Intermediate (2-5 years of experience)
Summary of the Role
The Chief Information Security Officer (CISO) is responsible for establishing and maintaining the enterprise vision, strategy, and program to ensure information assets are adequately protected. The CISO directs staff in identifying, developing, implementing, and maintaining processes across the organization to reduce information and information technology (IT) risks. They respond to incidents, establish appropriate standards and controls, manage security technologies, and direct the establishment and implementation of policies and procedures.
Required Skills
Ability to lead and motivate cross-functional, interdisciplinary teams to achieve tactical and strategic goals.
Strong analytical skills to analyze security needs and relate them to appropriate security controls.
Excellent written and verbal communication skills, including the ability to effectively communicate security and risk-related concepts to technical and nontechnical audiences.
Strong understanding of the business impact of security tools, technologies, and policies.
Strong project management, financial/budget management, scheduling, and resource management skills.
Ability to maintain a high level of discretion and personal integrity in the exercise of duties, including the ability to professionally address confidential matters.
Qualifications
Bachelor's or Master's degree in Computer Science, Information Systems, Information Security, or a related field.
Professional security management certifications such as CISSP, CISA, CISM, or equivalent.
Proven experience in a similar role, ideally in an information security position.
Knowledge of common information security management frameworks, such as ISO/IEC 27001 and NIST.
Experience with contract and vendor negotiations and management including managed services.
Experience with Cloud computing/EaaS/IaaS/PaaS/SaaS environments.
Experience with incident response and response planning.
Responsibilities
Develop, implement, and monitor a strategic, comprehensive enterprise information security and IT risk management program.
Work with the business and IT to identify, evaluate, and report on IT and information security risks in a manner that meets compliance and regulatory requirements.
Create and manage information security and risk management awareness training programs for all employees, contractors, and approved system users.
Work directly with the business units to facilitate IT risk assessment and risk management processes, and work with stakeholders throughout the enterprise on identifying acceptable levels of residual risk.
Manage the enterprise's information security organization, consisting of direct reports and indirect reports. This includes hiring, training, staff development, performance management, and annual performance reviews.
Coordinate with organization-wide compliance, risk, and legal entities to ensure that all information owned, collected, or controlled by or on behalf of the company is processed and stored in accordance with applicable laws and other global regulatory requirements.
Manage security incidents and events to protect corporate IT assets, including intellectual property, regulated data, and the company's reputation.
Monitor the external threat environment for emerging threats and advise relevant stakeholders on the appropriate courses of action.
Coordinate with the IT department to ensure alignment between security and enterprise architectures, thus coordinating the strategic planning implicit in these architectures.