About FlightSafety International
FlightSafety International is the world's premier professional aviation training company and supplier of flight simulators, visual systems and displays to commercial, government and military organizations. The company provides training for pilots, technicians and other aviation professionals from 167 countries and independent territories. FlightSafety operates the world's largest fleet of advanced full-flight simulators and award-winning maintenance training at Learning Centers and training locations in the United States, Canada, France and the United Kingdom.
Purpose of Position
The VP, CISO is a key leadership role responsible for the enterprise Information Security & Risk program. This position leads all Information Security efforts in support of end-to-end security strategy, design, and operational support. The Information Security leader serves as the principal and accountable representative for the enterprise security roadmap and related matters, while building and delivering a highly collaborative working relationship with the end-user community as well as fellow technology and engineering teams. This role is both strategic and tactical, demonstrating strong technical capabilities in the risk / security arena while also exhibiting strong leadership skills within the team and across adjacent functions. This role partners closely with Information Technology while providing leadership and guidance on security implementations, purpose and priority. This position reports to the Chief Information Officer.
Tasks and Responsibilities
Oversee the development, implementation, and maintenance of the security strategy, risk and governance framework, based on National Institute of Standards and Technology (NIST),that can scale across multiple regulatory controls, geographies, and internal business units to enable a culture of security throughout the enterprise
- Create a metrics-driven culture using the appropriate methodologies, tools and communications practices.
- Translate technical risks into interpretable organizational risks for a wide range of business and leadership audiences, including the Board and Senior Leadership Team (SLT)
- Partner closely with the business and IT leadership to continually communicate on prioritized industry trends, threat groups / actors as well as emerging risks
- Collaborate with IT teams within both FSI & NetJets to ensure that security practices are integrated into all systems and processes, balancing security requirements with business agility
- Develop and implement security policies, protocols, and procedures to safeguard the company's data, intellectual property, and systems from internal as well as external cyber threats
- Monitor the external threat environment for emerging threats, advising relevant stakeholders, and coordinating with external agencies, such as law enforcement and other advisory bodies, to ensure that the organization maintains a strong security posture
- Define and implement 1st and 3rd party risk assessment processes and controls for new technology platforms
- Lead third-party security assessments for future and existing business partners
- Work with cyber insurance carriers to implement long term strategic initiatives that comply with external industry / insurance requirements
- Liaise with business control teams (i.e. Legal, Compliance, HR, Finance, etc.) and IT groups in the security analysis, design, and planning phases of IT and business-related projects to ensure practices are in line with organizational and regulatory policies
- Partner on security tactics across DevOps, Architecture, and Engineering to ensure robust security engineering practices are in place
- Establish a strong set of controls for SaaS solutions, enterprise cloud environments and cloud service provider platforms - such as Microsoft Azure, and others - and their embedded security as well as multi-cloud security management technologies
- Ensure all security incidents are properly investigated, remediated and appropriately communicated
- Lead internal and external security audits using a rigorous and repeatable methodology, security questionnaires, and provide consistent reporting of results
- Interact with government regulators and auditors across multiple jurisdictions domestically or globally
- Builds and leads a high-performing Information Security team; provides feedback & coaching to help team develop professionally and grow their skills
- Travel as required
- May perform other duties as assigned
Minimum Education
Bachelor's degree in Computer Science, Computer Engineering, Electrical Engineering, Business, or related field of study, requiredAdvanced degree, a plusRelated certification(s) required -Certified Information Systems Security Professional (CISSP), and Computer Information Security Manager (CISM), preferred - Certified Information Systems Auditor (CISA), or otherSecurity clearance requiredMinimum Experience
15 years of relevant information security, risk, and technology experience7+ years' experience in a supervisory capacityExperience operating in a matrixed organization supporting one or more business units or internal functionsExperience in strategic advisory that directly influences the organization's operating planExperience in project management and responsibility for an operating budgetSignificant experience in managing third party relationships and suppliersKnowledge, Skills, Abilities
Excellent written and verbal communication skills with high emotional intelligence, including the ability to explain technical concepts to senior leaders, middle management, and individual contributorsAbility to independently collaborate across a broad spectrum or stakeholders and senior leaders in a matrixed operating environment to achieve mutually beneficial resultsCollaborative ability to build rapport as a strategic partner, vertically within the function or business unit, as well as with senior leadership and other cross-functional teamsDemonstrated ability to adapt to changes rapidly, meet necessary timelines, and perform in a fast-paced work environmentResults-orientated with high drive to independently achieve objectives and formulate project plans or results from ambiguous directivesProblem solver with a focus on process, organization and detail orientationFocus on continuous improvement with the ability to drive organizational changeDemonstrated experience in key areas of cyber security such as : secure coding techniques, penetration testing, vulnerability management, network administration, event management, forensics, threat management, identity access management, data loss prevention, governance, and risk management practicesMust demonstrate knowledge of common information security management frameworks such as ISO / IEC 27001, ITIL, COBIT and NIST and an understanding of relevant legal and regulatory requirements such as Health Insurance Portability and Accountability Act (HIPAA) and Payment Card Industry / Data Security StandardFamiliarity with DoD cybersecurity policies, procedures, and frameworks, such as NISPOM, CMMC, NIST 800-53Experience working with or within DoD environments, understanding the unique security challenges and requirements of defense-related information systemsEstablished familiarity with common security methodologies, tools, controls, and common security flaws that apply to software development including, but not limited to : Logging, Encryption, SAST, DAST, IDS, IPS, IAMStrong understanding how technical controls can be applied to solve specific Information Security and risk problemsDemonstrated ability to define and articulate business impacts and risk to both technical and non-technical audiencesStrong ability to influence engineering teams and business partners on security and IT architecture and project roadmaps to effectuate positive and protective change for the enterpriseDemonstrated strength in the ability to motivate and lead a team of Information Security professionalsHigh regard for ethics; compliance with all company policies and proceduresMaintains regular and punctual attendanceProficient in Microsoft Office suite or related software, in particular Excel, Word, PowerPoint and OutlookOther software programs may be requiredFlightSafety is an Equal Opportunity Employer / Vet / Disabled. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, or disability.