Serves as a strategic partner and senior advisor to the Corporate Security Officer (CSO), overseeing the development and execution of the organization's enterprise-wide information security programs. Leads cross-functional initiatives that reduce risk, ensure compliance, and protect critical systems, data, and infrastructure. Provides expert-level guidance on security policies, vendor risk management, proposal responses, and regulatory assessments while building partnerships across business and technology units.
Essential Functions:- Acts as a delegate and representative of the Corporate Security Officer to support executive initiatives and enterprise security strategy.
- Develops and maintains comprehensive security policies, standards, procedures, and response plans in alignment with industry best practices and compliance requirements.
- Provides written technical responses to security-related requirements in proposals for federal, state, and commercial contracts.
- Leads enterprise-wide initiatives including risk assessments, incident response coordination, cloud security evaluations, and secure development lifecycle (DevSecOps) implementations.
- Presents security postures, risk summaries, and investment justifications to senior executives and stakeholders in clear, actionable formats.
- Builds cross-functional partnerships with business units and IT leaders to integrate security into organizational processes and initiatives.
- Oversees supply chain and third-party vendor risk management programs to ensure alignment with corporate security objectives.
- Coordinates and facilitates internal and external security audits, risk assessments, and regulatory compliance reviews.
Level of Supervision Received:Functions independently within broad scope of established departmental policies/practices; generally refers specific problems to manager only where clarification of departmental operating policies/procedures may be required.
Education (can be substituted for experience):Master's Degree required
Work Experience (can be substituted for education):15+ years required
Certifications:Certified Information Systems Security Professional (CISSP) or equivalent required.
Certified Information Security Manager (CISM) preferred.
Certified Cloud Security Professional (CCSP) preferred.
GIAC Security Leadership Certification (GSLC) preferred.