Chief Information Security Officer (CISO)

Seneca Resources

Birmingham (AL)

Hybrid

USD 210,000 - 270,000

Full time

33 hours ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Relocation assistance

Job summary

Seneca Resources is seeking a Chief Information Security Officer to lead our global cybersecurity, risk, and resilience efforts from a Birmingham-hybrid location with relocation assistance. This executive will report to senior leadership and the Board, embedding security into business strategy and growth.

The CISO will shape enterprise strategy across IAM, data protection, cloud security, incident response, and regulatory compliance; build a high-performing team; and translate risk for the

Qualifications

  • Bachelor's degree in Cybersecurity, Computer Science, Information Systems, Information Technology, or a related field.
  • Master's degree preferred.
  • 15+ years of cybersecurity, information security, risk management, or technology leadership experience.
  • Experience serving in senior cybersecurity leadership roles within public companies or regulated enterprises.

Responsibilities

  • Develop and execute the enterprise-wide information security and cybersecurity strategy aligned with business objectives, growth initiatives, and risk tolerance.
  • Lead governance, risk, and compliance programs across the organization including regulatory requirements.
  • Provide executive-level reporting on cyber risk, financial exposure, and regulatory obligations to leadership and Board.
  • Oversee security operations, threat detection, vulnerability management, incident response, and security engineering.
  • Define and modernize IAM strategies including PAM and CIAM with least-privilege principles.
  • Drive data protection, privacy, cloud security, and crisis management across the enterprise.

Skills

Executive leadership
Cybersecurity strategy
GRC expertise
IAM & PAM
Board communications
Budget management

Education

Bachelor's degree in Cybersecurity or related field
Master's degree preferred

Job description

Position Title: Chief Information Security Officer (CISO)

Location: Hybrid in Birmingham, AL (relocation assistance offered)

Position Status: Direct Hire

Lead Enterprise Security Strategy and Business Resilience

We are seeking a Chief Information Security Officer (CISO) to lead and evolve our global cybersecurity, identity, risk, compliance, and resilience capabilities. This executive will serve as a trusted advisor to senior leadership and the Board, ensuring cybersecurity is embedded into business strategy, operational excellence, digital innovation, and long-term growth.

The successful candidate will bring deep expertise across Cybersecurity, Information Security, IAM, Cyber Defense, Governance Risk & Compliance (GRC), Data Protection, Cloud Security, AI Security, Incident Response, and Regulatory Compliance, while demonstrating the ability to translate complex security risks into practical business decisions.

Key Responsibilities
Enterprise Cybersecurity Strategy & Leadership
  • Develop and execute the enterprise-wide information security and cybersecurity strategy aligned with business objectives, growth initiatives, and risk tolerance.
  • Lead and continuously mature the Information Systems Security (ISS) operating model, including governance, architecture, cyber defense, identity and access management, compliance, privacy, data protection, application security, and incident response.
  • Serve as the organization's senior cybersecurity advisor to executive leadership, Board members, and key stakeholders.
  • Establish cybersecurity priorities, investment strategies, and roadmaps that balance risk reduction with business agility.
  • Design and maintain enterprise cybersecurity governance frameworks, including risk appetite, control ownership, exception management, executive escalation, and board reporting.
  • Create risk prioritization methodologies that connect cybersecurity remediation activities to business impact, customer commitments, regulatory requirements, and operational resilience.
  • Translate technical vulnerabilities and cyber threats into business-focused risk assessments and investment decisions.
  • Ensure audit readiness through effective controls, evidence management, and governance processes.
Board, Executive & Regulatory Engagement
  • Provide executive-level reporting that clearly communicates cyber risk, financial exposure, operational impact, customer trust implications, and compliance obligations.
  • Lead cybersecurity readiness and governance activities supporting public company reporting requirements.
  • Oversee SEC cybersecurity disclosure readiness, including incident materiality assessments, executive decision support, legal partnership, disclosure documentation, and post-incident reviews.
  • Advise leadership during significant cyber events and business continuity situations.
Security Operations & Cyber Defense
  • Oversee enterprise cyber defense capabilities including threat detection, incident response, vulnerability management, security operations, and security engineering.
  • Drive continuous improvement of enterprise security monitoring and defensive controls.
  • Lead cross-functional response efforts during cybersecurity incidents, partnering with Legal, Communications, HR, Finance, Operations, and Technology teams.
  • Strengthen ransomware preparedness, cyber resilience, crisis management, and recovery planning capabilities.
Identity & Access Management (IAM)
  • Define and execute enterprise IAM strategy, including Privileged Access Management (PAM), Customer Identity and Access Management (CIAM), access governance, identity lifecycle management, and least-privilege principles.
  • Modernize identity controls to support cloud platforms, digital experiences, acquisitions, and emerging technologies.
  • Improve access certification, entitlement management, and account governance processes.
Compliance, Privacy & Risk
  • Lead global compliance programs and regulatory requirements including SOX, PCI-DSS, GDPR, privacy regulations, and other applicable frameworks.
  • Oversee third-party risk management, vendor security assessments, contractual cybersecurity requirements, and supply chain security practices.
  • Maintain enterprise security policies, standards, procedures, and controls aligned with industry best practices.
Cloud, Data Protection & Emerging Technology Security
  • Partner with business and technology leaders to secure critical platforms including eCommerce, supply chain, cloud services, analytics environments, engineering systems, and customer-facing technologies.
  • Define enterprise security requirements for AI-enabled technologies, automation platforms, and emerging digital capabilities.
  • Lead initiatives focused on data protection, data loss prevention (DLP), secure cloud adoption, and privacy protection.
  • Establish governance for responsible AI usage, model security, vendor risk management, monitoring, and data safeguards.
Mergers & Acquisitions (M&A)
  • Define cybersecurity requirements for acquisition due diligence, integration planning, and post-close risk management.
  • Establish security baselines for newly acquired entities, including network security, endpoint protection, identity governance, vulnerability management, and regulatory compliance.
  • Support business expansion while maintaining consistent enterprise security standards.
Talent Leadership & Organizational Development
  • Build, develop, and retain a high-performing, diverse cybersecurity organization.
  • Lead and mentor cybersecurity leaders, technical specialists, and strategic partners across global operations.
  • Foster a security-first culture that encourages collaboration, accountability, continuous learning, and innovation.
Required Qualifications
Education
  • Bachelor's degree in Cybersecurity, Computer Science, Information Systems, Information Technology, or a related field.
  • Master's degree preferred.
Experience
  • 15+ years of progressive cybersecurity, information security, risk management, or technology leadership experience.
  • Experience serving in a senior cybersecurity leadership role within a publicly traded, highly regulated, or large-scale enterprise environment.
  • Demonstrated success leading enterprise cybersecurity transformations across multiple business units, subsidiaries, or geographic regions.
  • Proven experience presenting to executive leadership teams, Boards of Directors, Audit Committees, and regulators.
Preferred Expertise
The ideal candidate will have demonstrated expertise in:
  • Enterprise Cybersecurity Strategy
  • Information Security Leadership
  • Governance, Risk & Compliance (GRC)
  • Identity & Access Management (IAM)
  • Privileged Access Management (PAM)
  • Customer Identity & Access Management (CIAM)
  • Security Operations (SOC)
  • Incident Response & Crisis Management
  • Application Security
  • Data Protection & Privacy
  • Zero Trust Security Architecture
  • Third-Party Risk Management
  • Cyber Resilience & Business Continuity
  • AI Security & Governance
  • Regulatory Compliance (SOX, PCI-DSS, GDPR)
  • M&A Cybersecurity Integration
  • Executive & Board Communications
  • Exceptional executive presence and communication skills.
  • Ability to influence and drive strategic decisions across business and technology functions.
  • Strong financial acumen and experience managing large cybersecurity investments and budgets.
  • Proven ability to build high-performing teams and develop future leaders.
  • Effective collaborator capable of aligning security initiatives with business growth, customer experience, operational excellence, and innovation.
  • Demonstrated success translating complex technical challenges into practical business solutions.
Preferred Certifications
One or more of the following certifications are highly desirable:
  • CISSP (Certified Information Systems Security Professional)
  • CISM (Certified Information Security Manager)CRISC (Certified in Risk and Information Systems Control)
  • CISA (Certified Information Systems Auditor)
  • CCSP (Certified Cloud Security Professional)
  • Equivalent executive cybersecurity certifications
About Seneca Resources:

At Seneca Resources, we are more than just a staffing and consulting firm, we are a trusted career partner. With offices across the U.S. and clients ranging from Fortune 500 companies to government organizations, we provide opportunities that help professionals grow their careers while making an impact.

When you work with Seneca, you’re choosing a company that invests in your success, celebrates your achievements, and connects you to meaningful work with leading organizations nationwide. We take the time to understand your goals and match you with roles that align with your skills and career path. Our consultants and contractors enjoy competitive pay, comprehensive health, dental, and vision coverage, 401(k) retirement plans, and the support of a dedicated team who will advocate for you every step of the way.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information Technology Security Specialist
Information Technology Security Specialist

Seneca Resources • Virginia (MN)

Remote
USD 120,000 - 160,000
Competitive pay
Health, dental, and vision coverage
401(k) retirement plans
+1
Chief Information Security Officer
Chief Information Security Officer

The Security Executive Council • Chicago (IL)

On-site
USD 150,000 - 250,000
Base salary
Incentive bonus opportunities
Medical, dental, vision options
+1
Chief Information Security Officer
Chief Information Security Officer

The Security Executive Council • Jacksonville (FL)

Hybrid
USD 180,000 - 280,000
Medical, dental & vision insurance
401(k) with company match
Employer paid life insurance and AD&D
+7
Chief Information Security Officer - Southern NH- Hybrid
Chief Information Security Officer - Southern NH- Hybrid

Incendia Partners • Nashua (NH)

Hybrid
USD 150,000 - 200,000
CISO
CISO

ECS • Sierra Vista (AZ)

On-site
USD 180,000 - 240,000
Chief Information Security Officer
Chief Information Security Officer

Private Company • Arlington (VA)

On-site
USD 150,000 - 200,000
Cybersecurity Advisor - Senior
Cybersecurity Advisor - Senior

MISSION ONE, LLC • Virginia (MN)

On-site
USD 110,000 - 150,000
401(k) matching
Dental insurance
Health insurance
+2
Chief Information Security Officer
Chief Information Security Officer

ITAC Solutions • Birmingham (AL)

On-site
USD 200,000 - 230,000
Board seat at Audit Committee
Ground-floor security governance role
Broad governance scope
+1
Principal Architect (AI, Security & Emerging Technologies)
Principal Architect (AI, Security & Emerging Technologies)

Seneca Resources • Birmingham (AL)

Hybrid
USD 180,000 - 240,000
CISO (Chief Information Security Officer)
CISO (Chief Information Security Officer)

Versa Networks • United States

Hybrid
USD 300,000 - 400,000
Competitive Salary & Incentives
Health & Wellness
PTO & Holidays
+5