Virtual Chief Information Security Officer (vCISO)
Indexed description
Requirements
RESPONSIBILITIES AND DUTIES
- Governance, Risk, and Compliance (GRC):
- Assist in the development, implementation, and maintenance of effective cyber security policies, procedures, and standards.
- Support governance initiatives by establishing and maintaining security frameworks, controls, and documentation.
- Conduct risk assessments and work closely with stakeholders to identify, analyze, and mitigate potential security risks.
- Ensure compliance with relevant regulatory requirements, industry standards, and best practices.
- Assist in the preparation and participation in security audits and assessments.
- System Security Engineering:
- Collaborate with cross-functional teams to incorporate security controls and requirements into system design and development processes.
- Conduct security architecture reviews and provide technical guidance to ensure the implementation of robust security measures.
- Perform security assessments and penetration testing on systems, networks, and applications.
- Identify vulnerabilities, analyze security flaws, and recommend remediation strategies.
- Stay updated with emerging threats, vulnerabilities, and security technologies to enhance system security engineering practices.
- Incident Response and Security Monitoring:
- Contribute to the development and testing of incident response plans and procedures.
- Participate in security incident investigations, root cause analysis, and remediation efforts.
- Collaborate with the incident response team to implement proactive security monitoring and threat detection measures.
- Assist in the deployment and management of security monitoring tools and technologies.
- Bachelor’s degree in computer science, Information Technology, or a related field.
- Proven experience as a Cyber Security Engineer, Security Analyst, or a similar role.
- Strong understanding of cyber security principles, risk management methodologies, and compliance frameworks.
- In-depth knowledge of security technologies, including firewalls, intrusion detection/prevention systems, SIEM, and vulnerability scanning tools.
- Familiarity with regulatory requirements (e.g., GDPR, HIPAA), industry standards (e.g., NIST, ISO 27001), and frameworks (e.g., COBIT, ITIL).
- Experience with and interpreting cyber security framework (e.g., NIST CSF, HIPAA HITRUST, CIS20, CSA CSF)
- Experience in system security engineering, secure software development, or secure system design.
- Proficiency in conducting security assessments and vulnerability management.
- Familiarity with incident response processes and security monitoring practices.
- Excellent problem-solving and analytical skills.
- Strong communication and collaboration abilities.
- Relevant certifications such as CISSP, CISM, CASP+, or GIAC are highly desirable.
WORK PERKS
- 100% permanently remote position with no plans to return to an office
- Extensive paid time off including paid holidays and float holidays
- Highly competitive and flexible medical, dental, and vision benefits plans to suit your needs
- 401(k) with generous employer match
- Tailored Life and Disability insurance plans
- Full reimbursement for approved professional certification and career enriching opportunities
- Monthly mobile phone plan and internet service stipend
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search