Virtual Chief Information Security Officer (vCISO)

Virtual Chief Information Security Officer (vCISO)

Vollzeit Vor Ort
M

h3DESCRIPTION /h3pAs a vCISO, you will play a critical role in ensuring the security of our organization's systems and infrastructure. You will be responsible for supporting governance initiatives, assessing and managing risks, ensuring compliance with relevant regulations and standards, and providing technical expertise to enhance system security engineering. Additionally, you will support responsibilities related to SOC 2 Type II, HIPAA, and PCI compliance audits while ensuring the security of systems and infrastructure through strategic oversight. /ph3POSITION SUMMARY /h3pAs a vCISO, you will play a critical role in ensuring the security of our organization's systems and infrastructure. You will be responsible for supporting governance initiatives, assessing and managing risks, ensuring compliance with relevant regulations and standards, and providing technical expertise to enhance system security engineering. Additionally, you will support responsibilities related to SOC 2 Type II, HIPAA, and PCI compliance audits while ensuring the security of systems and infrastructure through strategic oversight. /ph3RESPONSIBILITIES AND DUTIES /h3ulliGovernance, Risk, and Compliance (GRC): /liliAssist in the development, implementation, and maintenance of effective cyber security policies, procedures, and standards. /liliSupport governance initiatives by establishing and maintaining security frameworks, controls, and documentation. /liliConduct risk assessments and work closely with stakeholders to identify, analyze, and mitigate potential security risks. /liliEnsure compliance with relevant regulatory requirements, industry standards, and best practices. /liliAssist in the preparation and participation in security audits and assessments. /liliSystem Security Engineering: /liliCollaborate with cross-functional teams to incorporate security controls and requirements into system design and development processes. /liliConduct security architecture reviews and provide technical guidance to ensure the implementation of robust security measures. /liliPerform security assessments and penetration testing on systems, networks, and applications. /liliIdentify vulnerabilities, analyze security flaws, and recommend remediation strategies. /liliStay updated with emerging threats, vulnerabilities, and security technologies to enhance system security engineering practices. /liliIncident Response and Security Monitoring: /liliContribute to the development and testing of incident response plans and procedures. /liliParticipate in security incident investigations, root cause analysis, and remediation efforts. /liliCollaborate with the incident response team to implement proactive security monitoring and threat detection measures. /liliAssist in the deployment and management of security monitoring tools and technologies. /li /ulh3QUALIFICATIONS /h3ulliBachelor’s degree in computer science, Information Technology, or a related field. /liliProven experience as a Cyber Security Engineer, Security Analyst, or a similar role. /li liStrong understanding of cyber security principles, risk management methodologies, and compliance frameworks. /liliIn-depth knowledge of security technologies, including firewalls, intrusion detection/prevention systems, SIEM, and vulnerability scanning tools. /liliFamiliarity with regulatory requirements (e.g., GDPR, HIPAA), industry standards (e.g., NIST, ISO 27001), and frameworks (e.g., COBIT, ITIL). /liliExperience with and interpreting cyber security framework (e.g., NIST CSF, HIPAA HITRUST, CIS20, CSA CSF) /liliExperience in system security engineering, secure software development, or secure system design. /liliProficiency in conducting security assessments and vulnerability management. /liliFamiliarity with incident response processes and security monitoring practices. /liliExcellent problem-solving and analytical skills. /liliStrong communication and collaboration abilities. /liliRelevant certifications such as CISSP, CISM, CASP+, or GIAC are highly desirable. /li /ulh3HOURS SCHEDULE /h3pThis position is primarily business hours (Monday-Friday 8am – 5pm EST) with occasional after-hours work for incident troubleshooting or project work. All engineers are part of an on-call rotation and may be escalated issues off hours. /ph3WORK PERKS /h3ulli100% permanently remote position with no plans to return to an office /liliExtensive paid time off including paid holidays and float holidays /liliHighly competitive and flexible medical, dental, and vision benefits plans to suit your needs /lili401(k) with generous employer match /liliTailored Life and Disability insurance plans /liliFull reimbursement for approved professional certification and career enriching opportunities /liliMonthly mobile phone plan and internet service stipend /li /ulh3What We Do /h3pMagna5 is a rapidly growing IT Managed Service Provider delivering cybersecurity, private and public cloud hosting, backup and disaster recovery and other advanced services from mid-market to enterprise customers nationwide, including leaders within the education, healthcare, government, financial services, manufacturing, and other industry segments. We integrate advancements in technology and processes to drive businesses forward. As a trusted managed services provider, we bring together the right mix of managed IT services, security, and network connectivity, fully managed by our team of experts 24/7/365. Our passion is to help companies function better, faster, and smarter. We offer an exciting and collaborative environment, with growth potential. For more information, visit our website at /p #J-18808-Ljbffr

M

Kontaktdaten:

Magna5 Recruiting-Team