Chief Information Security Officer (CISO)
- Роль
- Безопасность
- Опыт
- C-Level
- Занятость
- Полная занятость
- Размер компании
- Крупная
Доступно для: US only. Укажите, откуда вы работаете, чтобы проверить доступность.
Коротко по делу
Enterprise-level security leader (CISO) needed for global cyber security, information risk, and resilience. Must define and execute global security strategy, lead operations and governance, and ensure compliance. Requires 10+ years in information security with 5+ in senior leadership, incident response experience, and relevant certifications (CISSP, CISM, CISA).
Ключевые навыки
Обязательные навыки
Желательные навыки
Обязательные языки
Welcome to JD Power Careers! JD Power is a proven leader in business-critical data and intelligence to drive auto-related decisions with confidence and clarity. By leveraging unmatched proprietary data, advanced analytics and deep industry expertise, JD Power fuels original equipment manufacturers, retailers, lenders, insurers and partners to enhance their performance. Since 1968, JD Power has delivered incisive guidance and intelligence about customer interactions with brands and products. To learn more about the company, visit JDPower.com.
Чем предстоит заниматься
- Define and own the global cyber security strategy, aligned to business objectives and risk appetite.
- Provide senior-level leadership and act as a trusted advisor to the CTO, Operating Team, Board Cybersecurity Committee, and senior leaders.
- Lead global planning, budgeting, capability development, and vendor strategy for all security domains.
- Promote a strong security culture across all regions, embedding secure behaviors and accountability.
- Lead the design, implementation, operation, and continuous improvement of the Information Security Management System (ISMS) aligned to ISO 27001, SOC2, TISAX, and other relevant frameworks.
- Oversee global risk management, including risk assessments, control selection, and enterprise risk reporting.
- Ensure compliance with global cyber security regulations and industry standards.
- Lead the development and maintenance of global security policies, standards, and guidelines.
- Oversee third-party and supply-chain security, including vendor assessments and due diligence.
- Lead global Security Operations (SecOps), including monitoring, detection, threat intelligence, and vulnerability management.
- Establish and mature global CSIRT/CSOC capabilities, ensuring 24/7 coverage where required.
- Act as executive incident commander for major cyber events, ensuring effective response, communication, and recovery.
- Maintain incident playbooks, escalation paths, and post-incident reviews to drive continuous improvement.
- Define and oversee secure architecture, cloud security standards, and identity & access management (IAM).
- Embed security into the software development lifecycle (SDLC), including secure coding, DevSecOps, and product security reviews.
- Partner with Engineering and Technology teams to ensure secure design, encryption, and access controls across all platforms.
- Act as the senior representative for cyber security with regulators, auditors, customers, and partners.
- Oversee responses to customer and partner security assessments and due-diligence requests.
- Monitor global regulatory developments and translate them into actionable controls and programs.
- Lead and develop global teams across security operations, governance, risk, compliance, and resilience.
- Build organizational capability, succession planning, and specialist talent pipelines.
- Foster a collaborative, high-performance culture across regions and functions.
Что требуется
- 10+ years of experience in information security, cybersecurity, with at least 5+ years in a senior leadership role
- Proven track record of incident response leadership and crisis management.
- Experience leading large-scale enterprise security programs and managing global teams, including leaders of leaders.
- Strong knowledge of modern enterprise security practices, including identity and access management, cloud security, endpoint security, DevSecOps, threat detection, and vulnerability management.
- Understanding of emerging AI security risks and controls, including securing AI-enabled workflows and enterprise AI platforms.
- Experience securing modern cloud and development environments across platforms such as AWS, Azure, or GCP.
- Familiarity with modern security frameworks and standards such as NIST, ISO 27001, PCI, or OWASP.
- Demonstrated ability to communicate complex security topics to executive leadership and nontechnical stakeholders.
- Experience with risk management, compliance, and regulatory requirements relevant to enterprise software companies.
- Strong business acumen, particularly in aligning security investments with financial and operational priorities.
null
Что говорят о компании
3.4/ 5