SUMMARY
The Chief Information Security Officer oversees planning and implementation of the organization's data security programs. This includes strategy development, risk assessments and mitigation efforts and associated processes, and compliance with relevant laws and regulations. The CISO reports into the CFO as part of the team's senior leadership team. The role serves as the technical subject matter expert and authoritative voice for all cybersecurity and data protection initiatives across the organization. The CISO will drive a resilience-first approach, emphasizing prevention, rapid detection/response, and business-aligned recovery.
Key Responsibilities
1. Information Security Strategy and Policy Development
Develop and implement a comprehensive information security strategy aligned with business goals
Create, maintain, and enforce security policies, standards, and procedures
2. Risk Management and Compliance
Conduct enterprise-wide risk assessments and prioritize security initiatives based on risk exposure.
Ensure compliance with applicable laws, regulations, and industry standards (e.g., GDPR, HIPAA, PCI DSS)
3. Security Architecture and Operations
Oversee the design and implementation of secure IT architecture and network infrastructure
Monitor threat intelligence and respond to emerging cybersecurity threats
Manage security operations, including incident detection, response, and recovery
Implement Zero Trust principles across network and remote access
4. Leadership and Team Management
Lead and mentor security teams, including security analysts, engineers, and incident responders
Collaborate with other executives and departments to foster a security-aware culture
Lead incident response and disaster recovery planning to ensure minimal business disruption
5. Incident Response and Disaster Recovery
Establish and oversee incident response plans for potential cyber attacks or data breaches
Coordinate disaster recovery and business continuity planning related to information security
6. Budgeting and Resource Planning
Manage budgets for security initiatives and justify investments in technology and personnel
Evaluate new security technologies to enhance organizational security posture
Skills and Qualifications
Extensive experience in information security, risk management, and IT governance
Experience with network segmentation, resilient backup strategies, and security culture transformation
Knowledge of cybersecurity frameworks and standards (e.g., NIST, ISO 27001)
Strong leadership, communication, and strategic planning skills
Ability to balance security priorities with business objectives