Howard Hughes logo

Sr. Vice President, Cybersecurity, IT and AI Governance, Risk, and Compliance

Howard Hughes
1 hour ago
Full-time
On-site
The Woodlands, Texas, United States
AI Governance, VP, Director & Partner

Dedicated to innovative placemaking, Howard Hughes Communities is the real estate platform of Howard Hughes Holdings Inc. (NYSE: HHH) and is recognized for its ongoing commitment to design excellence and to the cultural life of its communities. Building on that foundation, we foster a culture of curiosity that empowers every employee to shape their own story within our organization.

About the Role

The Sr. Vice President, Cybersecurity, IT and AI Governance, Risk, and Compliance owns the Company’s cybersecurity program and technology risk oversight, including AI and IT. This position continuously improves these capabilities, translates technology risk into business decisions, and advises executive leadership and the Audit Committee.

Reporting to the Chief Information Officer, the position collaborates with technology teams, business leaders, control owners, vendors, and managed-service partners to maintain scalable, measurable, and business-aligned cybersecurity and governance programs spanning privacy and regulatory compliance, third-party risk, security policy, and resilience. This role enables innovation, modernization, and business growth through informed risk decisions and appropriate safeguards.


What You Will Do

Cybersecurity Strategy and Risk Management

  • Lead a risk-based cybersecurity strategy, governance framework, operating model, roadmap, and investment priorities aligned with business objectives.

  • Assess cybersecurity maturity, control effectiveness, organizational capabilities, and resource needs; convert findings into measurable improvement priorities.

  • Establish policies, standards, accountability structures, and performance measures that adapt to changing business, technology, regulatory, and threat requirements.

  • Advise executive leadership, the Audit Committee, and the Board on cybersecurity posture, material risks, resilience, emerging threats, and recommended actions.

AI and IT Governance, Risk, and Compliance

  • Collaborate with HHX Innovation, Business, Technology, Legal, and Risk stakeholders to establish and maintain an enterprise AI governance model, architecture, risk assessments, responsible-use standards, vendor oversight, monitoring, and accountability.

  • Own the IT GRC framework, including IT SOX, internal controls, risk assessments, control testing, audit readiness, remediation, risk acceptance, and management reporting.

  • Ensure technology and cybersecurity risks are documented, prioritized, assigned to accountable owners, and managed to resolution, with strong evidence quality and data-protection practices.

  • Maintain alignment with NIST CSF 2.0, NIST AI 600-1 and applicable legal, regulatory, contractual, privacy, and industry requirements.

Security, Resilience, and Incident Leadership

  • Set strategic direction across security architecture and engineering, application and product security, identity, cloud, threat intelligence, vulnerability management, security operations, detection and response, and recovery.

  • Oversee the cybersecurity operating model, control lifecycle, managed services, security tooling, awareness, and measurable risk-reduction outcomes.

  • Lead the response to material cybersecurity incidents, coordinating containment, recovery, executive decisions, business continuity, stakeholder communications, and regulatory engagement as required.

  • Sponsor tabletop and recovery-readiness exercises and drive post-incident reviews, corrective actions, lessons learned, and continuous improvement.

Technology, Third-Party Risk, and Business Enablement

  • Embed cybersecurity and GRC requirements into enterprise architecture, application development, cloud adoption, procurement, project delivery, technology change, and operational processes.

  • Govern risk across vendors, affiliates, service providers, and technology integrations through due diligence, contractual requirements, ongoing monitoring, and remediation.

  • Ensure cybersecurity and GRC are integrated into acquisitions, divestitures, major transformations, and emerging-technology initiatives.

  • Balance security, customer experience, operational resilience, delivery speed, and business enablement through clear risk decisions and practical safeguards.

Executive Leadership and Accountability

  • Own the cybersecurity and IT GRC budget, portfolio, resource strategy, managed-service model, and investment recommendations.

  • Build a high-performing, distributed organization through workforce planning, leadership development, performance management, succession planning, and organizational design.

  • Provide concise reporting on risk, threats, control performance, resilience, regulatory developments, business impact, and strategic investments.

  • Represent the Company with auditors, regulators, customers, strategic partners, and other external stakeholders, coordinating authorized communications with relevant leaders.

About You

  • Bachelor’s degree in a relevant discipline; master’s degree preferred.

  • 15+ years of progressive cybersecurity, technology risk, IT governance, compliance, audit, or related leadership, including significant enterprise-level responsibility.

  • Executive leadership of integrated cybersecurity and IT GRC programs in complex, distributed, or highly outsourced environments.

  • Broad expertise across security architecture, application security, cloud, security operations, threat intelligence, vulnerability management, incident response, resilience, recovery, IT SOX, privacy, and third-party risk.

  • Demonstrated ability to lead material incidents, crisis communications, regulatory coordination, post-incident reviews, and corrective-action programs.

  • Strong executive communication skills, with the ability to translate technical issues into business implications, options, recommendations, and decisions for leadership teams, boards, auditors, regulators, customers, and partners.

  • Track record managing budgets, portfolios, vendors, managed services, organizational design, distributed teams, and succession planning while integrating cybersecurity into acquisitions and major transformations.

  • Preferred certifications include CISSP, CISM, CRISC, CISA, CGRC, or comparable credentials; relevant executive leadership may substitute for a specific certification.

  • Strong judgment, executive presence, collaboration, negotiation, and influence, with the ability to make sound decisions amid uncertainty and operate effectively in a fast-moving, highly visible environment.

Benefits Built for You
At Howard Hughes Communities, we offer competitive, market-based compensation that rewards performance and supports career growth. Our comprehensive benefits package designed to support employees at every stage of their career, is focused on holistic wellness—social, emotional, financial, and physical.

  • Competitive 401k plan

  • Generous PTO policy

  • Premium medical, dental, and vision coverage

  • Voluntary benefits for unexpected life events

  • Student loan assistance and stipends to assist with lifelong learning

About Howard Hughes Communities

Howard Hughes Communities develops, owns, and operates the nation’s premier large-scale master planned communities and mixed-use developments. Our award-winning portfolio includes The Woodlands®, Bridgeland®, and The Woodlands Hills® in Greater Houston; Summerlin® in Las Vegas; Teravalis™ in Greater Phoenix; Ward Village® in Honolulu; and Merriweather District® in Columbia, Maryland. Strategically positioned to meet and accelerate development based on market demand, we offer one of the strongest real estate platforms in the country. Learn more at communities.howardhughes.com.

This job description is not meant to be an “all-inclusive” list of the duties and responsibilities of this job.  Other related duties and responsibilities may be assigned.  Howard Hughes Communities reserves the right to change or modify job duties as necessary based on business necessity.



NOTICE TO THIRD-PARTY AGENCIES
Please note that Howard Hughes Communities does not accept unsolicited resumes from recruiters or employment agencies. In the absence of a signed Recruitment Fee Agreement, Howard Hughes Communities will not consider or agree to payment of any referral compensation or recruiter fee. In the event a recruiter or agency submits a resume or candidate without a previously signed agreement, Howard Hughes Communities explicitly reserves the right to pursue and hire those candidate(s) without any financial obligation to the recruiter or agency. Any unsolicited resumes, including those submitted to hiring managers, are deemed to be the property of Howard Hughes Communities.