- Company Name
- Incendia Partners
- Job Title
- Chief Information Security Officer - Southern NH- Hybrid
- Job Description
-
**Job Title**
Chief Information Security Officer (CISO)
**Role Summary**
Lead the organization’s information security strategy, protecting data, intellectual property, and technology assets. Oversee risk management, compliance, incident response, security operations, and security integration across IT, DevOps, and product engineering. Build and manage a high‑performance security team, ensuring alignment of security initiatives with business objectives and industry regulations.
**Expectations**
- Develop and execute a comprehensive security strategy that safeguards enterprise data, systems, and services.
- Maintain ongoing compliance with global standards (ISO 27001, NIST, SOC 2, PCI‑DSS, GDPR, HIPAA, etc.).
- Lead incident response, threat intelligence, and security operations to detect, contain, and remediate cyber incidents.
- Foster a culture of security through awareness training, governance, and collaboration with cross‑functional stakeholders.
- Demonstrate thought leadership and represent the organization in external security forums, customer engagements, and industry groups.
**Key Responsibilities**
- Own enterprise security strategy, architecture, and roadmap.
- Design and enforce controls for Managed IT, hosting services, SaaS, cloud, APIs, and third‑party integrations.
- Champion zero‑trust IAM, encryption, DevSecOps, and secure DevOps practices.
- Establish and run GRC programs, risk assessments, audit and compliance management.
- Lead incident response, threat intelligence, vulnerability management, and security operations center (SOC) oversight.
- Guide security product implementation (endpoint, identity, network, cloud security).
- Partner with product, engineering, infrastructure, and operations to embed security into pipelines.
- Serve as external security authority, interacting with customers, partners, and industry groups.
- Build and mentor security leadership team and develop professional growth.
- Report on security posture, risk metrics, and remediation progress to executive leadership.
**Required Skills**
- Executive leadership and stakeholder management.
- Deep knowledge of information security frameworks, risk management, incident response, and security architecture.
- Experience with cloud (AWS/GCP/Azure), SaaS, MSP, and zero‑trust implementations.
- Strong understanding of regulatory compliance (GDPR, HIPAA, PCI‑DSS, SOC 2, ISO 27001, NIST).
- Proven track record of building and scaling security operations, SOC, and GRC programs.
- Excellent communication, influence, and collaborative skills.
- Ability to translate complex security concepts into business‑impact language.
**Required Education & Certifications**
- Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or related field (advanced degree preferred).
- Industry certifications: CISSP, CISM, CISA, CRISC, CCISO, or equivalent; at least 2–3 senior‑level security credentials required.
---