Business Information Security Lead (Remote)
$100,000–$155,000 year
RemoteAlaska, United States
Job Summary
Consult on key business initiatives to ensure comprehensive end-to-end identification and risk management. Execute the security program by identifying and remediating risks in accordance with security policies and standards. Act as the single point of contact for security concerns, providing escalation paths and guiding decision-making for Value Stream partners. Perform audits, assess risks, and manage remediation of issues found in security assessments, penetration tests, and internal discovery. Provide visibility into current security compliance status through defined metrics and benchmarking. Coach Product Teams to mature their understanding and use of security tools and information. Present monthly gap analysis, remediation plans, and areas of success to the Value Stream Lead.
Required Qualifications
- At least 5+ years of information security experience
- Broad foundational knowledge in many information and cyber security domains with priority given to security risk management and application security
- Familiarity with compliance requirements (PCI, HIPAA, SOX, etc) and with security frameworks such as NIST CSF, ISO 27001, CIS, etc
- Demonstratable experience in building positive working relationships with leaders and associates across multiple areas of the business
- Must have the ability to work independently and make decisions that reflect the policies of the Information and Cyber Security Team
- Experience measuring and tracking cybersecurity risks, issues, and exceptions
- Ability to present complex security topics to a variety of audiences, including senior technical leaders
- Ability to advise, collaborate, and work in a team environment enabling others to trust your input and seek your guidance
- Ability to influence without authority to drive desired outcomes
- Experience executing security compliance plans, vulnerability management programs, risk management lifecycle, and/or security assessment/governance processes
- Track record of acting with integrity, taking pride in work, seeking to excel, being curious and adaptable, and communicating effectively
- Proactive self-development, staying current on evolving threat landscape, security trends/best practices, and dynamic regulatory requirements
- Bachelor's degree from an accredited college/university OR equivalent professional experience required
- Experience developing, measuring, and tracking key performance metrics, preferably in a cybersecurity program
- Highly organized, efficient, and attention to detail
- Demonstrable track record of successful development of resources, mentoring, and career guidance
- Strong written and verbal skills enabling effective communication with different levels of leadership
- Must be able to work remotely anywhere in the United States except Hawaii or United States Territories
- Can live anywhere in continental US and Alaska
- Travel as needed for business
Desired Qualifications
- SANS GSEC, GCIA (or related), CISSP
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.