Jobs and Careers
SI

Chief Information Security Officer (CISO)

Sinch
United States - Remote, United StatesRemotefull_timeVerifiedPosted 3 Jan 2024

About the role

Sinch is a leading global CPaaS (Communications Platform as a Service) providing cloud-based Messaging, Email, Voice, and Application services to major brands, including many leading tech companies, worldwide.

We are now looking for a global CISO whose mission is to protect Sinch's information and systems.

In this role you will lead and manage our security strategy, roadmap, initiatives, and coordinate with related activities across all entities within Sinch. To be successful, you will work closely with the global group leadership, representing strategy, human resources, finance, product, engineering, business IT, data, legal/privacy teams, and regional presidents (who lead Sales, Field Marketing, and Customer Success).

We therefore seek an experienced CISO that with expertly define our security strategies, update our security roadmap, coordinate its execution as part of Sinch’s program portfolio, and develop and lead a team of highly skilled security leaders and professionals. 

Reporting to our Chief Data and Transformation Officer, you will lead and manage a global security team in defining our security strategy, roadmap, and initiatives. You will coordinate these with related activities across all Sinch entities, identify and manage risks, govern compliance, define key security architectures, and oversee critical external services. Furthermore, you will develop and lead a team of highly skilled security professionals and be responsible for reporting all aspects of security risks, status, and initiatives to the Sinch Group Leadership team and Board of Directors regularly.

 Being a global company with teammates located in many regions, this role is hybrid in nature using remote ways of working.  It is expected that some travel will be required to build trust and rapport with your security team and leaders across the company, but qualified candidates will be effective working with dispersed teams.

 

Main Responsibilities

  • Define, manage, and progress the security risk program by developing the strategy, roadmap, and initiatives required to mitigate the evolving security risks using industry best practices
  • Protect Sinch from cyber-attack through effective cyber security intelligence and operations, including preparation, prevention, detection of potential threat actor attack along with response and recovery
  • Collaborate with group leadership to identify and mitigate information security concerns within the product development lifecycle through consistent and comprehensive testing processes
  • Create a “security by design” culture that considers security in all relevant designs, processes, and decisions and use regular training to
  • Perform regular, ongoing and rigorous reviews of personnel resources to ensure that project plans are executed effectively, offering alternative solutions that still achieve desired outcomes when necessary
  • Lead the Incident Response Team and coordinate with group leadership to contain, investigate (including Root Cause Analysis), mitigate, and prevent future computer security incidents or breaches
  • Refine group level security policies and procedures (ISMS)
  • Define and provide ongoing tracking of group wide security KPIs for governance and continuous improvement
  • Provide quarterly security report for the leadership team and board of directors  
  • Drive cost efficiency by consolidating policies, tooling and services that are not unique to product lines
  • Budget management for Sinch Information Security
  • Flexibility to work across time zones and willingness to travel up to 25% (sometimes internationally) as needed

Requirements

  • Degree in Information Security, Software Engineering, Computer Science, Information Systems, or equivalent work experience and training
  • At least 10 years' experience leading information security teams, with preference given to global experience
  • At least 3 years' experience with security testing within the product development lifecycle, preferably with automation best practices related to Continuous Development/Continuous Integration pipelines
  • Relevant certifications such as CISA, CISSP
  • In depth knowledge about security standards and regulations such as ISO27001, SOC2, NIST CSF
  • Deep understanding of audit, assessment and RFx processes with external parties
  • At least 3 years working experience with global data privacy laws and regulations
  • Solid understanding of cloud computing, IP networking, software development and operations
  • Project management skills to organize and drive cross functional initiatives
  • Experience with contract and vendor negotiations, including third party management and vetting
  • Highest level of personal integrity and accountability
  • P

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Sinch

View company profile →