Job Placement · Cybersecurity · Director of Security
BEG recruits directors of security through direct hire milestone billing, not a percentage of salary. The fee for this seat runs $19,080 to $22,896, priced at Tier IV, with an average fill time of 23 to 35 days, and the reporting line and budget are confirmed before the search starts, not discovered at offer stage.
See your exact placement price - no call required
See pricing before you talk to anyone. No demo gate, no obligation, and no co-employment.
TL;DR
This seat is defined by whom it reports to. A director under a CIO with no CISO is a CISO without the title at director pay, and strong candidates ask about the reporting line on the first call and drop out when the answer changes.
The Hiring Problem
The seat is defined by whom it reports to. A director under a CIO with no CISO is a CISO without the title at director pay, and candidates who sense that drop out mid process.
How BEG Fills This Seat
Four steps that confirm the reporting line and budget before sourcing starts, since that is what actually determines whether this is a director role or a CISO role at director pay.
| Step | What it requires | Where it stalls |
|---|---|---|
| Name the reporting line | Written confirmation of whether this director reports to a CIO, a CISO, or directly to a board committee | Postings leave the reporting line vague, and candidates learn mid process that it changes the job entirely |
| Source for program ownership, not a bigger title | Candidates who have run a budget, vendor contracts and an audit calendar, not just a large technical team | Many strong senior engineer applicants have never owned a budget line or negotiated a vendor contract |
| Vet against a real framework | Evidence the candidate can build a program against NIST CSF or an equivalent, not just describe security concepts | Candidates describe tools and incidents well but cannot describe how they would structure a program |
| Close with the reporting line still intact | Confirmation in writing that the structure discussed on the first call has not shifted before an offer goes out | The reporting line or budget changes between calls and the candidate walks away from an otherwise strong offer |
Most director searches do not fail on talent, they fail on a reporting line that moves between the first call and the offer. BEG gets that in writing before sourcing begins.
Milestone Billing Against Contingency
The $175,140 May 2025 median for computer and information systems managers sets the contingency baseline: $35,028 at 20 percent, $43,785 at 25 percent. Against that, BEG's flat Tier IV fee, $19,080 to $22,896, works out to 54 to 65 percent of the lower figure, and the gap widens further once the offer clears the median, which it usually does at this level. BLS OEWS
What the Math Shows at Director Level Pay
Priced at the level this seat is usually offered, the gap widens. At the $220,730 75th percentile, a 20 percent contingency fee is $44,146 and BEG is 43 to 52 percent of it. Information employers pay a $200,510 median for the same code, closer still to where this seat typically lands, and the arithmetic only improves from there. BLS OEWS
Direct Hire, Contingency, or Staffing
This seat owns a company wide program and vendor contracts that outlive any single engagement, which makes a temporary or contract placement a poor structural fit.
| Model | Who employs | How you pay | Right when |
|---|---|---|---|
| BEG, direct hire | You, from the director’s start date | Installments totaling $19,080 to $22,896, locked in at the offer stage regardless of final pay | You need one accountable owner for the program, the budget and vendor contracts, not a rotating name |
| Contingency recruiter | You | Typically 20 to 25 percent of first year pay, invoiced on the director’s start date | Your executive team already agrees on the reporting line and can validate program experience without a specialist |
| Staffing agency | The agency, which keeps the director on its own payroll | An hourly rate carrying the agency’s markup | You need short term coverage during a transition, not the person who will own the audit calendar going forward |
Vendor contracts and audit calendars need one accountable owner, not a contractor who reports to a staffing agency. See the rest of the ladder on the cybersecurity hub.
FAQ
The security program company wide: policy, the risk register, the budget, vendor contracts, the audit and compliance calendar, and the managers under this seat. The executive seat and the board relationship sit above it.
It should. NIST’s Cybersecurity Framework 2.0 is the published reference most programs are built against, with community profile templates and informative references mapping it to other NIST resources.
A fixed Tier IV milestone, $19,080 to $22,896, agreed before sourcing begins rather than calculated as a share of whatever base the director accepts.
The seat is defined by whom it reports to. A director under a CIO with no CISO is functionally a CISO without the title at director pay, and candidates who ask about the reporting line drop out when the answer shifts.
A security manager owns one team and its rota. This seat owns the company wide program, the budget, vendor contracts and the audit calendar, and manages other managers rather than engineers directly.
This seat reports to a CISO or a CIO and runs the program underneath them. A VP or CISO holds the executive seat itself, with budget negotiation and board exposure this seat does not carry.
A bachelor’s degree in computer science or IT plus five years or more of related experience, with some employers requiring or preferring a graduate degree at this level.
Yes. Information companies pay a $200,510 median for the closest manager code, finance and insurance $182,510 and computer systems design $179,510, all above the $175,140 national figure.
Against the $175,140 median, BEG's fee of $19,080 to $22,896 is 54 to 65 percent of a 20 percent contingency fee, and against the $220,730 75th percentile it is 43 to 52 percent.
The staffing agency, not you, employs the contractor, which does not fit a seat that signs vendor contracts and owns an audit calendar on the company’s behalf. BEG places direct hire only.
Setting policy, maintaining the risk register, managing the security budget, negotiating vendor contracts and running the audit and compliance calendar, all reporting up through a CISO or CIO.
The executive seat itself and direct board accountability sit with a VP of security or a CISO. This seat runs the program underneath that seat, not in place of it.
Compare this to a security manager, who reports into this seat, or a VP of security, who this seat often reports to. The complete cybersecurity ladder sits on the placement hub.
More cybersecurity placement
Ready?
Answer a few questions, get your exact number in about 90 seconds. No call required, no commitment.
See your exact placement price - no call required