Chief Information Security Officer
Company: Dmsusa
Location: Hayward
Posted on: May 29, 2023
|
|
Job Description:
** Chief Information Security Officer****Job Category****:**
Information Technology **Requisition Number****:** CHIEF005413
Showing 1 location **Job Details****Description**Ultra Clean
Technology is conducting a search for an experienced and highly
qualified **Chief Information Security Officer (CISO)** in our
**Hayward, CA** facility. The CISO is responsible for establishing
and maintaining the enterprise vision, strategy, architecture, and
a multi-year roadmap that ensures that UCTs information assets are
adequately protected. A key element of this role is communicating
security at a strategic level to executive management, the Audit
and Compliance Board, and the Board of Directors and evangelizing
security across the business to drive adoption of security best
practices. The CISO will manage a small team of dedicated resources
and a larger team of matrixed resources.**Essential Duties and
Responsibilities:*** Develop and implement a strategic, long-term
information security strategy and roadmap to ensure that UCTs
information assets are adequately protected.* Work with senior
leaders across the business to assess and communicate acceptable
levels of risk.* Identify, evaluate and report on information
security risks, practices and projects to the Executive Committee
and the Board of Directors, and provide subject matter expertise on
security standards and best practices (e.g. FFIEC, Dodd-Frank, SOX,
PCI, etc.).* Develop, mentor, and manage a high performing staff of
information security professionals.* Chair the information security
steering committee.* Develop the Boards understanding of security
beyond a compliance-only view.* Lead the development of up-to-date
information security policies, procedures, standards and
guidelines, and oversee their approval, dissemination, and
maintenance.* Ensure that the security management program is in
compliance with applicable laws, regulations, and contractual
requirements.* Act as the champion for the enterprise information
security program and foster a security-aware culture.* Oversee the
evaluation, selection and implementation of information security
solutions that are innovative, cost-effective, and minimally
disruptive.* Partner with enterprise architects, infrastructure,
and applications teams to ensure that technologies are developed
and maintained according to security policies and guidelines.*
Manage regular intrusion detection and vulnerability reporting,
internal and external IT audit groups reviews, and the coordination
of all required fixes.* Develop business metrics to measure the
effectiveness of the security management program and increase the
maturity of the program over time.* Monitor the industry and
external environment for emerging threats and advise relevant
stakeholders on appropriate courses of action.* Liaise with law
enforcement and other advisory bodies as necessary to ensure that
the organization maintains a strong security posture.* Oversee
incident response planning and the investigation of security
breaches, and assist with any associated disciplinary, public
relations and legal matters.* Oversee and lead the creation,
communication, and implementation of a process for managing vendor
risk and other third-party risk.* Lead due diligence and post
integration activities related to information security for all
M&A activity.**Other Duties**Please note this job description
is not designed to cover or contain a comprehensive listing of
activities, duties or responsibilities that are required of the
employee for this job. Duties, responsibilities, and activities may
change at any time with or without notice.**Knowledge, Skills and
Abilities:*** A proven track record in developing information
security policies and procedures, and successful execution.*
Extensive knowledge of business risk, risk assessment and
risk-based decision making.* Able to communicate security and
risk-related concepts to both technical and non-technical audiences
(in business terms), including board level.* A natural influencer
and coalition builder; passionate about building high performing
teams.* Ability to inspire and motivate cross-functional,
interdisciplinary teams to achieve tactical and strategic goals, an
innovative leader, problem solver and consultant.* Ability to
evangelize IT security to make it a critical part of business
operations; build trust and respect for the security function.*
Excellent written and verbal communication, interpersonal and
collaborative skills.* Experienced with contract and vendor
negotiations.* Ability to effectively prioritize and execute tasks
in high-pressure situations.* Knowledge of security, risk and
control frameworks and standards such as ISO 27001 and 27002,
SANS-CAG, NIST, FISMA, COBIT, COSO and ITIL.* Understanding of
cloud, SaaS, and IoT architectures, and their implications on
information security strategy.* Technical acumen including but not
limited to: OSI, IT infrastructure, cloud, application development
languages, tools and frameworks, database technologies, web
technologies, next gen mobile, network architecture, enterprise
architecture, and directory services.* Security technology acumen
and experience including but not limited to firewall, intrusion
detection, cyber-attack tools and defenses, encryption, certificate
authority, web filtering, anti-malware, anti-phishing, identity,
and access management, multi factor
authentication.**Educational/Certification Requirement:***
Bachelors Degree in computer science, engineering, or a related
field; (graduate degree preferred).* Professional certifications,
such as a CISSP, CISM, CISA.**Experience Requirement:****Work
Experience:** * Minimum 10 years of IT and/or business leadership
experience, and 5+ years of information security/cybersecurity
experience.**Physical Demands and Working Conditions:** *This
section is required for compliance with the Americans with
Disabilities Acts (ADA)***Criteria:****Work Environment:***
Reasonable accommodations may be made to enable individuals with
disabilities to perform the essential functions* Work is performed
primarily in an office environment**Work Hours:*** Standard Office
Hours**Physical Demands:*** Ability to kneel, reach, walk, push,
pull and grasp.* Ability to lift up to 25 lbs. * Ability to move
arms, hands, and fingers* Ability to sit or stand for sustained
periods of time.* Required to wear personal protective equipment.*
The ability to talk on the phone and use the computer for extended
periods of time may be required.**Environmental Exposure:***
Required to wear personal protective equipment where applicable.*
Subject to frequent interruptions.* The ability to talk on the
phone and use the computer for extended periods of time may be
required.* May involve exposure to moderate noise levels from
printers, faxes, computers, etc.**Travel:*** Work may require
out-of-town travel depending upon assignment (training and
meeting). 15%* Local travel to various worksites is
required.**UCT** offers an excellent benefits package to all
full-time employees which includes medical, dental, vision, 401(k),
and paid time off.**UCT** is an equal opportunity employer,
dedicated to promoting a culturally diverse
workforce.**Qualifications****Skills****Behaviors****:**
**Motivations****:** **Education****Experience****Licenses &
Certifications**
Keywords: Dmsusa, Hayward , Chief Information Security Officer, Executive , Hayward, California
Click
here to apply!
|