Information Security Officer
Shaw Systems Associates
Chief Information Security Officer (CISO)
Shaw Systems is a leading national software provider serving the consumer lending and financial services industry. We are seeking a Chief Information Security Officer (CISO) to lead the protection of corporate and client information assets and drive a secure, scalable technology environment.
This role owns enterprise security strategy, operations, compliance, and risk management while enabling secure adoption of AI, cloud, and automation platforms. The ISO serves as Shaw's primary authority on information security, partnering across business, technology, and client teams to strengthen security posture and support growth.
Organizational Scope
- Direct Reports: Service Operations Manager, Senior Security Engineers, Security/InfoSec Analysts
- Team Size: ~8 FTEs + contractors + SOC partner
- Enterprise Reach: Full client portfolio (financial services focus)
- Cross-Functional Influence: AI Committee; DevOps, Cloud, Implementation
Responsibilities
1. Security Strategy & Program Leadership
- Define and mature enterprise information security strategy, policies, and standards
- Own and evolve Shaw's Information Security Program and SOC 2 Type II compliance
- Serve as primary security representative for clients, auditors, and executives
- Lead risk identification, mitigation, and enterprise security roadmap
- Oversee access controls, third-party risk, and security readiness exercises (DR, incident tabletop)
- Present security posture, risks, and compliance status to leadership and external stakeholders
- Hold named accountability for security representations in client agreements (including MSAs and processing agreements); present security posture and risk to clients, prospects, auditors, and executive forums as required
2. Security Operations (SecOps)
- Oversee 24/7 SOC operations (via partner) and incident response lifecycle
- Manage threat detection, monitoring, vulnerability management, and remediation
- Lead response to authentication threats, phishing, and unauthorized access events
- Maintain and enhance security tooling across the stack, including Microsoft Defender, FortiClient VPN, Arctic Wolf MDR, Keeper, KnowBe4, PAM solutions, and data protection technologies (e.g., DLP)
- Ensure endpoint, identity, and infrastructure security across cloud and on-prem environments
- Drive network, cloud, and infrastructure hardening initiatives
3. AI Governance & Security Architecture
- Lead enterprise AI security strategy and rollout (Copilot, LLMs, AI tools)
- Design and enforce AI governance framework (usage policies, data protection, access controls)
- Architect secure AI/LLM environments (mitigating data leakage, prompt injection, etc.)
- Own Microsoft Purview strategy (DLP, labeling, information protection)
- Represent AI security posture to clients, auditors, and leadership
- Manage strategic vendor relationships, including Microsoft, Anthropic, Arctic Wolf, Fortinet, Keeper, and other security and AI partners, ensuring enterprise value and risk alignment
4. Service Operations Oversight
- Provide leadership oversight to Service Operations (infrastructure, endpoints, support)
- Ensure reliability, patching, identity governance, and cloud operations (M365/Azure)
- Drive SLA performance, operational efficiency, and automation initiatives
- Ensure operational rigor through established tooling and cadences, including patch management (e.g., WSUS), endpoint monitoring, and environment audits
5. Compliance, Risk & Audit
- Co-own SOC 2 Type II audit lifecycle and evidence management
- Maintain enterprise risk register and mitigation tracking
- Lead client/vendor security assessments and regulatory readiness
- Ensure alignment with frameworks (ISO 27001, NIST, FFIEC, GLBA, SOX)
- Ensure third-party vendor due diligence, security requirements, and contractual obligations are aligned with Shaw's Information Security Program and documented appropriately
- Monitor regulatory developments (including AI and privacy laws)
- Own security representations in client agreements and audit responses
- Provide security review, guidance, and approval on security-related representations in client, regulatory, and third-party engagements, in partnership with executive leadership, Legal, and Compliance
6. Leadership & Culture
- Lead, mentor, and develop InfoSec and Service Ops teams
- Manage vendors, contractors, and partner performance
- Promote enterprise-wide security awareness and training programs
- Partner with HR on hiring, workforce planning, and organizational design
7. Strategic & Cross-Functional Collaboration
- Advise executive leadership on security and AI risk strategy
- Partner with DevOps, Cloud, and Implementation teams on secure design practices
- Support business development (security questionnaires, client discussions)
- Translate technical risk into business impact for diverse stakeholders
Requirements
Education
- Bachelor's or Master's degree in Computer Science, Engineering, or related field
Experience & Expertise
- 10+ years in information security leadership
- 5+ years securing cloud environments (Azure preferred, AWS acceptable)
- Strong experience with SOC 2, ISO 27001, NIST, OWASP, FFIEC, GLBA, SOX
- Deep technical background across DevOps, infrastructure, and security tooling
- Expertise in network security, IAM, DLP, SIEM, and vulnerability management
- Experience with Microsoft security stack (Defender, Purview, Intune, Entra ID, Azure)
- Demonstrated experience with AI platforms and governance (e.g., Copilot, LLMs)
- Financial services or lending industry experience preferred
Certifications
- CISSP (required)
- CCSP (required)
- ISSAP (preferred)
Leadership Competencies
- Strategic security leadership and business alignment
- AI governance and emerging technology risk management
- Operational execution and compliance discipline
- Strong communication, stakeholder influence, and executive presence
- Analytical problem-solving and results orientation
- Vendor and partner management expertise
Performance Expectations (First 12 Months)
- SOC 2 Type II audit completed with no material findings
- Enterprise AI governance framework fully implemented
- Microsoft Purview DLP and labeling deployed enterprise-wide
- Mature security operations cadence with measurable SLAs
- Updated BCP/DR program tested
- Improved phishing awareness and security training outcomes
Supervisory Responsibility
- Leads a team of internal, contractor, and external partners supporting security operations and enterprise infrastructure.
Location
- Hybrid: Within 75 miles of Houston, TX
- Remote (eligible states): TX, VA, FL, GA, ID, LA, MI, MN, NJ, NC, PA, UT
- Travel: 10–25% as needed
Work Environment
- Full-time, Monday–Friday; standard business hours with occasional after-hours support as needed.
- ...Network Security Administrator The Alaka`ina Foundation Family of Companies (FOCs) is looking for a Network Security Administrator... ...Technical Implementation Guide (STIGs) and Checklists, Defense Information Systems Agency (DISA) Security Compliance Checker (SCC)...SuggestedLocal areaRemote work
- ...Responsibilities & Qualifications We are seeking a Network Security Administrator to join ITSSsupporting Department of Navy... ...RMF (Risk Management Framework) . Coordinate with Information System Security Officers (ISSOs) and Information System Security Managers (ISSMs)...SuggestedFull timeContract workTemporary workFor contractorsWork at officeLocal areaDay shift
$91k - $95k
...programs, which may vary. Ready to Join the Movement? Apply today and start moving your career in the direction you want. For more information, visit or follow the brand on Facebook ( , Instagram ( , Twitter ( , YouTube ( and LinkedIn ( . Powered by JazzHR...SuggestedFull timeImmediate startWeekend work$101.84k - $127.34k
...opportunity in their community. Purpose of the Role As the Information Security Manager, you'll be reporting directly to the Senior Director... ...role is between $101,840 and $127,344. This is an in‑office role based at the Obama Presidential Center in Jackson Park,...SuggestedWork at office$150k - $175k
...Chief Impact Officer The Chief Impact Officer (CIO) is a key member of the Senior Leadership Team, responsible for shaping and advancing... ...measure and communicate impact. • Use data and insights to inform strategy, drive improvement, and support decision-making....Suggested$98.15k - $166.85k
...recruiting for an experienced Senior Cyber Security Analyst to support the research and... ...protect and defend its networks and critical information systems. This role will support a large... ...full-time employment is: $98,145.00 - $166,846.00 Florida Client Office (FL88)...Full timeContract workWork experience placementWork at officeRemote work2 days per week3 days per week- ...leadership, guidance, and technical guidance to ensure appropriate security protocols are leveraged to protect NFCU's brand, data, and IT... ...with change control procedures Expert knowledge of cyber/information security systems engineering lifecycle Experience managing...For contractorsInternshipMonday to Friday
- Division Chief Of Urology Nemours Children's Health, Pensacola is seeking a Division Chief of Urology to work in partnership with Studer Family Children's Hospital at Ascension Sacred Heart. Key Responsibilities Evaluates and treats patients with appropriate...Full timeRelocation
- ...Assisting with the 5 L's of operations: Leadership: Recruit and onboard program staff and volunteers Location: Research, secure and prepare facility and transportation Logistics: Coordinate details and maintain positive communications with the school Loot...Local area
- Job Description **Nemours is supportive of J-1 waiver candidates** Nemours Children's Health, Pensacola is seeking a Division Chief of Urology to work in partnership with Studer Family Children's Hospital at Ascension Sacred Heart. Key Responsibilities ...Relocation
- ...sponsored events throughout the year Background and Drug Screening Requirements- As part of our commitment to maintaining a safe and secure workplace, successful completion of a background check and drug screening is a mandatory condition for employment. All offers of...Temporary workPart timeWork experience placementShift work
- President The President will be responsible for providing strategic leadership, overseeing all aspects of the company's operations, and driving growth and profitability. The ideal candidate will have a strong background in the health and wellness industry, with a proven...
$89k - $143.75k
...Performing periodic risk assessment of security vulnerabilities in software for the product... .... Ability to work onsite at the J&J office in Santa Clara, CA. The expected base... ...year. For additional general information on Company benefits, please go to: This...Full timeTemporary workWork at officeLocal areaRemote workNight shift- ...in northern Indiana that has available office space. Periodic travel is required to perform... ...of appropriate course of action. Secures all property used as collateral... ...bankruptcy accounts. Accurately records information through Akcelerant regarding financial status...For contractorsWork at officeMonday to Friday
- ...Correctional Officer (Unarmed) We are seeking highly vigilant and professional Correctional Officers (Unarmed) to maintain safety... ...this crucial role, you will contribute to the facility's overall security framework by providing diligent monitoring and support, working...Flexible hoursNight shift
- ...Commercial Relationship Officer Job ID 2026-15327 Job Locations US-FL-Pensacola | US-FL-Pensacola | US-FL-Milton... ...procedures, and procedure manuals ~ Ability to effectively present information and respond to questions from groups of managers, clients,...Contract workLocal area
$150k - $175k
...? Join WWT today! What will you be doing? World Wide Technology, Inc. (WWT) is seeking a highly driven and experienced Cyber Security Specialist to join our dynamic Security Sales team. In this role, you will collaborate closely with cross-functional teams to develop...Full timeRemote workShift work- ...Epic solutions meet regulatory, patient safety, privacy, and security requirements.• Proactively identify and mitigate program risks... ...Effectively communicates departmental, organization, and industry information to staff.• Assists in other duties as assigned to support the...Full timeLocal areaImmediate startShift work
- ...regarding medications. Along with all other correctional institution employees, incumbent is charged with responsibility for maintaining security of the institution. The staff correctional responsibilities precede all others required by this position and is performed on a...Contract work
- ...make life's journey more meaningful. Equal Opportunity Employer This employer is required to notify all applicants of their rights pursuant to federal employment laws. For further information, please review the Know Your Rights notice from the Department of Labor....
- Job Title Quality Control Inspector Job Description Individual contributor. Assure products are manufactured to pre-determined specifications. Tests and inspects products at various stages of production processes. Evaluates data to determine and maintain quality...Full timeShift work
- ...transportation in good working condition Must be able to safely drive an automobile in all types of weather conditions Additional Information As a national leader in home-based care, Enhabit is consistently ranked as one of the best places to work in the country. We'...Local areaWork from home
$50k - $95k
...awareness. Responsibilities: Analyze the potential of the company's service area to determine target markets. Visit Doctor' offices, hospitals, Assisted Living facilities, Skilled Nursing Facilities and other possible sources of referrals to present Agency...Full timeTemporary workWork at officeRemote workVisa sponsorshipFlexible hours- Overview Connect Care. Guide Families. Make Every Day Count. We are seeking an experienced and compassionate Hospice Clinical Liaison to join our team. In this role, you will ensure that intake and referral processes are completed efficiently and effectively to...Daily paidFull timePart timeLocal areaShift work
- ...of attack and defense vessels and systems all work in tandem to carry out the Navy’s most critical missions. As an Engineering Duty Officer, your job is to keep the fleet moving forward. The Navy will rely on your sharp math and science skills to design, develop and...Part time
- ...colonoscopies, trigger point injections, pain management blocks, imaging, etc.). Act as liaison between the patient and physician/specialty offices to ensure the best possible scheduling outcome for the patient. Project a professional image and representation of the Medical...Work at office
- ...drop ordnance and conduct defensive missions—all in the F/A-18 Hornet and the cutting-edge F-35C Lightning II. AIRCRAFT HANDLING OFFICER - Every performance needs a choreographer and on the deck of an aircraft carrier, that person is you. You’re in charge of directing...Part time
$23 per hour
...not be exempt from using company provided equipment. Home Office Requirements Using Maximus-Provided Equipment: - Internet speed... ..., age, national origin, disability, veteran status, genetic information and other legally protected characteristics. Pay Transparency...Full timeContract workCurrently hiringRemote workWork from homeHome officeMonday to FridayShift work- ...This program allows full-time seminary students (pursuing Master of Divinity (MDiv)) to be commissioned as a Navy Officer while completing theological studies at an accredited seminary or graduate school. You’ll receive on-the-job training under the direct supervision...Full time
- Overview Expand Access. Lead Markets. Transform Care. We are seeking a RN Executive Director Specialist – Hospice to join our leadership team. This role acts as the administrator on call and is responsible for the overall operation of assigned markets, including ...Daily paidFull timePart timeLocal area
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Information Security Officer. Be the first to apply!
- information security lead Kokomo, IN
- remote ciso
- chief information security officer
- business information security officer biso
- information security officer iso
- ciso
- information systems security officer sso
- chief information security officer ciso
- information systems security officer
- information security officer


