
Deputy CISO
Posted Sep 9

Posted Sep 9
This is a fully remote position, open to applicants in United States.
• Act as the senior operational partner and second-in-command to the CISO within the Information Security organization.
• Oversee the daily operations of the department, which includes coordinating team meetings, leadership discussions, one-on-ones, project reviews, status updates, and executive briefings.
• Lead, mentor, and cultivate the development of team members focused on security, IT, cloud, compliance, and risk.
• Foster a culture of accountability and execution throughout the security organization.
• Serve as the representative for the security organization when interacting with executives, customers, auditors, legal, privacy, engineering, product teams, IT, and business stakeholders.
• Provide the CISO with insights regarding department performance, project status, risks, obstacles, resource requirements, and critical decisions.
• Formulate and enhance security strategies that align with business objectives, customer needs, regulatory demands, and industry best practices.
• Set security outcomes, key performance indicators (KPIs), dashboards, quarterly business reviews (QBRs), and executive reporting mechanisms.
• Lead initiatives to improve maturity across areas such as vulnerability management, incident response, identity and access management, endpoint security, cloud security, managed detection and response (MDR)/Security Operations Center (SOC) operations, governance, risk management, compliance (GRC), IT operations, and security engineering.
• Manage projects from initiation to completion, ensuring clarity on ownership, deadlines, milestones, dependencies, decisions, risks, and subsequent steps.
• Maintain project tracking systems, dashboards, Jira/Confluence organization, timelines, meeting documentation, and executive summaries.
• Hold project owners accountable for their commitments, timely updates, deadlines, and follow-through on tasks.
• Lead preparations for internal and external audits, including response coordination, evidence gathering, remediation, and compliance activities.
• Supervise compliance initiatives for SOC 2, ISO 27001, and ISO 42001 alongside associated control frameworks.
• Collaborate with Legal, Privacy, Finance, IT, Engineering, Product, and business leaders on governance activities.
• Assist in managing or enhancing the risk committee, ensuring that risks are identified, documented, prioritized, tracked, and addressed effectively.
• Maintain policies, standards, procedures, and controls that safeguard company and customer data.
• Serve as a liaison for auditors, customers, regulators, vendors, and internal stakeholders.
• Coordinate incident response efforts, including communication, containment, recovery, and post-incident improvements.
• Conduct and oversee risk assessments, threat modeling, vulnerability management, and security audits.
• Guide secure cloud architecture and governance across platforms such as AWS, Azure, GCP, or similar environments.
• Assess tools, vendors, services, and resource requirements.
• Promote continuous improvement through automation, workflows, documentation, and accountability.
• Over 10 years of progressive experience in cybersecurity, IT, security operations, cloud security, compliance, risk management, or related technical leadership roles.
• More than 5 years of experience in people leadership, encompassing team management, individual meetings, performance expectations, and departmental operational rhythms.
• Demonstrated ability to manage a security department or significant security program with minimal oversight.
• Strong practical understanding of security, IT, cloud, compliance, privacy, and risk operational frameworks.
• Experience in rebuilding or enhancing a security program, including its controls, processes, metrics, governance, and reporting structures.
• Proven experience in managing audits, compliance programs, gathering evidence, tracking controls, remediation efforts, and executive communications.
• Excellent skills in project and program execution, including ownership of deadlines, dependencies, priorities, obstacles, and cross-functional follow-through.
• Ability to articulate complex security and risk topics clearly to technical, non-technical, executive, customer, and board-level audiences.
• Experience collaborating with Legal, Privacy, Product, Engineering, IT, Finance, Sales, Customer Success, and executive leadership.
• Strong judgment, discretion, urgency, ownership, and decision-making capabilities in uncertain situations.
• Familiarity with Jira, Confluence, dashboards, executive reporting, QBRs, and operational metrics.
• U.S. Person status as defined under ITAR: U.S. citizen, lawful permanent resident, refugee admitted to the U.S., or individual granted asylum by the U.S. government.
• Successfully pass a pre-employment background check.
• Verify identity and eligibility to work in the United States upon hiring.
• Preferred: experience in SaaS, cloud-first environments, managed security services, MDR, or technology-driven settings.
• Preferred: familiarity with SOC 2, ISO 27001, PCI, HIPAA, NIST, GDPR, CCPA, and ISO 42001 standards.
• Preferred: experience with cloud security architecture and governance on AWS, Azure, or GCP platforms.
• Preferred: knowledge of GRC platforms, ServiceNow, SIEM, EDR, vulnerability management platforms, identity platforms, and security operations tools.
• Preferred: strong financial acumen, including budget planning, vendor management, resource allocation, and headcount planning.
• Preferred: previous roles as a Deputy CISO, Director of Security, VP of Security, or Head of Security Operations.
• Bonus
• Stock options
• Medical, dental, vision, and disability insurance
• Flexible Time Off (FTO)
• 12 company holidays
• Sick leave
• 8-Weeks Paid Parental Leave
• Unique professional development benefits with annual “development dollars”
• Wellness contests and monthly educational programs
• 401(K) retirement program
• Disability accommodations available upon request
• Option for remote work from a home office when not at a corporate location
Budderfly
St. Croix Hospice
GuestReady
Academy of Art University School of Game Development
Get handpicked remote jobs straight to your inbox weekly.