Group Chief Information Security Officer
$350k - $400kThe Security Executive Council
Group Chief Information Security Officer
Organization:
Location:
New York, NY
Description:
Job Summary
The Chief Information Security Officer (CISO) will lead and oversee the Information Security program across the entire organization. The role will be responsible for developing, implementing, and maintaining a unified enterprise security strategy that ensures the confidentiality, integrity, and availability of the company’s information assets, platforms, infrastructure, and customer data across all business operations.
As the organization continues to modernize its retail, digital, cloud, and enterprise technology platforms, we require a transformational security leader capable of driving the next phase of cybersecurity maturity across the group. This role is significantly broader than traditional cybersecurity operations and compliance management. The CISO will play a critical leadership role in helping the organization securely navigate large-scale technology transformation, AI adoption, cloud modernization, evolving regulatory requirements, and an increasingly sophisticated global threat landscape.
The CISO will be responsible for establishing and leading a group-wide cybersecurity strategy across both US and UK operations, driving consistency in governance, policy, standards, risk management, incident response, and operational security practices. This includes developing enterprise security standards, modernizing security architecture, implementing Zero Trust principles, strengthening cloud and identity security, improving business resilience, and reducing legacy technology and operational risk across the environment.
Cybersecurity has evolved far beyond traditional perimeter defense and audit-driven compliance programs. We now face a rapidly changing threat environment driven by AI-enabled attacks, ransomware, cloud complexity, third-party supply chain risk, increasing regulatory scrutiny, and growing operational dependence on digital platforms. As a result, the CISO must operate not only as a security leader, but also as a strategic business partner and an agent for transformation.
This role will require close collaboration with executive leadership, technology teams, legal, compliance, operations, and external partners to ensure security is embedded into the organization’s strategy and business operations. Given the strategic importance of cybersecurity and enterprise risk management to the organization, the CISO role will maintain a regular reporting cadence with the Board Risk Committee and will be responsible for providing ongoing updates related to cybersecurity posture, operational risk, regulatory compliance, major initiatives, emerging threats, and overall enterprise resilience.
What You Do
Global Security Strategy
- Define and execute a unified cybersecurity strategy that supports the business objectives of both B&N and Waterstones.
- Lead the development and implementation of security policies, standards, and procedures that align with local regulations and best practices.
- Serve as a trusted advisor to executive leadership and Board of Directors for both organizations.
Security Operations & Incident Response Leadership
- Lead the enterprise cybersecurity incident response and crisis management program, coordinating cross-functional response activities during major cyber incidents, ransomware events, operational disruptions, and data breaches.
- Act as the primary technical contact with external crisis response agencies, cyber insurance providers, legal counsel, forensic investigators, regulators, and law enforcement agencies during significant cybersecurity incidents.
- Drive the continuous maturation of the organization’s cyber resilience capabilities, including incident response planning, ransomware preparedness, disaster recovery, business continuity, tabletop exercises, and enterprise recovery strategies.
- Establish and maintain enterprise-wide cyber incident response standards, escalation procedures, communication protocols, and post-incident review processes to improve organizational readiness and operational resilience.
- Direct 24/7 global security operations, including monitoring, detection, and response to security incidents.
Technology & Infrastructure Security
- Leverage AI to improve detection, response, and scale.
- Ensure security is embedded in infrastructure, applications, cloud environments, and software platforms.
- Drive Zero Trust adoption, identity and access management, and secure data handling practices across both organizations.
- Oversee regular penetration testing, vulnerability assessments, and third-party risk management.
Team Leadership & Development
- Lead and foster collaboration between the B&N and Waterstones Information Security teams.
- Recruit, mentor, and retain top cybersecurity talent.
- Directs work and ensures appropriate performance levels of all Security team members across Waterstones and B&N, working together with the senior leadership team to create a performance-based culture.
- Partner with IT, Legal, Risk, HR, and other business units to ensure a holistic approach to Information Security.
Executive Leadership & Cybersecurity Influence
- Serve as a visible and influential cybersecurity leader across both organizations, representing the Information Security function internally and externally.
- Champion a strong culture of security awareness at all levels of the organization and across both businesses.
- Act as the public and internal face of the cybersecurity function, partnering with executive leadership, board members, auditors, and external partners to communicate the organization’s security vision and maturity.
AI-Enhanced Cyber Defense & Governance
- Leverage AI to improve detection, response, and scale.
- Automate incident triage and response (SOAR + AI).
- Enhance phishing and fraud detection using ML models.
- Collaborate with HR and Legal to define AI security policies and acceptable use standards.
- Classify and approve AI tools and vendors.
- Align with emerging regulatory frameworks (EU AI Act, etc.).
- Prevent data leakage into external AI platforms.
- Enforce data classification and masking for AI use.
- Monitor environment for unauthorized use of enterprise data in AI tools.
- Assess AI capabilities in vendor platforms.
Prepare For and Defend Against
- AI-generated phishing (highly personalized)
- Deepfake-based social engineering
- Automated vulnerability discovery by attackers
Update training and awareness programs accordingly.
Utilize AI to reduce reliance on manual Tier 1/2 SOC work.
Shift talent toward engineering, threat hunting, and strategy.
Integrate AI into security tooling stack (SIEM, EDR, XDR).
Knowledge & Experience
Data Security & Protection
- Define and enforce enterprise data security standards, policies, and controls to ensure the confidentiality, integrity, and availability of corporate and customer data.
- Establish data classification standards and ensure data is appropriately categorized, protected, retained, archived, and disposed of based on business and regulatory requirements.
- Oversee encryption standards and key management practices for data at rest, in transit, and within cloud environments.
- Ensure appropriate access controls, and privilege security models are implemented across enterprise platforms and data repositories.
- Partner with Legal, Compliance, and technology teams to ensure adherence to data privacy and regulatory requirements, including GDPR, PCI-DSS, SOX, CCPA, and other relevant industry standards.
- Develop and maintain Data Loss Prevention (DLP) strategies and monitoring capabilities to reduce the risk of unauthorized disclosure or exfiltration of sensitive information.
- Support the development of enterprise-wide awareness and training programs related to data handling, privacy, cybersecurity, and acceptable AI usage practices.
Third-Party & Supplier Risk Governance
- Establish third-party cybersecurity risk management program to assess, monitor, and mitigate risks associated with vendors, cloud providers, SaaS platforms, outsourced service providers, and strategic technology partners.
- Define security governance standards and due diligence processes for vendor onboarding, contract reviews, system integrations, and vendor risk assessments.
- Oversee continuous monitoring and risk evaluation of critical third-party providers, including incident response coordination, security assessments, penetration testing, and remediation monitoring if needed.
- Develop governance frameworks and contingency strategies to reduce operational, financial, and reputational risk associated with third-party cyber incidents, software supply chain compromise, and critical vendor outages.
Regulatory & Audit Compliance Responsibilities
- Lead the information security compliance program to ensure alignment with applicable regulatory, legal, and industry requirements across the organization, including SOX or equivalent, PCI-DSS, GDPR, UK GDPR, data privacy regulations, and other applicable corporate and retail compliance obligations.
Qualifications:
Education & Professional Background
- Bachelor’s degree in Information Security, Computer Science, Engineering, or a related field; advanced degree (e.g., MS in Cybersecurity) preferred.
- 15+ years of experience in Information Security, with at least 7 years in a senior or executive leadership role overseeing enterprise-scale security programs.
- Proven success leading global cybersecurity initiatives across multi-national or multi-brand organizations.
Technical & Strategic Expertise
- Deep understanding of information security frameworks, technologies, and architectures, including Zero Trust, cloud security, and identity management.
- Strong knowledge of regulatory requirements across U.S. and European jurisdictions, including GDPR, CCPA, and other privacy/security regulations.
- Demonstrated ability to balance security risk management, ensuring security strategies are aligned with business objectives.
- Experience in incident response, crisis management, and executive-level communications during security incidents.
Leadership & Influence
- Recognized as a strategic cybersecurity leader who can inspire trust and confidence at board, executive, and operational levels.
- Strong executive presence, with the ability to communicate complex technical concepts in clear, business-relevant terms.
- Proven capability to build, mentor, and lead high-performing security teams and encourage collaboration across geographies and business functions.
Certifications (Preferred)
- CISSP, CISM, CISA, CRISC, CCISO, or equivalent industry-recognized credentials.
Compensation:
Benefits for those who are scheduled to work less than 20 hours per week include Employee Discount, EAP and Sick Pay.
For those scheduled to work between 20 and 29.99 benefits include Employee Discount, EAP, Sick Pay and Paid Time Off including paid Maternity and Parental Leave, Company Paid Holidays, Transit and 401(k) with Company Match.
For those scheduled to work 30 hours or more benefits include Employee Discount, EAP, Sick Pay and Paid Time Off including paid Maternity and Parental Leave, Company Paid Holidays, 401(k) with Company Match, Comprehensive Health Benefits (Medical, Dental and Vision), Healthcare and Dependent Care Spending Accounts, Healthcare Spending Account, Disability Benefits, Life Insurance, Transit, and Tuition Reimbursement. All benefits provided are in accordance with the terms of the current plan and may be subject to future change. Benefits may vary depending on location/state regulations. More information can be received by the recruiter or Human Resources.
An employee in this position can expect an annual starting rate between $350,000 - $400,000 depending on experience, seniority, geographic locations, and other factors permitted by law.
We know how to fine-tune corporate security because we've led effective and efficient Fortune 500-level security programs. The SEC helps businesses find the best balance of risk mitigation, cost and innovation.
#J-18808-Ljbffr$350k - $400k
Job Summary The Chief Information Security Officer (CISO) will lead and oversee the Information Security program across the entire organization. The role will be responsible for developing, implementing, and maintaining a unified enterprise security strategy that ensures...SuggestedFull timeContract work- ...our Proof of Reserves. Across our multiple offices globally, we are united by our core... ...About the opportunity We're looking for a security leader for the Americas who's equally comfortable... ...team and within an outsourcing model to central Group affiliates. #J-18808-Ljbffr...Suggested
- Chief Information Security Officer (CISO) US or Canada Location: Remote (U.S. or Canada) Type: US Applicants - Full‑Time; Canadian Applicants - Independent... ..., we do not discriminate on the basis of any protected group status under any applicable law. Voluntary Self‑...SuggestedFull timeContract workFor contractorsFor subcontractorWork at officeRemote workDay shift
- ...CompanyArgo GroupArgo Group is an underwriter of specialty insurance products in... ...Inc.Job DescriptionBusiness Title(s): Chief Claims Officer, Argo Group Employment Type: Full-Time... ...on timely and meaningful exchanges of information. Possesses an extensive knowledge and...SuggestedFull timePart timeWork at office
$300k - $350k
...decided to fix it. National security professionals, journalists, parents... ...of their most personal information. The Team At Cape, we are the... ...Mission) The CISO is our chief protector. Our infrastructure... ...is based out of our NYC or DC office and reports to our founder and...SuggestedOdd jobFull timeWork at officeImmediate startRelocation package$125k - $150k
Job Description The Department of Records and Information Services is seeking to hire a Computer Systems Manager Non-Manager to serve as the Chief Information Security Officer (CISO). The Computer Systems Manager-Non-Manager will be responsible for compliance with the...Permanent employmentFull timeWork at officeShift workWeekend workAfternoon shift$350k - $400k
...exceptional service to seller and buyer clients. Executive Summary Compass International Holdings is seeking a seasoned Chief Information Security Officer to own and evolve the enterprise security program. This is an executive & highly technical role at the intersection...Flexible hours- ...Responsibilities Establish and execute an enterprise information security strategy and operating model aligned with business objectives and risk appetite. Continuously assess and strengthen Genworth’s cyber and technology risk posture in support of enterprise resilience...Contract workTemporary work
$300k - $375k
...regulatory compliance in everything we do. Join us and help build the future of global investing! About the Role As Chief Information Security Officer, you will be responsible for leading and strengthening the company’s entire security function across four key domains...Full timeWork at officeWorldwide$164.4k - $285.6k
...Corporate Relationship Manager U.S. Media & Entertainment Industries Group BMO's U.S. Media & Entertainment Industries Group ("MEIG") is... ...send an e‑mail to ****@*****.*** and let us know the nature of your request and your contact information. #J-18808-Ljbffr...Contract workWork experience placementLocal area- ...Chief Information Security Officer (CISO) About the Company Innovative online real estate platform Industry Real Estate Type Privately Held, VC-backed Founded 2012 Employees 1001-5000 Funding $200+ million Categories Curated Web...Local area
- ...Chief Information Security Officer (CISO) About the Company Established data management and secure communications firm serving highly regulated industries. Industry Information Technology and Services Type Privately Held About the Role The Company...
- ...Chief Information Security Officer (CISO) About the Company Trusted provider & publisher of consumer insights about car models & auto brands Industry Market Research Type Privately Held, Private Equity-backed Founded 1968 Employees 1001-5000...
- CHIEF INFORMATION SECURITY OFFICER THE POSITION IN A NUTSHELL Sciens is seeking a Chief Information Security Officer (CISO), who will be responsible for establishing and operating a right‑sized, risk‑based cybersecurity program that protects the company, supports growth...Temporary workWork experience placement
- CAIS is seeking a Chief Information Security Officer (CISO) who pairs deep technical expertise with strategic vision to lead the firm’s cybersecurity program and Operational Risk Management practices This role will drive security strategy—including AI security strategy...Work at officeFlexible hours
- Who are we? Cohere is the leading security-first enterprise AI company. We build cutting... ...in Toronto and San Francisco, with key offices in London, New York City, Montreal,... ...Join us! The Opportunity Cohere seeks a Chief Information Security Officer who can help shape...Full timeWork at officeLocal areaRemote workHome office
$300k - $375k
Chief Information Security Officer Location: New York, NY (Hybrid) Pay Range: $300,000 USD - $375,000 USD About The Role As Chief Information Security Officer, you will lead and strengthen the company’s entire security function across Governance, Risk & Compliance (GRC...Visa sponsorship$125k - $150k
...partners - City Hall and the Office of Mass Engagement (to whom PEU... ...with a very diverse group of stakeholders. They will know... ...Planning M1 to function as a Chief Strategy Officer who can help... ...described in "1" above. Additional Information The City of New York is an...Full timeWork at officeMonday to FridayFlexible hoursShift work$250.44k - $375.67k
...Reserves. Across our multiple offices globally, we are united by... ...opportunity We're looking for a security leader for the Americas who's... ...outsourcing model to central Group affiliates. Nice to have... ...of race, color, genetic information, creed, religion, sex, sexual...Full time- ...PNC Financial Services Group, Inc. seeks a Managing Director, MBS Portfolio Manager to lead their... ...investments in agency mortgage-backed securities and working closely with portfolio managers and the Chief Investment Officer. The ideal candidate will possess at least...Work at office
$150k
...Overview Our top-notch Information Security team quickly finds and responds to real time threats. These critical thinkers have... ...in this growing and ever-changing field. The Deputy Chief Information Security Officer (Deputy CISO) serves as the principal lead to the...Full timeTemporary workApprenticeshipWork at officeLocal areaImmediate startRemote workFlexible hoursShift work$250k - $275k
...more enjoyable, more productive and more secure. Since our founding almost a century... ...organization and reporting to the Chief Information Officer (CIO), this role provides thought leadership... ...committees and project steering groups. Oversight of Security Architecture and...Immediate startFlexible hours$100 per hour
...Chief Technology Officer April 2026 About NYC Kids RISE NYC Kids RISE is a nonprofit... ...can contribute to groups of these NYC Scholarship Accounts... ...school family—and as secure and efficient record-keeping... ...College Program’s data and information systems as well as overseeing...Work at officeWork from homeFlexible hours- ...A stealth-mode fintech group operating in the cross-border payments space requires an Interim CTO to bridge a 6-month leadership gap during a critical product scaling phase. This is a board-level engagement with direct P&L accountability. The successful candidate will...Interim role
- ...Client Executive - Small Cap Investment Banking Coverage Group, Managing Director NY, United States Job Identification 210776... ...under pressure and tight deadlines, synthesize large volumes of information, and to develop innovative solutions. Adaptability and independence...Full timeShift work
- ...Job Information Level: G8 Division/Office: Division of Instructional and Information Technology... ...1,800 schools. The Chief Information Officer... ...alongside data privacy, security, and best practices. It manages... ...and user/stakeholder groups, external partners, City...Full timeTemporary workWork at office
- .... Teaching hours depend on teacher availability within the schedule options above. Role Overview • Teach engaging 1-on-1 or small group (2-6 students) online classes • Deliver lessons using structured teaching materials (textbooks, slides, etc.) • Track student progress...Part timeRemote workWorldwideFlexible hours
$220k - $385k
...global travel brand of Zurich Insurance Group, one of the world’s leading multi-line insurers... ...in Computer Science, Engineering, Information Systems, Data Engineering, or a related... ...balance with the flexibility of 3 days in the office and 2 days working from home. Career...Temporary workWork at officeLocal areaWork from homeWorldwide- ...Cybersecurity Assessments And Exercises Vice President Drive the security of critical banking applications and platforms through hands-on... ..., security research, and participation in relevant industry groups. Contribute to the continuous improvement of penetration...
- ...site collection efforts as well as an in‑office presence at the primary firm office,... ...train other team members to increase the group’s overall knowledge base as well as cultivate... ...with CGS on our Job Board: For more information about CGS please #J-18808-Ljbffr CGS...Full timeWork at officeRemote workFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Group Chief Information Security Officer. Be the first to apply!
- information security officer New York, NY
- business information security officer New York, NY
- information security officer iso New York, NY
- ciso New York, NY
- chief information security officer New York, NY
- chief information security officer ciso New York, NY
- information security analyst New York, NY
- information security compliance analyst New York, NY
- director information security New York, NY
- information security internship New York, NY



