Position Overview:
You are an information security leader with deep experience across all domains of information security, with particular strength in governance, risk management, and compliance (GRC), and a proven record of directly managing technical security teams. You know how to build trust and influence outcomes across the organization, using your domain knowledge, prior experience, and executive presence to engage both technical and business leaders.
Reporting to the Chief Information Security Officer (CISO), the Vice President, Deputy Chief Information Security Officer (Deputy CISO) is the direct people manager for Security Engineering, Security Operations (SecOps), and Governance, Risk, and Compliance (GRC), with full accountability for the strategy, staffing, performance, and budget of each function. The Deputy CISO ensures the enterprise’s personnel, data, and assets are protected against current and emerging threats, and provides leadership continuity for the security program in the CISO’s absence.
Location: must work in the Pleasant Grove, Utah office, not taking remote applicants at this time
Responsibilities:
- Directly manages the Security Engineering, Security Operations (SecOps), and GRC functions, including hiring, performance management, and development of each team’s leadership.
- Sets strategy and priorities across security engineering, security operations, and GRC, ensuring the three functions operate as one coordinated program.
- Owns the organization’s security governance framework and compliance posture against industry frameworks and regulations (e.g., SOC 2, ISO 27001/27701, NIST CSF/800-53, PCI DSS, GDPR, CCPA), including third-party risk management and audit oversight.
- Oversees the security engineering roadmap and the operation of security monitoring, threat detection, and incident response, including post-incident governance and regulatory notification.
- Owns the enterprise security risk management program, including risk assessment, treatment, reporting, and the organization’s risk register.
- Manages the combined budget for security engineering, SecOps, and GRC, and contributes to enterprise security budget planning alongside the CISO.
- Provides leadership continuity in the CISO’s absence, including strategy execution, decision-making, and representation at the executive and board levels.
- Delivers security metrics, KPIs, and risk reporting to executive leadership, the board, and audit or risk committees.
- Partners with Legal and Privacy to align security requirements with contractual, regulatory, and privacy obligations, including customer due diligence and RFP responses.
- Acts as a representative for Arctic Wolf’s security and compliance posture with customers, auditors, regulators, and senior executives.
Skills and Requirements:
- 8+ years of leadership experience directly managing security engineering, security operations, or GRC teams.
- 10+ years of progressive information security experience spanning both technical security engineering functions and GRC.
- Demonstrated experience building and leading enterprise risk management programs, including risk assessment, risk registers, and reporting to executive leadership.
- Demonstrated experience managing SOC 2, ISO 27001, or similar certification and audit processes from initiation through completion.
- Experience with international industry security standards (NIST, ISO, SOC 2) and data privacy regulations (GDPR, CCPA, and other regional standards).
- Experience managing third-party and vendor risk management programs.
- Ability to establish executive-level relationships across business and technology leadership and manage competing priorities under pressure.
- A Bachelor’s Degree in Computer Science, Information Systems, Engineering, or a related technical field.
- Deep knowledge of information security governance, risk management, and compliance (GRC) frameworks, including NIST CSF, NIST 800-53, ISO 27001/27701, SOC 2, and CIS Controls.
- Demonstrated ability to lead security engineering and security operations teams, including secure architecture, SOC operations, and incident response.
- Experience designing and operating enterprise risk assessment, risk register, and audit or certification processes (e.g., SOC 2 Type II, ISO 27001).
- Strong understanding of data privacy regulations, including GDPR and CCPA/CPRA, and third-party risk management practices.
- Familiarity with Secure SDLC, DevSecOps, and security automation practices.
- Strong executive communication, board reporting, and stakeholder management skills.
- Ability to translate technical and regulatory risk into business risk language for non-technical audiences.
Preferred Skills and Requirements:
- Experience serving as a CISO, Deputy CISO, or acting CISO.
- Relevant industry certification(s) such as CISSP, CISM, CRISC, or CISA.
- Master’s degree in a related field, or MBA.
- Experience in a regulated industry, such as financial services, healthcare, or SaaS/cybersecurity.
- Familiarity with GRC platforms, tools, and automation (e.g., Archer, OneTrust, Vanta, or Drata).
On-Camera Policy:
To support a fair, transparent, and engaging interview experience, candidates interviewing remotely are expected to be on camera during all video interviews. Being on camera fosters authentic connection, improves communication, and allows for full engagement from both candidates and interviewers. We understand that technical, bandwidth, or location-related challenges may occasionally prevent video use. If this applies, candidates are required to notify us in advance so we can explore appropriate accommodations.
Security Requirements
- Conducts duties and responsibilities in accordance with AWN’s Information Security policies, standards, processes, and controls to protect the confidentiality, integrity and availability of AWN business information (in accordance with our employee handbook and corporate policies).
- Background checks are required for this position.
- This position may require access to information protected under U.S. export control laws and regulations, including the Export Administration Regulations (“EAR”). Please note that, if applicable, an offer for employment will be conditioned on authorization to receive software or technology controlled under these U.S. export control laws and regulations.