- Define enterprise information security strategy and a multi-year roadmap
- Own enterprise security architecture across cloud/on-premise infrastructure, APIs, and internal applications
- Own all security policies, standards, and procedures
- Represent InfoSec at Board of Directors and executive committee meetings
- Remain accountable to external regulators, auditors, and cyber insurers
- Drive risk appetite definition and enterprise risk posture
- Manage compliance programs including SOC 2, NIST CSF, GLBA Safeguards Rule, and ISO 27001
- Oversee third-party security partners and tooling selection
- Report on security program maturity and key risk indicators
- Serve as primary liaison to Legal, Risk, and Compliance
- Provide vision and leadership for continuous security improvement
- Provide input and guidance on enterprise IT systems, business operations, and facility defenses
- Identify issues and risks in existing systems
- Direct administration of security policies, activities, and standards
- Lead development of strategic plans, goals, and policies for functional areas
- Work cross-functionally with leadership and the C-Suite to solve complex organizational problems
- Manage staffing plans, division leaders, performance standards, staff development, and strategic people management
- Lead geographically distributed teams with 2+ direct and 5+ indirect reports
- Work primarily in a sedentary office setting during the business week
Requirements
- Bachelor's Degree directly related to the position or equivalent, preferred
- Minimum 10 years progressive experience in cybersecurity
- Demonstrated breadth across security architecture, risk management, compliance, and security operations
- Minimum five years senior leadership experience
- CISSP required
- CISM, CISA, and CRISC preferred
- Proven track record of building and scaling enterprise security programs in complex, high-growth environments
- Hands-on experience with PCI DSS, SOC 2, NIST CSF, GLBA Safeguards Rule, and ISO 27001
- Deep knowledge of cloud security, including AWS, GCP, and/or Azure
- Knowledge of DevSecOps practices and modern security tooling
- Executive presence and communication skills to engage a Board of Directors and translate technical risk into strategic business terms
- Experience leading high-performing, geographically distributed teams
- Prior CISO title or equivalent accountabilities at a technology company, financial institution, or regulated fintech
- Excellent verbal and written communication skills required
- Highly organized and detail-oriented
- Ability to work in a fast-paced, metrics-driven environment required
- Proficiency in Microsoft Office Suite, Word, Excel, Wiki, collaborative cloud-based programs, and third-party software applications required
- Commitment to company values
- Ability to learn new tasks, remember processes, maintain focus, complete tasks independently, and make timely decisions
- Ability to operate standard office equipment and keyboards
- Ability to accurately perceive, distinguish, and interpret visual and audio information
- Ability to communicate detailed information verbally
- Monday–Friday business-week availability
- Travel 5% or less
Core Competencies
Demonstrates expertise in defining and implementing enterprise information security strategies, managing compliance programs, and leading high-performing teams. Proficient in risk management, security architecture, and engaging with executive leadership to drive security initiatives.
Highest-signal resume keywords
- CISSP
- Cybersecurity Leadership
- Security Architecture
- Compliance Management
- Cloud Security
ATS Optimization Keywords
Hard Skills
- Risk Management
- Security Operations
- DevSecOps Practices
- PCI DSS
- SOC 2
- NIST CSF
- GLBA Safeguards Rule
- ISO 27001
- Cloud Security (AWS, GCP, Azure)
- Enterprise Security Program Development
Soft Skills
- Executive Presence
- Communication Skills
- Organizational Skills
- Detail-Oriented
- Problem-Solving
Certifications & Qualifications
Industry Keywords
- Information Security Strategy
- Enterprise Risk Posture
- Security Policies
- Compliance Programs
- Board Engagement
- High-Growth Environments
- Geographically Distributed Teams
Tools & Technologies
- Microsoft Office Suite
- Collaborative Cloud-Based Programs
- Third-Party Software Applications