Talent.com
Chief Information Security Manager

Chief Information Security Manager

InterSourcesSyosset, NY, United States
2 hours ago
Job type
  • Full-time
Job description

Chief Information Security Manager

Address : Syosset, NY (Hybrid)

Full Time Position

Scope of Work :

The vCISO shall provide expert virtual cybersecurity services during normal business hours except in the event of a security incident or breach.

HCC seeks a fresh perspective on its security measures and protocols to not only improve its posture, but also to identify new risks and opportunities. The vCISO will also be responsible for leading HCC's efforts to address the nine (9) elements of the Gramm-Leach-Bliley Act (GLBA) for compliance purposes.

  • Perform a detailed cyber risk assessment that includes the following, but not limited to :

Identifying, estimating, and prioritizing information cyber security risks at college;

  • Examining HCC's current technology, security controls, policies, and procedures to assess potential threats or attacks; and
  • Evaluating HCC's threat landscape, vulnerabilities, and cyber gaps that pose a risk to its assets.
  • Act as HCC's Qualified Individual (QI) to present quarterly reports to HCC Board of Trustees and leadership as required and specified by GLBA.
  • Develop an information security program using a framework such as National Institute of Standards and Technology (NIST) 800-53, Center of Internet Security (CIS) Critical
  • Security Controls, or CIS Implementation Group 1 (IG1) that protects HCC in accordance with GLBA security requirements.
  • Provide information security leadership, communication, investigation, mitigation, containment and post-incident analysis in the event of a cyber incident.
  • Update and enhance existing cybersecurity policies and procedures as required by GLBA.
  • The policies include but not limited to :

  • Vulnerability management
  • Data management
  • Incidence response
  • Software management
  • Hardware asset management
  • Provide guidance when analyzing real-time threat analysis identified by HCC's security operations center.
  • Perform third-party and partner evaluations Higher Education Community Vendor Assessment Toolkit (HECVAT).
  • Develop and implement the strategy to conduct regular security audits and assessments to identify vulnerabilities and ensure compliance with security policies.
  • Write a clear and concise incident response plan that meets industry standards.
  • CYBERSECURITY INCIDENT OR BREACH

    In the event of a cybersecurity incident or breach, the vCISO will :

  • Notify HCC within twenty-four (24) hours of the discovery of an incident or breach by telephone and in accordance with the agreed upon incident response plan unless a shorter notice time is required by law.
  • Implement the incident response plan, ensuring that all relevant teams are mobilized and aware of their roles and responsibilities.
  • Oversee the initial assessment to understand the scope and impact of the incident or breach.
  • Coordinate with internal stakeholders, including senior management and the board of directors, to keep them informed about the incident or breach and the steps being taken to address it.
  • Lead the investigation to determine the cause of the incident or breach, how it occurred, and what data or systems were affected.
  • Oversee the remediation efforts to fix vulnerabilities and restore affected systems.
  • Ensure that all actions taken during the incident or breach response are thoroughly documented.
  • Conduct a post-incident review to evaluate the response and identify lessons learned.
  • Provide a full written report of the incident, nature of the breach, compromised information, and correction actions taken to prevent future incidents or breaches.
  • All devices and equipment necessary to perform duties under this contract will be provided by HCC.

    EDUCATION

    At a minimum, the Contractor must possess a bachelor's degree in cybersecurity, computer science, information technology, or a related field from an accredited higher education institution in the United States. A master's degree is preferred.

    EXPERIENCE

  • IT Security : The Contractor must possess at least 7-10 years of experience in IT security-related roles such as security analyst, network administrator, or similar positions.
  • Leadership : The Contractor must possess experience in management or leadership roles as CISOs need to lead teams and make strategic decisions.
  • CERTIFICATION(S)

    The Contractor must possess at least one of the following related certifications :

  • Certified Information Systems Security Professional (CISSP)
  • Certified Information Security Manager (CISM)
  • Certified Information Systems Auditor (CISA)
  • KNOWLEDGE & SKILLS

  • Technical Skills : Demonstrates a deep understanding of information security principles, practices, and technologies.
  • Leadership and Communication : Possess strong leadership, communication, and strategic planning skills are essential.
  • Compliance and Risk Management : Possess knowledge of regulatory requirements and risk management practices.
  • Skill Matrix :

  • Technical Expertise :
  • Knowledge of Security Frameworks : Demonstrate an understanding and application of industry-standard security frameworks, such as the National Institute of Standards and Technology (NIST) 800-53, Center of Internet Security (CIS) Critical Security Controls, and CIS Implementation Group 1

    (IG1).

    Cybersecurity Technologies : Demonstrate familiarity with current security technologies, especially any commonly used technologies in higher education.

    Threat Intelligence and Incident Response : Demonstrate experience in threat detection, vulnerability / risk assessments, and incident response.

  • Experience & Qualifications :
  • Education : Possess a bachelor's degree or higher in cybersecurity, computer science, information technology, or a related field from an accredited higher education institution in the United States.

    Experience : Demonstrate years of experience providing CISO-level services, specifically virtual or remote services. Prove the ability to convey complex security concepts to non-technical stakeholders. Demonstrate leadership experience, especially in advising executive teams and boards on cybersecurity.

    Certifications : Demonstrate relevant professional certifications such as CISSP, CISM, or CISA to validate skills and knowledge.

  • Compliance & Risk Management :
  • Demonstrate knowledge of regulatory requirements and risk management practices.

    About Us :

    InterSources Inc. is a Small, Woman, and Minority-Owned Business Enterprise, ISO / IEC 27001, SOC 2 Type 2 certified company with massive 18+ years of diversified experience in providing IT Consulting Services, Artificial Intelligence, Data Analysis, Application Development, Cloud Services, Cybersecurity, Digital Marketing, ERP Management, Custom Software Development, Web Development, UI / UX Design, System Integration, QA Support etc. We make reasonable accommodations for clients and employees, and we do not discriminate based on any protected attribute including race, religion, color, national origin, gender sexual orientation, gender identity, age, or marital status. We also are a Google Cloud and Oracle partner company.

    Create a job alert for this search

    Information Security Manager • Syosset, NY, United States

    Related jobs
    • Promoted
    • New!
    Agency Chief Information Security Officer

    Agency Chief Information Security Officer

    City of New YorkNew York, NY, United States
    Full-time
    Agency Chief Information Security Officer.Agency : OFFICE OF LABOR RELATIONS.Job Category : Technology, Data & Innovation. Compensation : USD 114,930 - USD 173,473.The CISO is responsible for maintaini...Show moreLast updated: 2 hours ago
    • Promoted
    • New!
    Chief Information Security Officer

    Chief Information Security Officer

    GlocommsNew York, NY, United States
    Full-time
    This range is provided by Glocomms.Your actual pay will be based on your skills and experience talk with your recruiter to learn more. Registered Investment Advisors (RIAs).Chief Information Securit...Show moreLast updated: 2 hours ago
    • Promoted
    • New!
    Chief Information Security Officer

    Chief Information Security Officer

    Amalgamated BankNew York, NY, United States
    Full-time
    Amalgamated Bank seeks a dedicated Chief Information Security Officer to be r esponsible for designing and implementing the Bank’s Information Security program while protecting the business from cy...Show moreLast updated: 2 hours ago
    • Promoted
    Chief Information Security Manager

    Chief Information Security Manager

    Staffing the UniverseSyosset, NY, United States
    Full-time
    Chief Information Security Manager.Address : Syosset, NY (Hybrid) Full Time Position Scope Of Work : The vCISO shall provide expert virtual cybersecurity services during normal business hours except ...Show moreLast updated: 30+ days ago
    • Promoted
    • New!
    Chief Information Security Officer

    Chief Information Security Officer

    Credit GenieNew York, NY, United States
    Full-time
    Credit Genie is a mobile-first financial wellness platform designed to help individuals take control of their financial future. We leverage artificial intelligence to provide personalized insights a...Show moreLast updated: less than 1 hour ago
    • Promoted
    Chief Information Security Officer

    Chief Information Security Officer

    Grayson Search PartnersCity of White Plains, NY, United States
    Full-time
    Grayson Search Partners provided pay range.This range is provided by Grayson Search Partners.Your actual pay will be based on your skills and experience — talk with your recruiter to learn more.Chi...Show moreLast updated: 5 days ago
    • Promoted
    • New!
    Chief Information Security Office-Strategy, Programs & GRC AVP

    Chief Information Security Office-Strategy, Programs & GRC AVP

    Bank of ChinaNew York, NY, United States
    Full-time
    This incumbent will provide Strategy, Programs, Governance, Risk and Compliance functions as required to fulfill BOCNY information security program requirements. This incumbent will provide Strategy...Show moreLast updated: 2 hours ago
    • Promoted
    • New!
    Chief Information Security Officer (CISO)

    Chief Information Security Officer (CISO)

    VISTRADANew York, NY, United States
    Full-time
    Chief Information Security Officer (CISO).Vistrada is looking to hire strong Chief Information Security Officers (CISO).The CISO will provide strategic cybersecurity guidance and oversight to Vistr...Show moreLast updated: 2 hours ago
    • Promoted
    Head of Information Security Operations

    Head of Information Security Operations

    Point72New York, NY, United States
    Full-time
    A CAREER WITH POINT72'S TECHNOLOGY TEAM.As Point72 reimagines the future of investing, our Technology group is constantly improving our company's IT infrastructure, positioning us at the forefront ...Show moreLast updated: 30+ days ago
    • Promoted
    • New!
    Head of Information Security

    Head of Information Security

    Motion RecruitmentNew York, NY, United States
    Full-time
    Head of Information Security - Role Overview.Our client is on a mission to transform the way IT assets are managed for today's distributed workforce. As a rapidly growing organization, they are deve...Show moreLast updated: 2 hours ago
    • Promoted
    • New!
    Chief Information Security Officer (CISO) | Information Technology

    Chief Information Security Officer (CISO) | Information Technology

    Rockefeller UniversityNew York, NY, United States
    Full-time
    Information Technology (IT) aims to provide information resources and services to accelerate and support scientific research and administrative operations at The Rockefeller University.Our departme...Show moreLast updated: 2 hours ago
    • Promoted
    • New!
    Chief Information Security Officer

    Chief Information Security Officer

    Party CityWoodcliff Lake, NJ, United States
    Full-time
    PCHI) is a global leader in the celebrations industry, with its offerings spanning more than 70 countries around the world. PCHI is also the largest vertically integrated designer, manufacturer, dis...Show moreLast updated: 2 hours ago
    • Promoted
    Chief Information Security Officer (CISO)

    Chief Information Security Officer (CISO)

    ConfidentialNew York, NY, United States
    Full-time
    Chief Information Security Officer (CISO).Innovative provider of cloud-based software & touchscreen hardware.Privately Held, Private Equity-backed. Information Technology & Services.The Company is s...Show moreLast updated: 30+ days ago
    • Promoted
    • New!
    Head of Information Security

    Head of Information Security

    ConfidentialNew York, NY, United States
    Full-time
    Forward-thinking organization providing IT asset management solutions.Information Technology and Services.The Company is in search of a Head of Information Security to spearhead the development and...Show moreLast updated: 2 hours ago
    • Promoted
    • New!
    Mercer Chief Information Security Officer (CISO)

    Mercer Chief Information Security Officer (CISO)

    MMC CorporateNew York, NY, United States
    Full-time
    We are seeking a talented individual to join our Information and Security team at Mercer.This role can be based in New York, Boston, Dallas, Denver, Houston, Louisville, Morristown, Phoenix, Urband...Show moreLast updated: 2 hours ago
    • Promoted
    • New!
    Chief Information Security Officer

    Chief Information Security Officer

    Amalgamated Bank of NYNew York, NY, United States
    Full-time
    Amalgamated Bank seeks a dedicated Chief Information Security Officer to be responsible for designing and implementing the Bank's Information Security program while protecting the business from cyb...Show moreLast updated: 2 hours ago
    • Promoted
    • New!
    Assistant Chief Information Security Officer

    Assistant Chief Information Security Officer

    ConfidentialNew York, NY, United States
    Full-time
    Assistant Chief Information Security Officer.We are a leading provider of mobile security and risk management solutions, dedicated to safeguarding organizations against cyber threats.The Company is...Show moreLast updated: 2 hours ago
    • Promoted
    Manager, Information Security

    Manager, Information Security

    Metropolitan Jewish Health SystemNew York, NY, United States
    Full-time
    Our Corporate team may not provide direct care, but we still touch people's lives in a very real and substantial way.The services we provide contribute greatly to the overall patient and member exp...Show moreLast updated: 3 days ago