Chief Information Security Officer
4 days ago
Denver
Job DescriptionDescriptionThe Chief Information Security Officer (CISO) at Pathify is a director level position responsible for establishing and maintaining a comprehensive, enterprise-wide information security and risk management program. The CISO's primary objective is to ensure that the organization's information assets and associated technologies are adequately protected. This role involves identifying, evaluating, and reporting on legal, regulatory, and IT security risks to support the organization's strategic goals and protect its brand and reputation. The CISO is responsible for developing and implementing policies, procedures, and controls to manage and mitigate these risks. Key Responsibilities1. Strategy & Governance: • Develop, implement, and monitor a strategic, comprehensive enterprise information security and IT risk management program., • Establish and lead an information security governance framework, including management of the information security steering committee., • Create and manage a unified and flexible control framework to integrate and normalize the requirements of information security policies and regulations., • Develop and maintain a security-conscious culture through ongoing training and awareness programs for all employees. 2. Risk Management & Compliance: • Lead the information security risk assessment process, identifying potential threats and vulnerabilities to the organization's information assets., • Ensure compliance with all applicable data protection laws, regulations, and industry standards (e.g., GDPR, CCPA, HIPAA, PCI-DSS, ISO 27001)., • Work directly with business units to facilitate IT risk assessment and risk management processes, and identify acceptable levels of residual risk., • Provide regular reports on the status of the information security program to enterprise risk teams, senior business leaders, and the board of directors. 3. Security Operations & Incident Response: • Oversee the continuous monitoring and protection of information processing facilities, networks, and data., • Develop and manage a robust Security Operations Center (SOC) function, either in-house or through a managed service provider., • Create, implement, and maintain a comprehensive incident response plan to address security breaches in a timely and effective manner., • Lead and coordinate all incident response activities, including investigation, containment, eradication, and recovery. Conduct post-mortem analyses to prevent future incidents. 4. Technology & Architecture: • Provide strategic guidance and oversight for the design and implementation of security architecture for all IT projects., • Evaluate and recommend new security technologies and practices to protect the organization against emerging threats., • Specifically evaluate and recommend threat analysis and defense against AI enabled vectors., • Oversee identity and access management (IAM), vulnerability management, and data loss prevention (DLP) programs., • Ensure the security of cloud environments (IaaS, PaaS, SaaS) and third-party vendor systems. 5. Leadership & Team Management: • Lead the information security function across the company, including hiring, training, staff development, and performance management. Note that in the first iteration this role is a team of 1., • Create a budget for the information security program and manage it effectively., • Serve as a key liaison between the information security team and other departments, including IT, legal, HR, and business units., • Communicate security concepts and risks to both technical and non-technical audiences. Skills, Knowledge and ExpertiseEducation: • Bachelor's degree in Information Security, Computer Science, Information Technology, or a related field., • Master's degree (e.g., MBA, Master's in Cybersecurity) is highly preferred.Experience:, • Minimum of 10-15 years of experience in information security and/or IT risk management., • At least 5-7 years in a senior leadership or management role within a complex organization., • Proven track record of developing and implementing successful information security programs., • Experience with contract and vendor negotiations and management., • Experience in education or a similarly regulated industry (e.g., finance, healthcare) is a plus. Certifications (one or more preferred): • Certified Information Systems Security Professional (CISSP), • Certified Information Security Manager (CISM), • Certified Information Systems Auditor (CISA), • Certified in Risk and Information Systems Control (CRISC)Technical Skills:, • In-depth knowledge of security frameworks (e.g., NIST, ISO 27001/27002, COBIT)., • Strong understanding of network security, cryptography, application security, cloud security, and IAM., • Familiarity with security technologies such as firewalls, intrusion detection/prevention systems (IDS/IPS), SIEM, and endpoint protection. Key Competencies: • Strategic Thinking: Ability to align security initiatives with business objectives., • Leadership: Strong leadership, communication, and interpersonal skills to build consensus and influence change., • Business Acumen: Understanding of organizational mission, values, and goals., • Risk Management: Expertise in identifying and mitigating security risks., • Problem-Solving: Excellent analytical and problem-solving abilities., • Communication: Ability to effectively communicate complex security concepts to all levels of the organization., • Full-time, work from home position., • May require occasional travel to other company locations or for industry conferences., • Availability to respond to security incidents and emergencies, which may occur outside of standard business hours. Benefits • 401(K), • Employee stock purchase plan, • Company-sponsored outings, • Company-sponsored happy hours, • Home-office stipend for remote employees, • Continuing education stipend, • Job training & conferences, • Online course subscriptions available, • Promote from within, • Dental insurance, • Disability insurance, • Flexible Spending Account (FSA), • Health insurance, • Life insurance, • Pet insurance, • Vision insurance, • Wellness programs, • Mental health benefits, • Volunteer in local community, • Open door policy, • Remote work program, • Team based strategic planning, • OKR operational model, • Employee resource groups, • Family medical leave, • Generous parental leave, • Paid volunteer time, • Paid holidays, • Paid sick days, • Unlimited vacation policy