Back to search
Confidential Jobs Linkedin · Posted 1mo ago

Chief Information Security Officer (CISO)

Shanghai

Linkedin
Continue to application Add your email once, then Caio opens the original posting.

Indexed description

About the Role

We are seeking a visionary and strategic Chief Information Security Officer (CISO) to lead our enterprise-wide information security program. As a key member of the executive leadership team, you will be responsible for establishing and maintaining the company’s security vision, strategy, and governance. You will ensure that our digital assets, intellectual property, customer data, and infrastructure are protected against evolving cyber threats, while enabling business growth and regulatory compliance.

This is not just a technical leadership role—it is a business-enabling position that requires exceptional communication, risk management acumen, and the ability to translate complex security concepts into actionable business strategies.


Key Responsibilities

1. Strategic Leadership

  • Develop, implement, and maintain a comprehensive enterprise-wide information security and risk management program aligned with business objectives.
  • Define and communicate the organization's security vision, strategy, and roadmap to the executive team, Board of Directors, and key stakeholders.
  • Champion a "security-by-design" culture across all business units, engineering teams, and product lines.
  • Stay abreast of emerging threats, technologies, and regulatory changes to proactively adapt the security posture.

2. Governance, Risk & Compliance (GRC)

  • Establish and oversee security policies, standards, frameworks, and controls (e.g., NIST CSF, ISO 27001, SOC 2, CIS Controls).
  • Lead the organization's risk assessment processes, including third-party/vendor risk management and business impact analyses.
  • Ensure compliance with relevant regulatory requirements (e.g., GDPR, CCPA, HIPAA, PCI-DSS, SOX) and industry-specific mandates.
  • Manage relationships with external auditors, regulators, and legal counsel on security and privacy matters.

3. Security Operations & Engineering

  • Direct the design, implementation, and continuous improvement of security architectures, including network, endpoint, cloud (AWS/Azure/GCP), and application security.
  • Oversee Security Operations Center (SOC) functions, including threat intelligence, monitoring, detection, incident response, and forensic investigations.
  • Lead the development and testing of incident response plans, crisis management protocols, and business continuity/disaster recovery strategies.
  • Ensure effective identity and access management (IAM), data loss prevention (DLP), and encryption controls are in place.

4. Incident Response & Crisis Management

  • Act as the primary executive lead during cybersecurity incidents, coordinating containment, eradication, recovery, and post-mortem activities.
  • Communicate effectively with internal stakeholders, customers, regulators, and media during and after security events.
  • Conduct regular tabletop exercises and simulations to test organizational readiness.

5. Budget & Resource Management

  • Develop and manage the information security budget, ensuring optimal allocation of resources across people, technology, and external services.
  • Evaluate, select, and manage relationships with security vendors, managed security service providers (MSSPs), and consultants.
  • Build, mentor, and retain a high-performing security team, fostering a culture of continuous learning and innovation.

6. Stakeholder Engagement & Culture

  • Partner with engineering, product, legal, HR, and IT teams to embed security into all phases of the technology lifecycle.
  • Drive security awareness and training programs across the organization to cultivate a security-first mindset.
  • Serve as the external face of the company's security posture to customers, partners, investors, and industry forums.


Qualifications & Experience

Essential

  • 15+ years of progressive experience in information security, with 5+ years in a senior leadership role (e.g., CISO, VP of Security, Director of Information Security).
  • Proven track record of developing and executing security strategies in complex, global, and regulated environments (preferably in [industry, e.g., Fintech, Healthcare, SaaS]).
  • Deep understanding of security frameworks (NIST CSF, ISO 27001), regulatory requirements (GDPR, HIPAA, PCI-DSS, SOX), and cloud security architecture.
  • Hands-on experience with incident response, threat intelligence, and security operations at scale.
  • Strong financial acumen with experience managing multi-million-dollar security budgets.
  • Exceptional communication and influencing skills, with the ability to present complex risk topics to non-technical audiences, including the Board.

Desirable

  • Relevant professional certifications such as CISSP, CISM, CRISC, or GIAC.
  • Experience with DevSecOps, secure SDLC, and cloud-native security (AWS, Azure, GCP).
  • Prior experience as a CISO in a high-growth, publicly traded, or pre-IPO company.
  • Background in privacy, data protection, or cybersecurity law is a plus.
  • Master’s degree in Cybersecurity, Computer Science, Business Administration (MBA), or a related field.

Personal Attributes

  • Strategic Visionary: Ability to balance short-term tactical needs with long-term strategic goals.
  • Decisive & Resilient: Calm under pressure; capable of making high-stakes decisions during incidents.
  • Collaborative Partner: Builds trust and influence across all levels of the organization.
  • Ethical & Transparent: Unwavering commitment to integrity, privacy, and ethical conduct.
  • Continuous Learner: Passionate about staying ahead of the threat landscape and emerging technologies.


Free. 20 seconds. No password. See every match in this search.

Create a free Caio profile to unlock more results and save your role and location preferences.

Unlock free search
Want help applying to roles like this? Search Caio for free. If repetitive applications get heavy, Managed Job Search adds supervised execution for $99/month.
View Managed Job Search