Job Title: Chief Information Security Officer
Location: US-NJ-Princeton
Travel Required: Minimal
Overview:
The CISO is responsible for maintaining and maturing the enterprise-wide information security management program to ensure that information assets, intellectual property, and critical infrastructure are adequately protected.
Responsibilities:
- Oversee the development, implementation, and advancement of the company-wide Information Security program:
- Facilitate appropriate resource allocation and increase the efficacy of the program.
- Security organization development.
- Ensure alignment with Information Security Standards, such as ISO 27001/27002, COBIT.
- Develop, implement, and publish global information security standards, policies, and guidelines.
- Develop business-relevant metrics to measure the efficiency and effectiveness of the information security management program.
- Mentoring and management of internal security personnel.
- Security incident response management.
- Creation and implementation of Information Security Awareness programs.
Desired Experience:
Must have a solid understanding of information security technologies, methods, and risk management practices typically gained in 7 to 10 years of progressive information security management and/or risk management experience.
- Expert knowledge of security and control frameworks such as ISO 27001, ISO 27002, COBIT, ITIL.
- Ability to relate business requirements and risk to technology implementations for security-related issues.
- Knowledge of best-practice methodologies, tools, and technologies for policy development and implementation, role-based authorization, authentication technologies, and defending against security attacks.
- Excellent communication and presentation skills.
- Demonstrated ability to serve as an effective member of the senior management team and communicate security concepts to technical and non-technical audiences.
- High level of personal integrity, professionalism, and judgment in handling confidential matters.
Desired Certifications:
Information Security certifications such as CISSP or CISM are required, with CISSP highly preferred.