
Vice President, Chief Information Security Officer, CISO
Posted 21 hours ago

Posted 21 hours ago
This is a fully remote position, open to applicants in North Carolina.
• Direct the enterprise cybersecurity strategy, governance, risk management, and security operations program for the organization.
• Act as a senior cybersecurity consultant to executive leadership, the Board of Directors, and the Audit Committee.
• Create and implement a multi-year enterprise cybersecurity strategy that aligns with business goals, regulatory requirements, and risk tolerance.
• Formulate cybersecurity policies, standards, controls, and governance frameworks using guidelines such as NIST, CIS Controls, and ISO 27001.
• Define accountability for cybersecurity across corporate functions, brands, technology teams, franchise environments, and third-party providers.
• Present consistent cybersecurity scorecard outcomes and report on posture, risks, incidents, control maturity, initiatives, and remediation efforts.
• Lead the identification, assessment, prioritization, treatment, and monitoring of enterprise cybersecurity risks.
• Supervise compliance with SOX, PCI DSS, privacy, and contractual obligations while supporting audit remediation efforts.
• Provide executive oversight for security monitoring, detection, threat intelligence, investigation, containment, and incident response activities.
• Manage SIEM, SOAR, EDR/XDR, email security, cloud security, data protection, and interactions with managed security providers.
• Oversee major cybersecurity incident response, crisis management processes, post-incident evaluations, and root-cause analysis.
• Establish governance for identity lifecycle management, multifactor authentication, privileged access, access reviews, and segregation of duties.
• Direct enterprise vulnerability and exposure management along with risk-based remediation efforts.
• Implement controls to protect confidential, personal, financial, employee, customer, and franchisee information.
• Provide cybersecurity oversight for cloud adoption, applications, digital products, technology changes, artificial intelligence, and emerging technologies.
• Establish governance for the secure and responsible use of artificial intelligence, while monitoring AI-related risks.
• Manage third-party cybersecurity risk, including due diligence, assessments, contracting, monitoring, and reassessment processes.
• Oversee cybersecurity due diligence and risk planning for mergers, acquisitions, integrations, divestitures, and transition-service agreements.
• Define cyber-resilience requirements and supervise ransomware preparedness, backup protection, recovery access, and cyber-recovery testing.
• Lead cybersecurity awareness initiatives, phishing simulations, and role-specific training programs.
• Build and nurture the cybersecurity organization.
• Manage the cybersecurity budget, vendors, managed security providers, and strategic partnerships.
• Bachelor’s degree in cybersecurity, information systems, computer science, engineering, business, risk management, or a related discipline; advanced degree preferred.
• A minimum of fifteen years of progressive experience in cybersecurity, technology risk, or related fields.
• Extensive experience leading an enterprise cybersecurity program within a complex, distributed, regulated, or publicly traded organization.
• Proven experience in advising executive leadership, Boards, and Audit Committees.
• In-depth knowledge of cybersecurity frameworks, security operations, incident response, identity and access management, vulnerability management, cloud security, data protection, third-party risk, AI security governance, and regulatory compliance.
• Experience in supporting SOX IT general controls, audits, remediation programs, and business transactions.
• Proven track record in managing cybersecurity teams, budgets, vendors, and managed security service providers.
• CISSP or CISM certification is required or highly preferred.
• Additional certifications such as CRISC, CISA, CCSP, GIAC, or equivalent credentials are advantageous.
• Preferred experience in retail, automotive services, franchise, hospitality, restaurant, or other multi-location consumer-facing industries.
• Experience working with organizations that have multiple brands, decentralized operations, and complex third-party partner ecosystems is preferred.
• Health and wellness benefits.
• Paid time off.
• Holiday pay.
• Early access to 50% of earned wages at any time through the myFlexPay program.
• Supplemental pay types may include commissions or bonus incentives, depending on the role.
Nous Research
Akamai Technologies
Deutsche Telekom IT Solutions HU
CBIZ
Get handpicked remote jobs straight to your inbox weekly.