drjobs Virtual Chief Information Security Officer vCISO

Virtual Chief Information Security Officer vCISO

Employer Active

1 Vacancy
drjobs

Job Alert

You will be updated with latest job alerts via email
Valid email field required
Send jobs
Send me jobs like this
drjobs

Job Alert

You will be updated with latest job alerts via email

Valid email field required
Send jobs
Job Location drjobs

UK

Monthly Salary drjobs

Not Disclosed

drjobs

Salary Not Disclosed

Vacancy

1 Vacancy

Job Description

Your Career

Our leading consultancy seeks a dynamic and visionary vCISO to champion and operationalize cybersecurity best practices for a key public sector client. This crucial role will act as an account CISO and requires a trusted advisor who can effectively engage with client stakeholders (including CISOs security teams IT management and executive leadership) across the account. The vCISO will primarily be responsible for the delivery of security services as part of a largescale transformation programme and will also be required to identify and develop additional opportunities within the broader client organisation. 

This position requires a seasoned cybersecurity professional eager to influence client outcomes and drive meaningful improvements to their security posture. This role is key in managing and reducing operational security risks for our public sector clients to acceptable levels by leading remediation programs and guiding the implementation of appropriate security controls. 

The vCISO will serve as the primary point of contact for all client cybersecurity matters and requires a broad understanding of security control implementation within various corporate environments. Success in this role hinges on exceptional relationship management skills and the ability to drive adoption of recommended security solutions within the client organization.

Your Impact

Client Engagement and Programme Delivery:

  • Serve as a trusted security advisor to client stakeholders including CISOs security teams IT management and executive leadership. 

  • Work with different delivery partners across a complex product and service ecosystem to pragmatically manage risk and drive successful outcomes. 

  • Develop and own the programme delivery and security services operational risk register

  • Develop deep trusted relationships across the client organization fostering open communication and collaboration.

  • Provide strategic guidance and mentorship to client security teams empowering them to effectively manage security risks.

  • Present security recommendations and findings to various client audiences tailoring communication to the specific group.

  • Represent our consultancy on client calls and escalations offering expert security advice and guidance.

  • Champion security best practices within the client organization and drive the adoption of recommended solutions.

Thought Leadership & Industry Collaboration:

  • Maintain an uptodate understanding of UK government security policies

  • Stay abreast of industry best practices emerging threats and regulatory changes to provide cuttingedge guidance to clients.

  • Share relevant industry insights and best practices with the clients security team to foster continuous improvement.

  • Support executive engagement / peer relationships across the UK Public Sector and international peers.

Security Risk Management & Remediation:

  • Conduct cybersecurity risk assessments vulnerability analyses and maturity assessments for clients.

  • Develop and implement clientspecific cybersecurity roadmaps strategies policies and procedures.

  • Provide expert advice on security architecture incident response disaster recovery and business continuity planning.

  • Oversee and guide client security teams in implementing and managing security controls.

  • Assist clients with compliance requirements related to various regulations (GDPR CCPA HIPAA PCI DSS etc.) and standards (e.g. ISO 27001 SOC 2).

  • Manage security risk committees to support client cyber risk management practices.

  • Track and manage remediation of security audit and compliance findings for clients.

  • Review security metrics and lead remediation programs within the clients environment.

  • Lead or sponsor client security initiatives.

  • Ensure necessary security controls are in place in conjunction with client data privacy initiatives.


Qualifications :

Your Experience 

  • Proven experience as an inhouse CISO or as vCISO within a consulting or systems integrator organisation.

  • 10 years of experience in cybersecurity with expertise in areas like email security cloud security incident response application security vulnerability management network security cloud security security operations physical security and supplier risk management.

  • Strong experience in implementing and operating security controls in complex corporate environments.

  • Demonstrated ability to engage with Clevel executives and deliver impactful presentations.

  • UK public sector experience preferably within Emergency Services.

  • Deep understanding of UK public sector security policies compliance/assurance requirements and audit practices. 

  • Understanding of industryrecognised cybersecurity frameworks (NIST ISO 27001 CIS) global privacy regulations and emerging threats.

  • Current holder of (or able to be cleared to) SC and ideally DV security clearance.

  • Experience of working in multiprovider multiyear programmes.

  • Proven track record of building and implementing account growth strategies both in terms of security maturity and business development.

  • Exceptional communication (written/verbal) presentation and interpersonal skills including the ability to communicate technical concepts to diverse audiences.

Highly Desired:

  • Advanced degree in Cybersecurity Business Administration or a related field.

  • Professional certifications such as CISSP CISM CCISO or GIAC.

  • Experience with ISO 27001 Cyber Essentials and other relevant compliance standards.

  • Published thought leadership and public speaking experience at major industry events.


Additional Information :

The Team

Unit 42 brings together our worldrenowned threat researchers with an elite team of security consultants to create an intelligencedriven response ready organization. The Unit 42 Threat Intelligence team provides threat research that enables security teams to understand adversary intent and attribution while enhancing protections offered by our products and services to stop advanced attacks. As threats escalate Unit 42 is available to advise customers on the latest risks assess their readiness and help them recover when the worst occurs.

Our Commitment

Were problem solvers that take risks and challenge cybersecuritys status quo. Its simple: we cant accomplish our mission without diverse teams innovating together.

We are committed to providing reasonable accommodations for all qualified individuals with a disability. If you require assistance or accommodation due to a disability or special need please contact us at  .

Palo Alto Networks is an equal opportunity employer. We celebrate diversity in our workplace and all qualified applicants will receive consideration for employment without regard to age ancestry color family or medical care leave gender identity or expression genetic information marital status medical condition national origin physical or mental disability political affiliation protected veteran status race religion sex (including pregnancy) sexual orientation or other legally protected characteristics.

All your information will be kept confidential according to EEO guidelines.


Remote Work :

Yes


Employment Type :

Fulltime

Employment Type

Remote

Company Industry

Key Skills

  • International Development
  • Information Systems
  • Community
  • Information Technology Sales
  • Corporate Recruitment

About Company

Report This Job
Disclaimer: Drjobpro.com is only a platform that connects job seekers and employers. Applicants are advised to conduct their own independent research into the credentials of the prospective employer.We always make certain that our clients do not endorse any request for money payments, thus we advise against sharing any personal or bank-related information with any third party. If you suspect fraud or malpractice, please contact us via contact us page.