{"21443370":{"jobPath":"/jobs/21443370/risk-manager-of-aviation-capital-portfolio","source":"naylor","job":"21443370","jobTitle":"Risk Manager of Aviation Capital Portfolio"},"21451717":{"jobPath":"/jobs/21451717/information-technology-specialist","source":"naylor","job":"21451717","jobTitle":"Information Technology Specialist"},"21444066":{"jobPath":"/jobs/21444066/it-support-specialist","source":"naylor","job":"21444066","jobTitle":"IT Support Specialist"},"21449231":{"jobPath":"/jobs/21449231/security-officer","source":"naylor","job":"21449231","jobTitle":"Security Officer"},"21430580":{"jobPath":"/jobs/21430580/executive-director-of-security","source":"naylor","job":"21430580","jobTitle":"Executive Director of Security"},"21443229":{"jobPath":"/jobs/21443229/director-legislative-government-relations","source":"naylor","job":"21443229","jobTitle":"Director, Legislative & Government Relations"},"21448635":{"jobPath":"/jobs/21448635/information-technology-technician","source":"naylor","job":"21448635","jobTitle":"Information Technology Technician"},"21446731":{"jobPath":"/jobs/21446731/it-client-support-specialist","source":"naylor","job":"21446731","jobTitle":"IT Client Support Specialist"},"21446610":{"jobPath":"/jobs/21446610/it-security-journey-cyber-security-analyst","source":"naylor","job":"21446610","jobTitle":"IT Security ? Journey - Cyber Security Analyst"},"21446611":{"jobPath":"/jobs/21446611/administrative-services-manager-b-safety-and-security","source":"naylor","job":"21446611","jobTitle":"Administrative Services Manager B - Safety and Security"},"21443188":{"jobPath":"/jobs/21443188/chief-audit-executive","source":"naylor","job":"21443188","jobTitle":"Chief Audit Executive "},"21446675":{"jobPath":"/jobs/21446675/it-academic-applications-director-heo-department-of-instructional-computing-and-information-technology-icit","source":"naylor","job":"21446675","jobTitle":"IT Academic Applications Director (HEO) -Department of Instructional Computing and Information Technology (ICIT)"},"21444234":{"jobPath":"/jobs/21444234/library-it-devops-engineer","source":"naylor","job":"21444234","jobTitle":"Library IT DevOps Engineer"},"21446595":{"jobPath":"/jobs/21446595/it-architect-level-1-provisional","source":"naylor","job":"21446595","jobTitle":"IT Architect Level 1 - Provisional"},"21446199":{"jobPath":"/jobs/21446199/director-of-treasury-risk","source":"naylor","job":"21446199","jobTitle":"Director of Treasury & Risk"},"21441045":{"jobPath":"/jobs/21441045/outreach-focused-assistant-professor-in-community-nutrition-and-food-security","source":"naylor","job":"21441045","jobTitle":"Outreach-Focused Assistant Professor in Community Nutrition and Food Security"},"21449620":{"jobPath":"/jobs/21449620/it-technician","source":"naylor","job":"21449620","jobTitle":"IT Technician"},"21449004":{"jobPath":"/jobs/21449004/senior-security-officer-hs","source":"naylor","job":"21449004","jobTitle":"Senior Security Officer (HS)"},"21448133":{"jobPath":"/jobs/21448133/director-audit-and-reporting","source":"naylor","job":"21448133","jobTitle":"DIRECTOR-AUDIT AND REPORTING"},"21444292":{"jobPath":"/jobs/21444292/advisor-risk-management","source":"naylor","job":"21444292","jobTitle":"Advisor, Risk Management"},"21442548":{"jobPath":"/jobs/21442548/information-technology-architect","source":"naylor","job":"21442548","jobTitle":"Information Technology Architect"},"21444786":{"jobPath":"/jobs/21444786/security-officer-part-time","source":"naylor","job":"21444786","jobTitle":"SECURITY OFFICER PART-TIME"},"21447811":{"jobPath":"/jobs/21447811/analyst-security-operations-and-intelligence-center","source":"naylor","job":"21447811","jobTitle":"Analyst, Security Operations and Intelligence Center"},"21443633":{"jobPath":"/jobs/21443633/strategic-sourcing-specialist-it","source":"naylor","job":"21443633","jobTitle":"Strategic Sourcing Specialist - IT"},"21446503":{"jobPath":"/jobs/21446503/airport-security-coordinator","source":"naylor","job":"21446503","jobTitle":"AIRPORT SECURITY COORDINATOR"}}
Salary commensurate with experience and internal equity.
Required Education:
4 Year Degree
Chief Information Security Officer
Primary Purpose of Position
The Chief Information Security Officer (CISO) is a senior executive and strategic business partner responsible for establishing and leading a comprehensive, enterprise-wide information security and risk management program. The CISO provides the vision and leadership required to protect the organization’s information assets, intellectual property, and business operations against evolving digital threats.
Serving as a trusted advisor to the executive team and the Board of Directors, the CISO ensures that the security strategy is fully aligned and embedded in the broader business strategy. More than a guardian of digital assets, this leader is a key enabler of innovation, responsible for building a resilient and trustworthy digital environment that empowers the organization to achieve its goals, win customer confidence, seize new market opportunities securely, and act as a catalyst for sustainable, risk-aware growth.
Key Domains of Responsibility
Strategic Leadership & Governance: Lead the development and execution of the enterprise security vision, strategy, and governance framework in alignment with business objectives. Serve as the primary security advisor to the C-suite and Board of Directors, translating complex technical risks into clear business implications and reporting on the enterprise security posture.
Enterprise Risk & Compliance Management: Lead a holistic digital risk management program, encompassing technology, data, and third-party/supply chain risks. Ensure and demonstrate compliance with applicable legal, statutory, and regulatory requirements (e.g., GDPR, CCPA, HIPAA, SOX, PCI DSS) in collaboration with legal and compliance teams. Lead and maintain a robust Third-Party Risk Management (TPRM) program.
Security Operations & Resilience: Provide executive oversight of Security Operations Center (SOC) functions, including threat detection, vulnerability management, and incident response capabilities. Lead crisis management during security incidents. Ensure robust business continuity and disaster recovery plans are in place and regularly tested through exercises such as tabletop simulations.
Data Security & Governance: Partner with the Chief Data Officer, General Counsel, and other stakeholders to develop and enforce data governance, classification, and privacy policies. Implement technical controls, including encryption and Data Loss Prevention (DLP) solutions, to safeguard critical information assets.
Technology & Innovation Security: Drive the security strategy for both foundational and emerging technologies to enable secure innovation.
Zero Trust Architecture: Lead a multi-year, enterprise-wide transformation toward Zero Trust architecture, enforcing principles of least privilege, micro-segmentation, and continuous verification.
Cloud Security: Architect and manage a comprehensive security program for multi-cloud and hybrid environments, focusing on secure configuration and cloud-native protection mechanisms.
AI Security & Governance: Establish a robust AI governance framework to manage risks associated with artificial intelligence. Develop policies to mitigate “Shadow AI” risks from unauthorized public tools and secure the proprietary AI/ML supply chain from threats like data poisoning.
DevSecOps: Champion a “shift-left” cultural transformation, partnering with engineering teams to embed automated security controls and a “security as code” mindset into the CI/CD pipeline.
Culture & Team Leadership: Build, mentor, and lead a high-performing, diverse cybersecurity team. Address skill gaps and foster a culture of continuous learning. Champion a pervasive culture of security awareness and shared responsibility across the organization through continuous training and simulated phishing exercises.
Nonessential Duties
Perform other duties as assigned.
Supervisory Responsibilities
Directly supervise a group of 5-7 professional staff.
Reporting Relationship
Reports to the Chief Information Officer.
Knowledge, Skills, and Abilities
Required:
Executive Communication & Influence: World-class ability to articulate complex security concepts and risk analysis to non-technical audiences, including C-Suite and Board of Directors, in a clear, compelling, business-centric manner.
Business & Financial Acumen: Strong grasp of business operations, financial statements, and budget management, with the ability to build a compelling business case for security investments and demonstrate return on investment (ROI).
Collaborative & Empathetic Leadership: A proven “bridge-builder” with exceptional emotional intelligence and interpersonal skills, capable of fostering trust-based partnerships across all business and technology functions. A leader with “no ego” who is approachable and supportive of their team.
Strategic Vision: Ability to anticipate future threats, technological shifts, and regulatory changes, and to craft a long-term, forward-looking security vision that actively enables and supports the organization’s strategic plan.
Resilience & Decisiveness: Ability to lead with a calm, steady hand during high-stakes crises, make difficult decisions under intense pressure, and cope effectively with complexity and constant change.
Proactive Problem Solving: Possess a proactive, can-do attitude, with a passion for their work and a relentless desire to learn, improve, and solve complex challenges.
Qualifications
Required:
Bachelor’s degree in Computer Science, Information Security, Engineering, or a related field.
A minimum of 15 years of progressive experience in information security and risk management, including at least 7 years in a senior leadership capacity, managing cross-functional teams and influencing enterprise-wide strategy.
Demonstrated success in developing, implementing, and executing a strategic, comprehensive information security program that is demonstrably aligned with business goals.
Deep expertise in modern risk management methodologies and a strong command of major global compliance frameworks and regulations (e.g., NIST CSF, ISO 27001, GDPR, CCPA, HIPAA, SOX, PCI DSS).
Proven experience in architecting and securing modern technology stacks, including multi-cloud environments (AWS, Azure, GCP), Zero Trust principles, and sophisticated Identity and Access Management (IAM) solutions.
Extensive, hands-on experience with modern security operations, cyber threat intelligence, vulnerability management, and proven leadership experience in high-stakes crisis and incident response scenarios.
Working knowledge of key security technologies, including firewalls, intrusion detection/prevention systems (IDPS), Security Information and Event Management (SIEM) platforms, and encryption protocols.
Preferred:
Advanced degree, such as an MBA or a Master’s in Cybersecurity
Professional Certifications such as:
Certified Information Systems Security Professional (CISSP)
Certified Information Security Manager (CISM)
Certified in Risk and Information Systems Control (CRISC)
Certified Information Systems Auditor (CISA)
Experience developing and implementing governance and security controls for Artificial Intelligence and Machine Learning (AI/ML) systems and mitigating Shadow AI risks
Experience leading a “shift-left” cultural transformation by successfully implementing DevSecOps principles and practices in an agile development environment.
Knowledge of ethical hacking and penetration testing techniques.