
Virtual Chief Information Security Officer – vCISO
Posted Aug 28

Posted Aug 28
This is a fully remote position, open to applicants in United States.
• Assist in governance initiatives, conduct risk assessments, engage in compliance activities, and provide technical system security engineering support.
• Create, implement, and sustain cybersecurity policies, procedures, standards, security frameworks, controls, and documentation.
• Identify, evaluate, and address potential security risks in collaboration with stakeholders.
• Ensure adherence to regulatory requirements, industry standards, and best practices.
• Prepare for and engage in security audits and assessments, including SOC 2 Type II, HIPAA, and PCI compliance audits.
• Work with cross-functional teams to integrate security controls into system design and development processes.
• Conduct security architecture evaluations and offer technical guidance on effective security measures.
• Execute security assessments and penetration testing on systems, networks, and applications.
• Identify vulnerabilities, assess security flaws, and propose remediation strategies.
• Keep abreast of emerging threats, vulnerabilities, and advancements in security technologies.
• Develop and test incident response plans and procedures.
• Participate in investigations of security incidents, perform root cause analysis, and facilitate remediation efforts.
• Implement proactive security monitoring and threat detection strategies.
• Assist in the deployment and management of security monitoring tools and technologies.
• Bachelor’s degree in computer science, Information Technology, or a related discipline.
• Demonstrated experience as a Cyber Security Engineer, Security Analyst, or a similar position.
• Strong grasp of cyber security principles, risk management methodologies, and compliance frameworks.
• Comprehensive knowledge of security technologies, including firewalls, intrusion detection/prevention systems, SIEM, and vulnerability scanning tools.
• Familiarity with regulatory mandates such as GDPR and HIPAA.
• Knowledge of industry standards including NIST and ISO 27001.
• Acquainted with frameworks like COBIT and ITIL.
• Experience in interpreting cybersecurity frameworks such as NIST CSF, HIPAA HITRUST, CIS20, and CSA CSF.
• Background in system security engineering, secure software development, or secure system design.
• Proficient in conducting security assessments and vulnerability management.
• Familiarity with incident response processes and security monitoring techniques.
• Exceptional problem-solving and analytical abilities.
• Strong communication and collaborative skills.
• Relevant certifications like CISSP, CISM, CASP+, or GIAC are highly preferred.
• Availability for Monday-Friday, 8am-5pm EST business hours, with occasional after-hours work required.
• Willingness to participate in an on-call rotation and handle off-hours escalations.
• 100% remote position with no plans to return to an office.
• Generous paid time off, including paid holidays and floating holidays.
• Highly competitive and flexible medical, dental, and vision benefits tailored to your needs.
• 401(k) plan with a generous employer match.
• Customized Life and Disability insurance plans.
• Full reimbursement for approved professional certifications and career development opportunities.
• Monthly stipend for mobile phone plans and internet service.
• Opportunities for growth.
• Dynamic and collaborative work environment.
G-P
DyFlex Solutions
Papa Johns
Prelim
Get handpicked remote jobs straight to your inbox weekly.