San Jose, CA
Receive $500.00 when you refer someone to this job and gets hired!
Get $500.00 when you refer someone and they get the job!
We are looking for an ISO to assume overall responsibility for all aspects of information security throughout our company and be responsible for ensuring that our environment and processes are secure and in compliance with all relevant government regulations and contractual obligations.
Responsibilities:
· Develop technical security policies, standards, guidelines and procedures
* Assess functions and environments for compliance to existing information security policies, standards, regulatory requirements, or best practices.
* Work with IT and business support teams to influence policy compliance and adoption across global organization.
* Ensure general information security (putting the proper measures in place to protect the confidentiality, integrity and availability of information).
* Identify, prioritize and track information security vulnerabilities.
* Advise senior management on identified vulnerabilities and appropriate information security structures, policies and procedures.
* Establish, maintain and customize information security controls to provide cost effective protection that is responsive to the confidentiality, integrity and availability needs for information owned by or in our client's custody.
* Coordinate with the Information Technology Department on protection goals, objectives and metrics to measure effectiveness of new procedures and policies.
* Coordinate with the Legal Department on compliance with all relevant laws and confidentiality requirements.
* Coordinate with the Finance Department in ensuring implementation and maintenance of appropriate policies and controls.
Requirements:
· At least 3 years with primary focus of activities in information security, with at least 1 year of senior level responsibility for organizational information security.
· Bachelors degree in Computer Science, Computer Information Systems, Management Information Systems, or other related field required. Advanced degree highly desirable.
· Minimum of 10 years of professional experience.
· Ability to assess, analyze and propose efficient and cost effective solutions to identified risks.
· Knowledge / familiarity with current security policy compliance requirements such as HIPAA, GLB, SOX, PCI DSS.
· Familiarity with NIST and other applicable security standards.
· Significant project management experience.
· Experience in managing Incident Response teams.
· Demonstrated ability to present plans and proposals to Executive Management
· Experience in the development and implementation of security programs, policies, and procedures.
· CISSP certification
Preferred:
· Substantial (min 2-3 years) early experience as a software developer and/or information technology specialist.
· NSA IAM and IEM certification