
Regional Information Security Officer
Posted Sep 10

Posted Sep 10
This is a fully remote position, open to applicants in New York.
• Act as an independent second line of defense for Corporate Information Security in the region.
• Develop and implement information security policies, standards, and procedures.
• Analyze and interpret CSOPs, SSOPs, and various information security documents and directives.
• Guide regional security teams in the execution and enhancement of security standards and processes.
• Communicate and align information security strategies, programs, and services with business stakeholders.
• Oversee and enhance the regional security posture and maturity.
• Provide advice on principles such as least privilege, need-to-know, security-by-design, and security-by-default.
• Ensure compliance with ZEISS security standards for M&A projects and post-merger integrations.
• Evaluate security concepts for central business-supporting functions and regional needs.
• Manage regional incident tickets and service requests.
• Engage in security risk management and aggregation of first-line risks.
• Assist in regional incident response and facilitate the resolution of gaps and vulnerabilities.
• Collaborate with CIRT/SOC, CIT, regional IT, local IT, and Business IT during security incidents.
• Act as the primary escalation contact for regional information security matters.
• Participate in CIDA for regional security incidents.
• Conduct regional investigations, eDiscovery, and digital evidence gathering and analysis.
• Coordinate litigation holds with HR and Legal.
• Assess and authorize regional information security requirements, holding veto rights for critical risks.
• Evaluate project risks and establish security requirements, including those for M&A integrations.
• Direct local security assessments and undertake on-site compliance inspections.
• Support regulatory certifications and compliance, such as CMMC, ISO 27001, TISAX, HIPAA, CyberEssentials, and NIS2.
• Assess local regulatory requirements and provide guidance on cybersecurity modifications.
• Monitor regional information security status, KPIs, and KRIs.
• Identify business risks and develop mitigation strategies.
• Coordinate physical and facility security matters with Corporate Health & Safety.
• Assist BISO in reviewing information security contract amendments and security questionnaires.
• Propose regional security awareness initiatives and support Corporate InfoSec programs.
• Bachelor's degree in information security, information technology, engineering, cybersecurity, natural sciences, technology, or a related field.
• At least 10 years of experience in information security, IT security, or a related discipline.
• Demonstrated experience in a leadership role within information security, preferably at a regional or global level.
• Familiarity with technology-driven industries, ideally in manufacturing, healthcare, or other regulated sectors.
• Understanding of international and regional regulatory requirements and standards in cybersecurity and data protection.
• Practical experience with cybersecurity frameworks such as NIST and ISO 27001.
• Knowledge of risk management methodologies.
• Proven ability to manage security projects from start to finish.
• Capability to prioritize tasks and handle multiple projects at once.
• Experience collaborating with cross-functional teams and interacting with senior leadership.
• CISSP certification is a plus.
• Performance bonus or sales commissions.
• Medical plans.
• Vision coverage.
• Dental coverage.
• 401k matching.
• Employee Assistance Programs.
• Vacation and sick pay.
• Retirement savings plan.
• Paid time off.
WorkOS
Fortive
Brown and Caldwell
Galileo
Get handpicked remote jobs straight to your inbox weekly.