Senior Cyber Security & Infrastructure Lead
Indexed description
Job Title: Senior Cyber Security & Infrastructure Lead
Work Arrangement: Mostly remote with travel to the corporate office once a month, potentially twice a month or as needed
Schedule: 40 hours/week; flexible schedule with the expectation that the resource manages their own workload
Time Zone: Candidates outside the Eastern Time Zone must be willing to work East Coast hours
Contract-to-Hire: Possible, but not guaranteed
Travel: Required periodically; travel expenses are supported through the client’s expense process.
Duration: 12 Months on contract with possible extension
Cybersecurity Strategy & Leadership
Own and execute the enterprise cybersecurity strategy and multi-year security roadmap.
Serve as the organization's senior cybersecurity subject-matter expert and advisor to IT and business leadership.
Translate technical cybersecurity risks into clear business impact, priorities, and investment recommendations.
Establish measurable security objectives, key risk indicators, and executive-level reporting.
Develop business cases and recommendations for security investments based on risk reduction, business value, and total cost of ownership.
Governance, Risk & Compliance
Lead the continued development and maturity of the enterprise cybersecurity program using the NIST Cybersecurity Framework and other applicable standards and leading practices.
Maintain and enforce cybersecurity policies, standards, procedures, and control frameworks.
Own the enterprise cyber risk assessment process and maintain visibility into material cybersecurity risks and remediation plans.
Partner with Legal, Internal Audit, technology teams, and business stakeholders to support regulatory, contractual, insurance, and audit requirements.
Security Operations & Incident Response
Provide leadership and oversight for enterprise security monitoring, detection, investigation, containment, and response.
Maintain and continuously improve cybersecurity incident response plans, playbooks, escalation procedures, and crisis-management processes.
Lead the organization's response to significant cybersecurity incidents and coordinate activities across technology, leadership, Legal, communications, and third parties as necessary.
Security Architecture & Engineering
Partner with infrastructure, cloud, network, application, and enterprise architecture teams to embed security into technology design and operations.
Provide security review and approval for significant technology initiatives and architectural changes.
Establish and maintain appropriate security controls across identity and access management, endpoint security, networks, cloud environments, email, data protection, and enterprise applications.
Promote secure configuration, least privilege, segmentation, encryption, and modern identity-security practices.
Evaluate cybersecurity technologies and recommend changes based on capability, risk, cost, and operational effectiveness.
Security Awareness & Culture
Own the enterprise cybersecurity awareness and education program.
Develop targeted security education for employees, technology teams, privileged users, and executives.
Use phishing exercises, awareness metrics, incident trends, and other data to identify and address areas of human risk.
Build a culture in which cybersecurity is viewed as a shared business responsibility rather than solely an IT function.
Vendor & Partner Management
Provide security oversight for strategic cybersecurity vendors, managed service providers, and technology partners.
Establish performance expectations and hold providers accountable for service quality, risk reduction, and contractual obligations.
Participate in vendor selection, contract reviews, renewals, and security-related negotiations.
Identify opportunities to simplify the security technology portfolio and improve value from cybersecurity investments.
Quals--
Required
10 years of progressive information security or cybersecurity experience, including significant responsibility for enterprise security programs.
Demonstrated experience leading cybersecurity strategy, governance, risk management, security operations, and incident response.
Strong understanding of enterprise security architecture, network security, endpoint security, cloud security, identity and access management, and data protection.
Experience implementing or operating cybersecurity programs aligned with the NIST Cybersecurity Framework or a comparable control framework.
Demonstrated experience managing vulnerability remediation and cybersecurity risk across complex enterprise environments.
Experience leading significant cybersecurity incidents and communicating effectively with both technical and executive audiences.
Strong vendor-management and third-party risk-management capabilities.
Demonstrated ability to operate effectively in an environment requiring both strategic leadership and hands-on problem solving.
Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Information Systems, or a related discipline, or equivalent relevant experience.
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search