Match score not available

Chief Information Security Officer

Remote: 
Full Remote
Contract: 
Experience: 
Expert & Leadership (>10 years)
Work from: 

Offer summary

Qualifications:

Bachelor's or Master's degree in IT-based curriculum, 10 years' experience in risk management or information security, Certifications: CISM, CISSP, CISA, CRISC preferred, Deep knowledge of cybersecurity frameworks, Expertise in compliance and regulatory requirements.

Key responsabilities:

  • Provide strategic leadership for cybersecurity programs
  • Develop comprehensive cybersecurity strategies for clients
  • Identify future security and compliance challenges
  • Oversee incident response and risk assessments
  • Collaborate with senior management on security initiatives
VC3 logo
VC3 SME https://www.vc3.com/
51 - 200 Employees
See more VC3 offers

Job description

Logo Jobgether

Your missions

Application Deadline: 20 September 2024

Department: ThinkGard - Security

Location: USA - Remote

Description

Leveraging our standard technologies and process, coupled with our people and corporate structure, we deliver a unique result for our clients. Our clients will experience increased employee productivity, predictability in capital and operating expenditures, reduced downtime and risk, improved employee morale, less lost revenue, and enhanced business agility.

The Senior Virtual Chief Information Security Officer(Senior vCISO) will provide strategic leadership and oversight for the information security programs of VC3 managed clients. This role involves having a deep understanding of each client's unique business environment to develop tailored strategies that mitigate risks and align with client business objectives. The Senior vCISO is a top security expert that works with existing management and technical teams both within client environments and VC3 to manage risks and safeguard the company's and clients' data, while ensuring compliance with regulatory requirements. This role also assists in providing strategy for the Managed Security space to drive growth, delivery with consistency and excellence, and the desired level of profitability for the organization. Key focus areas are innovation, staying at or ahead of world events that are relevant, consistent excellence, proactiveness, and driving efficiency. By measuring progress and adjusting processes accordingly, the Senior vCISO keeps the clients under their purview on track.

The Managed Security department at VC3 is responsible for ensuring our clients have the right security tools, policies and processes to thrive in today's fast-moving threat landscape. They ensure that our internal teams are equipped with the training and knowledge to support our clients and make sure that effective security is a key aspect of everything we do within VC3.

In order to ensure an exceptional result, you will need to have a clear understanding of the challenges and opportunities our clients face and how our teams as a whole combine to deliver our promise. Providing services in a proactive, professional manner while ensuring key parties are kept informed is critical. We are a data driven company and analysis for decision making and overall strategy is ongoing. Culture is an integral part of working at VC3. Our company DNA represent the most important values, the ones we live by:

Our People:

Our team members are collaborative, positive, and dedicated to mutual success. Transparency isn't just a buzzword here; it's a commitment to open communication, ensuring every voice is heard and valued. Guided by our core values — Passionately Curious, Own It, Go Beyond, and Serve as One — we're here to create something extraordinary together.

Our Core Focus:

Our team members play a pivotal role in our focus: Serving those who serve with technologies for today and tomorrow that make life safe and simple. With nearly 30 years of specialized expertise, our team goes beyond conventional boundaries, delivering tailored managed services and cybersecurity solutions to our clients.

Your Growth:

We are a growth minded organization that prioritizes development, offering numerous opportunities for career advancement. Rooted in our core value of being Passionately Curious, VC3 offers a dynamic learning environment, emphasizing hands-on experiences and formal development programs that celebrate continuous learning to propel your career forward.

Key Responsibilities

  • Understand and follow "The VC3 Way". This is our set of standards and processes that produce a predictable result for the client. You must be aware of and maintain our standards.
  • Engage and provide consulting services to mid-market and enterprise clients, including:
  • Provide strategic leadership in translating complex cybersecurity concepts into non-technical terms for clients to clearly understand specific applications to their business priorities.
  • Understand and align with the client organization's overall strategy and business environment to ensure cybersecurity initiatives support business objectives
  • Lead the development and implementation of a comprehensive cybersecurity strategy for clients and VC3 that aligns with the organization's goals and objectives
  • Proactively identify and anticipate future security and compliance challenges for our clients and VC3, driving VC3 solutions
  • Partner with cross-functional teams to integrate security into product design and implementation, and to develop security solution offerings for clients.
  • Drive the creation and execution of a robust cybersecurity plan and program within client environments, ensuring alignment with industry best practices.
  • Assist in the development of the information security incident response program for the VC3 Managed Security Department.
  • Strategically develop and enhance client specific incident response programs as needed based on the development of Business Continuity and Disaster Recovery practices liaising with internal VC3 Departments as necessary.
  • Lead comprehensive cybersecurity risk assessments based on the client organization's assets, identify vulnerabilities, and recommend remediation strategies.
  • Collaborate within VC3 and with clients to assist with vendor selection, providing guidance and checklists to ensure third party security compliance.
  • Engage and provide services to VC3 as an organization, including:
  • Security Strategy & Vision:
  • Develop and implement a comprehensive information security strategy for internal operations and client-facing services.
  • Collaborate with senior management to align security initiatives with business objectives and regularly report on the status of security programs and initiatives.
  • Drive the adoption of security policies, standards, and guidelines that protect the company and its clients.
  • Risk Management:
  • Identify, evaluate, and report on information security risks in a manner that meets compliance and regulatory requirements.
  • Oversee risk assessments and mitigation strategies for both internal environments.
  • Compliance & Regulatory Oversight:
  • Ensure the organization complies with all relevant regulations, standards, and certifications (e.g., SOC II, FISMA, NIST).
  • Lead audits and assessments to maintain compliance and certification standards.
  • Incident Response & Management:
  • Establish and oversee the organization's incident response program, including detection, investigation, and remediation of security incidents.
  • Coordinate with legal, public relations, and other relevant teams to manage communication during and after a security breach.
  • Post-incident, lead efforts to identify root causes and implement changes to prevent future incidents.

Skills, Knowledge And Expertise

  • Bachelor's Degree or Master's Degree (preferred) in an IT-based curriculum, or at least 10 years' experience in risk management, information security, or programming.
  • One or more of the following qualifications: Certified Information Security Manager (CISM), Certified Information Systems Security Professional (CISSP), Certified Information systems Auditor (CISA), or Certified Risk & Information Security Controls (CRISC), Cisco Certified Internetwork Expert (CCIE) or equivalent
  • Extensive experience in cybersecurity strategy development, risk management, and program administration.
  • Deep knowledge of current common cybersecurity frameworks (CIS, NIST, MITRE ATT&CK)
  • Expertise in compliance and regulatory requirements across various industries.
  • An understanding of SIEM platforms, perimeter security, endpoint detection and response platforms, vulnerability management solutions, all aspects of IT infrastructure (compute, route/switch, security) and cloud security
  • Possesses a high level of self-motivation and initiative, consistently taking ownership of tasks and projects.
  • Demonstrate a strong sense of autonomy and resourcefulness, capable of making independent decisions and solving problems without relying heavily on coaching or direction.
  • Exhibit excellent time management and organizational skills, effectively prioritizing tasks and allocating resources to meet deadlines and achieve objectives without extensive oversight.
  • Displays a proactive and self-directed approach to learning and staying updated on industry trends, seeking out relevant information and resources to enhance their knowledge and skills.
  • Shows the ability to adapt and thrive in ambiguous or uncertain situations, quickly assessing and navigating challenges.
  • Possesses strong critical thinking and decision-making abilities, evaluating complex situations and determining the best course of action, while considering the broader organizational goals and objectives.
  • Demonstrates effective communication skills, both written and verbal, articulating ideas and expectations clearly and concisely, minimizing the need for frequent guidance or clarification.
  • Demonstrated ability to build and manage relationships with clients (internal and external) through consistent and proactive communication.
  • Extraordinarily strong interpersonal skills, able to build effective working relationships, solicit co-operation and collaborate with various stakeholders internally and externally.

Additional information you will want to know:

Additional information you will want to know:

  • Applicant selected will be subject to a criminal and department of motor vehicles background checks and must meet Criminal Justice Information Systems (CJIS) requirements post-employment
  • Travel up to 30% required
  • VC3 offers a comprehensive benefit package and 401K/RRSP company matching

Thank you for your interest in VC3. We appreciate all applications; however, only those candidates selected for an interview will be contacted.About VC3VC3 offers Managed IT Services, Private Cloud Services, Hosted VoIP, Custom Web Applications, SharePoint Consulting, and Website Design & Hosting.

VC3 has more than 25 years of experience providing a full range of Information Technology Solutions and Services to hundreds of municipalities and organizations throughout the United States and Canada. The technologies needed by our customers have changed many times over the years, but our focus has always stayed the same: connect the best technologies with our experienced and talented engineers, programmers, web designers and support specialists to deliver solutions that take our customers to the next level of productivity and results.

We pride ourselves on making IT personal, making IT easy, and getting IT right. And it all starts with our talented team that is committed to raising the bar.

Required profile

Experience

Level of experience: Expert & Leadership (>10 years)
Spoken language(s):
Check out the description to know which languages are mandatory.

Soft Skills

  • Social Skills
  • Self-Motivation
  • Adaptability
  • Proactivity
  • Verbal Communication Skills
  • Critical Thinking
  • Time Management
  • Decision Making
  • Analytical Thinking
  • Organizational Skills

Information Security Analyst Related jobs