
vCISO
Primary stack
Nice to have's
Job description
vCISO
Tempo
The Virtual CISO (vCISO) role combines technical expertise, strategic thinking, and leadership skills to ensure the organization's information assets are protected, risks are managed effectively, and compliance requirements are met.
About the Position
The vCISO is responsible for developing and implementing an organization's overall information security strategy and roadmap. This includes identifying security goals and objectives, assessing risks, and creating plans to mitigate them.
Responsibilities
- Develop Information Security Strategy: Identify security goals and objectives, assess risks, and create plans to mitigate them.
- Security Governance and Compliance: Ensure compliance with relevant security regulations, standards, and frameworks. Establish and maintain security policies, procedures, and guidelines, and monitor compliance with them.
- Risk Management: Identify and assess potential security risks and vulnerabilities in the organization's systems, networks, and applications. Develop risk mitigation plans and work with relevant stakeholders to implement appropriate controls.
- Incident Response and Management: Establish an incident response plan to handle and respond to security incidents and breaches effectively. Coordinate incident response activities, conduct post-incident analysis, and recommend improvements to prevent future incidents.
- Security Awareness and Training: Develop and deliver security awareness and training programs to educate employees about security best practices, policies, and procedures. Promote a culture of security within the organization.
- Vendor and Third-Party Risk Management: Assess the security posture of vendors and third-party partners, ensuring they meet the organization's security requirements. Establish and enforce security standards for third-party contracts and conduct regular audits to monitor compliance.
- Security Architecture and Technology: Advise on the selection and implementation of security technologies, such as firewalls, intrusion detection systems, encryption tools, and vulnerability management systems. Ensure that the organization's security architecture aligns with industry best practices.
- Incident Monitoring and Threat Intelligence: Oversee monitoring security events and alerts to identify potential threats and vulnerabilities. Stay updated on the latest security trends, emerging threats, and industry developments to proactively address security risks.
- Team Leadership and Collaboration: Collaborate with internal teams, such as IT, legal, and executive management, to integrate security into business processes and initiatives. Provide leadership, guidance, and mentorship to the security team if applicable.
- Continuous Improvement: Continuously assess the effectiveness of the organization's security program, identify areas for improvement, and implement necessary changes to enhance the overall security posture.
Requirements
- 10+ years of Information Security Management background, knowledge, and/or experience.
- Expert knowledge of and ability to implement technical aspects of HITRUST, HIPAA, ISO, SOC, NIST 800-171, and other compliance standards.
- Experience with SOC 2 or CMMC preferred.
- Prior history as a Qualified Security Auditor (QSA) and/or HITRUST assessor.
- Risk Management Framework (RMF) requirements.
- Relevant GRC / Audit / Security / Cloud Certifications.
- Resource management principles and techniques.
- Ability to detail unique compliance control requirements within HITRUST, & GDPR.
- Ability to demonstrate a strong understanding of network/system/application designs and virtualized environments.
- Strong leadership and communication skills.
- Ability to build and maintain relationships with customers within all layers of an organization.
- Excellent verbal and written English skills.
- Able to work independently and efficiently to meet deadlines.
- Self-motivated and detail-oriented.
We Offer
- Great experience in a global cyber security company.
- Opportunity to grow with the company in any area you choose.
- Direct contract with the American company.
- Open-minded, professional team that will be developing & supporting you.
- Paid vacation and sick leaves.
- Paid Voluntary Time Off and Mental health day.
- Paid professional training.
- Medical insurance after the integration period.
- Flexible, remote work environment😊
About the Company
Join our Team!
© Divoro. This job description was sourced from the employer's public career page. TheJob is not the employer — we index the posting and route candidates to the source. All content rights and hiring decisions belong to the employer.
Divoro is a cybersecurity company relentlessly focused on ensuring the operational resilience of our Customers against evolving cybersecurity threats.Our team is comprised of top professionals from around the world. We provide unparalleled services to our portfolio companies. Team members enjoy unprecedented opportunities to transform multiple technology companies, in a variety of industries, working alongside other world-class professionals.Our Mission:* Protect clients` assets* Insure safe business scalability* Develop and help peopleHow we do:* People* Focus* Result
More at Divoro
All 4 rolesSimilar jobs

AI First Security Manager/CSIO (part-time)
PeopleForce

AI First Security Manager/CSIO (part-time)
PeopleForce

AI First Security Manager/CSIO (part-time)
PeopleForce

AI First Security Manager/CSIO (part-time)
PeopleForce