Chief Information Security Officer
ACLUAbout the role
ABOUT THE JOB
The ACLU seeks the full-time position of Chief Information Security Officer in the Information Security Team of the ACLU’s National office in New York, NY. This is a hybrid role that has in-office requirements of two (2) days per week or eight (8) days per month.
The Information Security Team is responsible for the development and implementation of the ACLU’s information security strategy, and for ensuring compliance with regulations, conducting risk assessments, and increasing staff security awareness. It plays a critical role in protecting the ACLU and its work from cyber threats by helping to mitigate risk to the ACLU’s information assets.
WHAT YOU'LL DO
Reporting to the Chief Operating Officer, the Chief Information Security Officer (CISO) will oversee all aspects of the ACLU’s nationwide information security strategy. Specifically, the CISO will be responsible for creating and managing policies, systems, and compliance practices that keep the ACLU’s nationwide infrastructure secure. The role will collaborate with senior leaders within the ACLU, including General Counsel, Information Technology (IT), Business Operations, Privacy & Data Governance, and Technology to define a dynamic set of principles, guardrails, governance, risk mitigation, and ongoing monitoring for the ACLU’s information security management approach. The CISO will also be a senior leader within the Core Services Team, which includes Finance, Human Resources, Business Operations, IT, and Information Security. The ideal candidate is an experienced cybersecurity leader with demonstrated expertise and practical work experience, building and maintaining information security programs with a strong focus on proactive risk management.
YOUR DAY TO DAY
Leadership
- Develop and implement a comprehensive vision and strategy for the ACLU’s information security program that assures compliance with relevant regulatory standards, is aligned with organizational goals and values, addresses long- and short-term risks, and establishes appropriate guardrails for the ACLU’s nationwide infrastructure
- Lead by example in managing a team of information security professionals, driving results through the use of data, direct feedback and strong accountability in a supportive and learning environment that fosters high staff engagement and professional growth
- Participate in cross-departmental projects, providing functional expertise and thought leadership, and being a trusted advisor to organizational partners in developing policies and procedures that reflect best practices in information risk management and align with the ACLU’s commitment to digital accessibility and inclusion
- Set the bar for customer service excellence by providing timely, thorough and friendly responses to internal and external stakeholder inquiries
- Create and deliver accessible and inclusive trainings to ACLU National and affiliate staff on information security policies, systems and best practices, to ensure staff are able to fully participate in cultivating and retaining a strong security awareness posture
- Stay current with industry best practices, technological advances, and news related to information security
- Complete ad-hoc projects at the request of the COO
Information Security Operations
- Oversee the daily operations of the Information Security Team, including threat intelligence management as well as incident detection and response for the ACLU’s nationwide infrastructure
- Create and track long- and short-term information risk management goals; define metrics for compliance and performance, develop reporting, and communicate progress to organizational leadership
- Evaluate and resolve information security risks by working with internal and external partners to proactively assess vulnerabilities and implement solutions rooted in best practices, leading industry trends, and organizational policies
- Lead cybersecurity incident response process, including notifying relevant stakeholders, coordinating with law enforcement if necessary, and taking appropriate actions to address vulnerabilities and mitigate future incidences
- Oversee information security architecture and maintenance program for IT networks and applications for National and its affiliates to ensure optimal security structures are developed and maintained; ensure required security control initiatives are executed on schedule and in line with the ACLU's information security program objectives
- Oversee planning and procedures for testing ACLU’s public-facing technology platforms, ensuring security and privacy of information transmitted and stored
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s