
Chief Information Security Officer
Posted Aug 21

Posted Aug 21
This is a fully remote position, open to applicants in Alabama, +9 more states.
• Develop and oversee a cybersecurity governance framework that aligns with business objectives, regulatory requirements, client expectations, and industry standards.
• Take ownership of the information security strategy, governance, risk management, security architecture, incident preparedness, and compliance programs.
• Set security priorities and create a security roadmap based on business risks, evolving technology needs, and emerging threats.
• Provide guidance on risks, vulnerabilities, threats, and suggested mitigation strategies.
• Lead enterprise-level cybersecurity risk assessments and manage risk documentation, prioritization, remediation, or acceptance.
• Ensure compliance with PCI DSS, SOC 2, and relevant banking and financial institution regulations.
• Supervise PCI and SOC compliance initiatives, including security awareness training, weekly security scan evaluations, and ongoing compliance tasks.
• Offer leadership during regulatory examinations, client audits, penetration tests, vulnerability assessments, and third-party security evaluations.
• Manage third-party cybersecurity risk and monitor critical vendor activities.
• Oversee security architecture across applications, APIs, databases, networks, cloud environments, identity systems, endpoints, and third-party integrations.
• Define security architecture principles and standards that promote confidentiality, integrity, availability, resilience, and scalability.
• Ensure the effective functioning of firewalls, intrusion detection and prevention systems, endpoint security, encryption, data loss prevention, file integrity monitoring, vulnerability management, and security monitoring controls.
• Maintain robust identity and access management controls, including privileged access, authentication, authorization, MFA, and regular access reviews.
• Establish and manage a comprehensive vulnerability management program.
• Oversee security monitoring and detection capabilities.
• Collaborate with Technology, Network Operations, and Development teams to address vulnerabilities within risk-based timelines.
• Own the cybersecurity incident response program and regularly test documented plans, roles, escalation procedures, and communication protocols.
• Foster a security-conscious culture and ensure employees are aware of their responsibilities regarding information protection.
• Over 10 years of progressive experience in information security, cybersecurity, infrastructure security, security engineering, or related fields.
• Strong proficiency in cybersecurity governance, risk management, security architecture, incident response, vulnerability management, and security operations.
• In-depth knowledge of NIST cybersecurity frameworks, PCI DSS, and SOC 2.
• Hands-on experience with data protection, encryption, DLP, identity and access management, endpoint security, firewalls, intrusion detection/prevention, and security monitoring technologies.
• Experience collaborating with external auditors, regulators, financial institutions, clients, and third-party vendors on cybersecurity issues.
• Ability to balance security needs with business objectives and make risk-based decisions in a dynamic technology environment.
• Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, Information Systems, Engineering, or a related discipline.
• Relevant professional certifications such as CISSP, CISM, CRISC, CCSP.
• Willingness to work within CorServ's geographical footprint (AL, FL, GA, IA, KY, NE, NC, TN, TX, WI, WY).
• Company-sponsored medical, dental, and vision benefits.
• Generous paid time off (PTO) plan.
• 401k matching program.
• Flexible remote work environment.
• Competitive salary package.
GitLab
GitLab
Cisco
Lovesac
Get handpicked remote jobs straight to your inbox weekly.