Site Based, Redmond, WA

Just Evotec BiologicsRedmond, WA, United States
Full-time

Evotec Manufacturing Leadership Opportunity.At Evotec, we believe that curiosity is the spark that drives innovation and success.As a forward-thinking team, we thrive on challenging the status quo,... Show more

 • Promoted

Sr. Director, Product Safety and Technical Compliance

PelotonWoodinville, WA, United States
Full-time

Senior Director, Technical Product Safety & Regulatory Compliance.The Senior Director, Technical Product Safety & Regulatory Compliance leads Peloton's global Technical Product Safety organization,... Show more

 • Promoted

Director - Cloud Practice

ClifyXRedmond, WA, United States
Full-time

Cloud & Infrastructure Business Development Leader.We are seeking an accomplished and strategic Cloud & Infrastructure business development leader to drive growth across our Microsoft global partne... Show more

 • Promoted

Senior & Principal Security Researcher

Microsoft CorporationRedmond, WA, United States
Permanent

OverviewThe Cloud & AI organization accelerates Microsoft's mission and bold ambitions to ensure that our company and industry is securing digital technology platforms, devices, and clouds in o... Show more

 • Promoted

EH&S Manager

EvotecRedmond, WA, United States
Full-time

Location: Redmond, WA (with support of Seattle, WA site).At Just-Evotec, we believe that curiosity is the spark that drives innovation and success.As a forward-thinking team, we thrive on challengi... Show more

 • Promoted

Security Operations Manager - Full Time

SecuritasRedmond, WA, United States
Full-time

Security Operations Manager Full Time.We offer a full benefits package, PTO, weekly pay, and more!.Location: Redmond, Kirkland, & Everett, WA.We help make your world a safer place.At Securitas, we... Show more

 • Promoted

Director - Cloud Supply Chain Risk & Compliance

Microsoft CorporationRedmond, WA, United States
Full-time

Overview Microsoft's Cloud business is expanding, and the Cloud Supply Chain (CSCP) organization is responsible for enabling the hardware infrastructure underlying this growth including AI! CSCP's... Show more

 • Promoted

AO/SI Solution Architect Senior Manager/Associate Director Accenture - Redmond, WA Posted today

Massachusetts Gaming CommissionRedmond, WA, United States
Full-time

The primary responsibility of this role is to be a Value architect in medium sized to large opportunities that may involve solutioning and estimation of Systems Integration, Application Development... Show more

 • Promoted

Starlink Enterprise Account Director, Aviation

SpaceXRedmond, WA, United States
Permanent

Starlink Enterprise Account Director, Aviation.SpaceX was founded under the belief that a future where humanity is out exploring the stars is fundamentally more exciting than one where we are not.T... Show more

 • Promoted

OCM Lead

E-SolutionsRedmond, WA, United States
Full-time

My client is a global technology consulting and digital solutions company that enables enterprises across industries to reimagine business models, accelerate innovation, and maximize growth by harn... Show more

 • Promoted

Principal Applied Threat Intelligence Manager

MicrosoftRedmond, WA, United States
Full-time

When you upload your resume, we provide job recommendations to you.Please confirm you have read and understand how your data may be processed pursuant to the Microsoft Data Privacy Notice and Trans... Show more

 • Promoted

Principal Consulting Epidemiologist

J.S. Held LLCRedmond, WA, United States
Full-time

Department: Environmental Health & Safety Consulting.Compensation: USD 150000 - USD 300000 - yearly.Held is a global consulting firm that combines technical, scientific, financial, and strategic ex... Show more

 • Promoted

Retail Loss Prevention Detective

MarshallsRedmond, WA, US
$17.13 hourly
Full-time

Marshalls At TJX Companies, every day brings new opportunities for growth, exploration, and achievement.You’ll be part of our vibrant team that embraces diversity, fosters collaboration, and priori... Show more

 • Promoted

Sr. Director, Sports Retail Operations

BDAWoodinville, WA, United States
Full-time

Director, Sports Retail Operations.Location: Seattle/Woodinville, WA.This role supports retail operations for the Seattle Kraken and requires onsite attendance at all Kraken home games and designat... Show more

 • Promoted

Training Director

Chick-fil-AMaple Valley, WA, United States
Full-time

The Training Director is responsible for developing team members and leaders through structured training programs.This role ensures consistency, growth, and excellence across all positions.Design a... Show more

 • Promoted

Principal Product Manager - Threat Detection Engine and Content (Hybrid)

CrowdStrikeRedmond, WA, United States
Full-time

As a global leader in cybersecurity, CrowdStrike protects the people, processes and technologies that drive modern organizations.Since 2011, our mission hasn't changed we're here to stop breaches,... Show more

 • Promoted

Director, Worldwide Microsoft Co-Sell

NerdioRedmond, WA, United States
Full-time

Director, Worldwide Microsoft Co-Sell.At Nerdio, our mission is to simplify the lives of IT professionals and maximize their Microsoft cloud and end user computing investments.We support organizati... Show more

 • Promoted

Associate Director / Director, Regulatory Affairs IHC Companion Diagnostics (CDx)

SystimmuneRedmond, WA, United States
Full-time

Regulatory Affairs Leader For Ihc-Based Companion Diagnostics.SystImmune is a leading and well-funded clinical-stage biopharmaceutical company located in Redmond, WA and Princeton, NJ.It specialize... Show more

 • Promoted

Strategic Technical Account Director

CyrusOneRedmond, WA, United States
Full-time

Strategic Technical Account Director.We are seeking a Strategic Technical Account Director to join our team.The Strategic Technical Account Director for the Americas is a key Global Strategic Busin... Show more

 • Promoted

Principal Product Manager, Agent 365 Security & Governance

MicrosoftRedmond, WA, United States
Full-time

When you upload your resume, we provide job recommendations to you.Please confirm you have read and understood how your data may be processed pursuant to the Microsoft Data Privacy Notice and Trans... Show more