Jobs and Careers
IN

Director of Cybersecurity & Chief Information Security Officer

insightsoftware
United StatesRemotefull_timeVerifiedPosted 14 Dec 2023

About the role

Company Description

insightsoftware is a leading provider of reporting, analytics, and performance management solutions. Over 30,000 organizations worldwide rely on us to support business needs in the areas of accounting, finance, operations, supply chain, tax, budgeting, planning, HR, and disclosure management. We enable the Office of the CFO to connect to and make sense of their data in real time so they can proactively drive greater financial intelligence across their organization. Our best-in-class solutions provide customers with increased productivity, visibility, accuracy, and compliance. Learn more at insightsoftware.com.

Job Description

Overview

The Director of Cybersecurity & Chief Information Security Officer (CISO) will be responsible for the enterprise information security program. That will involve identifying, evaluating and reporting on legal and regulatory, IT, and cybersecurity risk to information assets, while supporting and advancing business objectives.

A key element of the CISO's role is working with executive management to determine acceptable levels of risk for the organization. He or she will proactively work with business units and ecosystem partners to implement practices that meet agreed-on policies and standards for information security. The CISO should understand and articulate the impact of cybersecurity on (digital) business, and be able to communicate this to the executive team and other senior stakeholders.

He or she serves as the process owner of the appropriate second-line assurance activities not only related to confidentiality, integrity and availability, but also to the safety, privacy and recovery of information owned or processed by the business in compliance with regulatory requirements.

The ideal candidate is a thought leader, a builder of consensus and of bridges between business and technology. He or she is an integrator of people, process and technology. While the CISO is the leader of the information security program, he or she must also be able to coordinate disparate drivers, constraints and personalities, while maintaining objectivity and a strong understanding that cybersecurity is foundational for the organization to deliver on its business goals and objectives. Ultimately, the CISO is a business leader, and should have a track record of competency in the field of information security and/or risk management, with 7 to 10 years of relevant experience, including 5 years in a significant leadership role. This role will report into the Chief Information Officer and lead a team of 7+ direct reports.

Tasks and Responsibilities

Establish Governance and Build Knowledge

  • Facilitates an information security governance structure through the implementation of a hierarchical governance program
  • Provides regular reporting on the current status of the information security program to enterprise risk teams, senior business leaders and the executive team as part of a strategic enterprise risk management program, thus supporting business outcomes
  • Develops, socializes and coordinates approval and implementation of security policies
  • Works with the vendor management office to ensure that information security requirements are included in contracts by liaising with vendor management and procurement organizations
  • Directs the information security awareness training program for all employees, contractors and approved system users, and establishes metrics to measure the effectiveness of this security training program for the different audiences
  • Understands and interacts with related disciplines, either directly or through committees, to ensure the consistent application of policies and standards across all technology projects, systems and services, including privacy, risk management, compliance and business continuity management
  • Provides clear risk mitigating directives for projects with components in IT, including the mandatory application of controls
  • Leads the security champion program to mobilize employees in key roles

Lead the Organization

  • Leads the information security function across the company to ensure consistent and high-quality information security management in support of the business goals
  • Determines the information security approach and operating model in consultation with stakeholders and aligned with the risk management approach and compliance monitoring of non-digital risk areas
  • Manages the budget for the information security function, monitoring and reporting discrepancies
  • Manages the cost-efficient information security organization, consisting of direct reports and dotted line reports (such as individuals in DevOps, Engineering, and IT operations). This includes hiring, training, staff development, performance management an

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

insightsoftware

View company profile →