Head of Information Security
C3.aiAbout the role
C3.ai, Inc. (NYSE:AI) is a leading Enterprise AI software provider for accelerating digital transformation. The proven C3 AI Platform provides comprehensive services to build enterprise-scale AI applications more efficiently and cost-effectively than alternative approaches. The C3 AI Platform supports the value chain in any industry with prebuilt, configurable, high-value AI applications for reliability, fraud detection, sensor network health, supply network optimization, energy management, anti-money laundering, and customer engagement. Learn more at: C3 AI
C3 AI is seeking an Information Security expert to own and lead the information security program. As the Head of Information Security, you will be responsible for protecting the organization's assets, applications, systems, and technology while enabling and advancing business initiatives.
Responsibilities:
Security Architecture & Strategy
- Develop, implement, and monitor comprehensive enterprise cybersecurity and IT risk management program leveraging secure processes, procedures and systems used to prevent, detect, mitigate, and recover from cyberattacks.
- Build and drive a cybersecurity strategy and framework, with initiatives to secure the organization's cyber, information and technology assets while providing leadership to the enterprise's information security organization.
- Formulate best practices and set security standards, while preparing and documenting information security policies, procedures and protocols.
- Lead security assessment processes of internal assets, encompassing penetration testing, vulnerability management, and secure software development.
- Analyze the costs, value, and risks of cybersecurity activities and recommend actions within a budget
Threat Management & Mitigation
- Continuously evaluate and manage the cyber and technology risk posture of the organization.
- Proactively spot security issues and threats, devising robust processes and systems to safeguard against them.
- Manage a robust incident management process.
- Convey information security and data privacy operational goals, relaying their impact to stakeholders.
- Keep ahead of security needs by implementing programs or projects that mitigate risks.
- Ensure that all internally written code is cyber secure by performing regular application security and penetrations tests.
- Conduct real-time analysis of immediate threats, triage and remediate as necessary.
- Lead cybersecurity operations and implement disaster recovery protocols and business continuity plans with business resiliency in mind.
- Make sure that data and intellectual property is safe from external and internal threats.
- Lead security incident investigations and forensic data collection activities during a security breach and conduct post-mortem exercises to prevent reoccurrence.
- Act as the focal point for security incident response planning and cyber security breach remediation.
Security Operations and Awareness
- Lead the effort for conducting vulnerability scans, reviews, and remediation activities to ensure a secure environment and to ensure that the products and services that C3.ai develops are secure.
- Manage the ongoing security awareness training and education program for employees
- Provide leadership and fostering a culture of cybersecurity awareness and ensuring continued training and development.
Governance
- Implement and manage the cyber governance, risk, and compliance frameworks and processes.
- Lead compliance endeavors, including external audits, regulatory compliance initiatives, and overarching security evaluations.
- Collaborate with the Security Committee to develop and implement information security policies, standards, procedures, and guidelines.
- Interact with related disciplines through committees to ensure the consistent application of policies and standards across all technology projects, systems, and services.
- Partner with business stakeholders across the company to raise awareness of risk management concerns and assist with business technology planning.
- Conduct and lead information security risk assessments, support audits (SOC 2, HIPAA, ISO 27001/27017, Cyber Essentials), and select controls to mitigate risks.
- Work with the legal/privacy teams to ensure compliance with privacy regulations.
Stakeholder & External Communication
- Report on Cybersecurity by providing the business leaders, board of directors or senior executives in area of cybersecurity risk profile and posture of organization, notable cyberse
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s