Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Group Chief Information Security Officer

$350k - $400k

Jobleads-US

Group Chief Information Security Officer

Organization:

Location:

New York, NY

Description:

Job Summary

The Chief Information Security Officer (CISO) will lead and oversee the Information Security program across the entire organization. The role will be responsible for developing, implementing, and maintaining a unified enterprise security strategy that ensures the confidentiality, integrity, and availability of the company’s information assets, platforms, infrastructure, and customer data across all business operations.

As the organization continues to modernize its retail, digital, cloud, and enterprise technology platforms, we require a transformational security leader capable of driving the next phase of cybersecurity maturity across the group. This role is significantly broader than traditional cybersecurity operations and compliance management. The CISO will play a critical leadership role in helping the organization securely navigate large-scale technology transformation, AI adoption, cloud modernization, evolving regulatory requirements, and an increasingly sophisticated global threat landscape.

The CISO will be responsible for establishing and leading a group-wide cybersecurity strategy across both US and UK operations, driving consistency in governance, policy, standards, risk management, incident response, and operational security practices. This includes developing enterprise security standards, modernizing security architecture, implementing Zero Trust principles, strengthening cloud and identity security, improving business resilience, and reducing legacy technology and operational risk across the environment.

Cybersecurity has evolved far beyond traditional perimeter defense and audit-driven compliance programs. We now face a rapidly changing threat environment driven by AI-enabled attacks, ransomware, cloud complexity, third-party supply chain risk, increasing regulatory scrutiny, and growing operational dependence on digital platforms. As a result, the CISO must operate not only as a security leader, but also as a strategic business partner and an agent for transformation.

This role will require close collaboration with executive leadership, technology teams, legal, compliance, operations, and external partners to ensure security is embedded into the organization’s strategy and business operations. Given the strategic importance of cybersecurity and enterprise risk management to the organization, the CISO role will maintain a regular reporting cadence with the Board Risk Committee and will be responsible for providing ongoing updates related to cybersecurity posture, operational risk, regulatory compliance, major initiatives, emerging threats, and overall enterprise resilience.

What You Do

Global Security Strategy

  • Define and execute a unified cybersecurity strategy that supports the business objectives of both B&N and Waterstones.
  • Lead the development and implementation of security policies, standards, and procedures that align with local regulations and best practices.
  • Serve as a trusted advisor to executive leadership and Board of Directors for both organizations.

Security Operations & Incident Response Leadership

  • Lead the enterprise cybersecurity incident response and crisis management program, coordinating cross-functional response activities during major cyber incidents, ransomware events, operational disruptions, and data breaches.
  • Act as the primary technical contact with external crisis response agencies, cyber insurance providers, legal counsel, forensic investigators, regulators, and law enforcement agencies during significant cybersecurity incidents.
  • Drive the continuous maturation of the organization’s cyber resilience capabilities, including incident response planning, ransomware preparedness, disaster recovery, business continuity, tabletop exercises, and enterprise recovery strategies.
  • Establish and maintain enterprise-wide cyber incident response standards, escalation procedures, communication protocols, and post-incident review processes to improve organizational readiness and operational resilience.
  • Direct 24/7 global security operations, including monitoring, detection, and response to security incidents.

Technology & Infrastructure Security

  • Leverage AI to improve detection, response, and scale.
  • Ensure security is embedded in infrastructure, applications, cloud environments, and software platforms.
  • Drive Zero Trust adoption, identity and access management, and secure data handling practices across both organizations.
  • Oversee regular penetration testing, vulnerability assessments, and third-party risk management.

Team Leadership & Development

  • Lead and foster collaboration between the B&N and Waterstones Information Security teams.
  • Recruit, mentor, and retain top cybersecurity talent.
  • Directs work and ensures appropriate performance levels of all Security team members across Waterstones and B&N, working together with the senior leadership team to create a performance-based culture.
  • Partner with IT, Legal, Risk, HR, and other business units to ensure a holistic approach to Information Security.

Executive Leadership & Cybersecurity Influence

  • Serve as a visible and influential cybersecurity leader across both organizations, representing the Information Security function internally and externally.
  • Champion a strong culture of security awareness at all levels of the organization and across both businesses.
  • Act as the public and internal face of the cybersecurity function, partnering with executive leadership, board members, auditors, and external partners to communicate the organization’s security vision and maturity.

AI-Enhanced Cyber Defense & Governance

  • Leverage AI to improve detection, response, and scale.
  • Automate incident triage and response (SOAR + AI).
  • Enhance phishing and fraud detection using ML models.
  • Collaborate with HR and Legal to define AI security policies and acceptable use standards.
  • Classify and approve AI tools and vendors.
  • Align with emerging regulatory frameworks (EU AI Act, etc.).
  • Prevent data leakage into external AI platforms.
  • Enforce data classification and masking for AI use.
  • Monitor environment for unauthorized use of enterprise data in AI tools.
  • Assess AI capabilities in vendor platforms.

Prepare For and Defend Against

  • AI-generated phishing (highly personalized)
  • Deepfake-based social engineering
  • Automated vulnerability discovery by attackers

Update training and awareness programs accordingly.

Utilize AI to reduce reliance on manual Tier 1/2 SOC work.

Shift talent toward engineering, threat hunting, and strategy.

Integrate AI into security tooling stack (SIEM, EDR, XDR).

Knowledge & Experience

Data Security & Protection

  • Define and enforce enterprise data security standards, policies, and controls to ensure the confidentiality, integrity, and availability of corporate and customer data.
  • Establish data classification standards and ensure data is appropriately categorized, protected, retained, archived, and disposed of based on business and regulatory requirements.
  • Oversee encryption standards and key management practices for data at rest, in transit, and within cloud environments.
  • Ensure appropriate access controls, and privilege security models are implemented across enterprise platforms and data repositories.
  • Partner with Legal, Compliance, and technology teams to ensure adherence to data privacy and regulatory requirements, including GDPR, PCI-DSS, SOX, CCPA, and other relevant industry standards.
  • Develop and maintain Data Loss Prevention (DLP) strategies and monitoring capabilities to reduce the risk of unauthorized disclosure or exfiltration of sensitive information.
  • Support the development of enterprise-wide awareness and training programs related to data handling, privacy, cybersecurity, and acceptable AI usage practices.

Third-Party & Supplier Risk Governance

  • Establish third-party cybersecurity risk management program to assess, monitor, and mitigate risks associated with vendors, cloud providers, SaaS platforms, outsourced service providers, and strategic technology partners.
  • Define security governance standards and due diligence processes for vendor onboarding, contract reviews, system integrations, and vendor risk assessments.
  • Oversee continuous monitoring and risk evaluation of critical third-party providers, including incident response coordination, security assessments, penetration testing, and remediation monitoring if needed.
  • Develop governance frameworks and contingency strategies to reduce operational, financial, and reputational risk associated with third-party cyber incidents, software supply chain compromise, and critical vendor outages.

Regulatory & Audit Compliance Responsibilities

  • Lead the information security compliance program to ensure alignment with applicable regulatory, legal, and industry requirements across the organization, including SOX or equivalent, PCI-DSS, GDPR, UK GDPR, data privacy regulations, and other applicable corporate and retail compliance obligations.

Qualifications:

Education & Professional Background

  • Bachelor’s degree in Information Security, Computer Science, Engineering, or a related field; advanced degree (e.g., MS in Cybersecurity) preferred.
  • 15+ years of experience in Information Security, with at least 7 years in a senior or executive leadership role overseeing enterprise-scale security programs.
  • Proven success leading global cybersecurity initiatives across multi-national or multi-brand organizations.

Technical & Strategic Expertise

  • Deep understanding of information security frameworks, technologies, and architectures, including Zero Trust, cloud security, and identity management.
  • Strong knowledge of regulatory requirements across U.S. and European jurisdictions, including GDPR, CCPA, and other privacy/security regulations.
  • Demonstrated ability to balance security risk management, ensuring security strategies are aligned with business objectives.
  • Experience in incident response, crisis management, and executive-level communications during security incidents.

Leadership & Influence

  • Recognized as a strategic cybersecurity leader who can inspire trust and confidence at board, executive, and operational levels.
  • Strong executive presence, with the ability to communicate complex technical concepts in clear, business-relevant terms.
  • Proven capability to build, mentor, and lead high-performing security teams and encourage collaboration across geographies and business functions.

Certifications (Preferred)

  • CISSP, CISM, CISA, CRISC, CCISO, or equivalent industry-recognized credentials.

Compensation:

Benefits for those who are scheduled to work less than 20 hours per week include Employee Discount, EAP and Sick Pay.

For those scheduled to work between 20 and 29.99 benefits include Employee Discount, EAP, Sick Pay and Paid Time Off including paid Maternity and Parental Leave, Company Paid Holidays, Transit and 401(k) with Company Match.

For those scheduled to work 30 hours or more benefits include Employee Discount, EAP, Sick Pay and Paid Time Off including paid Maternity and Parental Leave, Company Paid Holidays, 401(k) with Company Match, Comprehensive Health Benefits (Medical, Dental and Vision), Healthcare and Dependent Care Spending Accounts, Healthcare Spending Account, Disability Benefits, Life Insurance, Transit, and Tuition Reimbursement. All benefits provided are in accordance with the terms of the current plan and may be subject to future change. Benefits may vary depending on location/state regulations. More information can be received by the recruiter or Human Resources.

An employee in this position can expect an annual starting rate between $350,000 - $400,000 depending on experience, seniority, geographic locations, and other factors permitted by law.

We know how to fine-tune corporate security because we've led effective and efficient Fortune 500-level security programs. The SEC helps businesses find the best balance of risk mitigation, cost and innovation.

#J-18808-Ljbffr Jobleads-US
Vacancy posted 2 days ago
Similar jobs that could be interesting for youBased on the Group Chief Information Security Officer in New York, NY vacancy
  • $270k - $350k

    CompanyArgo GroupArgo Group is an underwriter of specialty insurance products in the...  ...Inc.Job DescriptionBusiness Title(s): Chief Claims Officer, Argo Group Employment Type: Full-Time...  ...on timely and meaningful exchanges of information. Possesses an extensive knowledge and... 
    Suggested
    Full time
    Work at office
    Local area

    Argo Group

    New York, NY
    15 hours ago
  •  ...Fire Department, City of New York (FDNY), seeks a full-time Chief Information Security Officer in the Bureau of Technology Development & Systems. The...  ...WAN, systems administration, active directory, PowerShell, group policy, virtualization, cloud and IT security... 
    Suggested
    Full time
    Local area

    New York City Fire Department

    New York, NY
    3 days ago
  •  ...Chief Information Security Officer (CISO) About the Company Large e-commerce payment solutions company Industry Financial Services Type...  ...evidence-based decision-making. Hiring Manager Title Group CISO Functions ~ Information Technology... 
    Suggested

    Confidential

    New York, NY
    3 days ago
  • $211.28k - $316.92k

     ...Private Client Coverage, Professional, WealthCompany: CitiThe Wealth Group Executive is accountable for management of complex/critical/...  ...time off (sick leave), and paid holidays. For additional information regarding Citi employee benefits, please visit citibenefits.com... 
    Suggested
    Full time
    Temporary work

    Citigroup

    New York, NY
    4 days ago
  • $375k - $400k

     ...Managing Director, US Origination, Government Solutions Group, to advise, structure, and originate debt securities across a range of government and public sector...  ...other skills tests (such as simulation, coding, MS Office). Our goal for the application process is to get to... 
    Suggested
    Full time
    Part time
    Remote work

    CIBC Bank

    New York, NY
    15 hours ago
  •  ...A global financial institution is seeking a hands-on Chief Information Security Officer to lead the Information Security program for its New York operation. The role combines executive cybersecurity leadership with direct involvement in cyber risk, regulatory compliance... 
    Full time
    Work at office
    Local area

    Madison-Davis, LLC

    New York, NY
    4 days ago
  •  ...Group Director, Cyber Risk & Security Engineering At Chanel, we are focused on creating an inclusive culture...  ...Cyber Risk champion to join our Information Security Team onsite in the N ew York...  ...Piscataway, NJ and New York, NY office locations Hybrid work model with... 
    Temporary work
    Work at office
    Flexible hours

    Chanel

    New York, NY
    2 days ago
  • $190k - $225k

     ...Infrastructure and Project Finance Group Fitch Ratings’ Energy and...  ...York, Chicago, or Toronto office. This role will report...  ...a global leader in financial information services with operations in more...  ...to providing global securities markets with objective, timely... 
    Work at office
    Local area
    Immediate start

    Fitch Group

    New York, NY
    5 days ago
  • $170k - $300k

     ...credit, corporate and investment banking, securities brokerage, transaction services, and...  ...Team:The Applications Development Senior Group Manager is a transformative technology leader...  ...), and paid holidays. For additional information regarding Citi employee benefits, please... 
    Full time
    Local area

    Citigroup

    New York, NY
    4 days ago
  •  ...Chief Information Security Officer (CISO) Find out if this opportunity is a good fit by reading all of the information that follows below. Department: Information Technology & Security Reporting to: Chief Technology Officer Location: New York, NY (One State... 
    Full time
    Work at office
    Remote work
    Worldwide
    Flexible hours

    IPC Systems

    New York, NY
    1 day ago
  • $85k - $125k

     ...attorneys and staff in assigned practice groups. The Practice Department Research...  ...assess, understand, and address research and information needs.Serve as the primary liaison between...  ...environment.Proficient in Microsoft Office, iManage and other firm applications.Preferred... 
    Full time
    Contract work
    Work at office
    Local area

    Troutman Pepper Hamilton Sanders

    New York, NY
    3 days ago
  •  ...advocacy seeks a Senior Systems & Security Administrator to lead the...  ...programs across multiple offices, supporting the firm’s ISO/IEC...  ...ensuring robust protection of information assets while supporting operational...  ...impact. The Phoenix Group Advisors is an equal opportunity... 
    Full time
    Work at office

    The Phoenix Group

    New York, NY
    2 days ago
  • %PDF-1.6%ÓôÌá1 0 obj /Rotate 0/StructParents 2/Tabs/S/Type/Page/Group endobj2 0 obj streamH‰ìW[—ÓÈ~÷¯èG;ÇÖè.yápÎ2L’IB€Å‡!'Gµm#Á² ~«U—nÉÏ,$yÚ—YêKÕWU_}uöÇuùU=|xöôüò‰ŠÔ£GŸœ«ÙÇYy¡Ê|/ U%žŸ«4_{y® éÙkUÍofg›¯µÙÍ|Ï÷ááZ¾·ÎÕÊW=¦©—ª,ñ½ W›³«ù‡EäÅjþv±Ôüþz¹š_›ÿ™š×Õ?ì»O‹˜-¾¨«¥*õ ­£E‹... 

    Covington & Burling

    New York, NY
    15 hours ago
  •  ...Chief Information Security Officer (CISO)At Varo Bank, we are on a mission to democratize access to high-quality, affordable financial services for everyday people. We combine the rapid-fire innovation of a tech startup with the trust and stability of an FDIC-insured... 
    Work at office
    Shift work

    Varo Bank

    New York, NY
    2 days ago
  • $81.13k - $164.57k

     ...multifaceted engagements, formal training, and informal mentoring. At KPMG, we believe nothing is...  ...a Global Executive & Private Client Group (GEPC) Senior Associate to join our...  ...headquartered companies; proficiency in Microsoft Office Suite (Excel, Word, Outlook, and... 
    Work at office
    Local area
    Relocation
    Relocation package

    KPMG

    New York, NY
    15 hours ago
  •  ...Environmental Protection (NYC DEP) Business Information Technology (BIT) division is...  ...residents of New York City. Reporting to the Chief Information Officer (CIO), the Business Information...  ...team seeks to hire a Chief Information Security Officer (CISO). Responsibilities... 

    City of New York

    New York, NY
    2 days ago
  •  ...Role Description This full-time remote Chief Information Security Officer (CISO) role is responsible for leading Nova Infra Invest’s information security strategy and operations. The CISO oversees the design, implementation, and continuous improvement of security policies... 
    Full time
    Remote work

    Nova Infra Invest

    New York, NY
    5 days ago
  •  ...Chief Information Security Officer (CISO)New York CityCAIS is the pioneer in democratizing access to and education about alternative investments and structured products for independent financial advisors, empowering them to engage and transact with leading asset managers... 

    CAIS

    New York, NY
    3 days ago
  •  ...Always hire up, never down. We partner with organizations of all sizes to explore, design, and implement AI strategies that are secure, scalable, and human-centered. We believe AI should amplify human potential, not replace it, and we build with that conviction in every... 
    Full time
    For contractors
    Remote work
    Day shift

    Human Agency

    New York, NY
    2 days ago
  • $299k - $344k

     ...apply human judgment to AI outputs, and keep building AI fluency in ways that support their role and our mission. The Chief Information Security Officer will be responsible for defining, leading, and advancing Spring Health’s enterprise-wide information security,... 
    Work at office
    Worldwide
    Relocation
    Sleeping nights
    2 days per week
    3 days per week

    Jobleads-US

    New York, NY
    5 days ago
  •  ...a place you can engage in meaningful work and grow your career. Let’s see what we can achieve. Together. Summary The Chief Information Security Officer (CISO), working in collaboration with and in support of the firm’s strategic initiatives, is a senior executive responsible... 
    Work at office
    Remote work
    Relocation
    Visa sponsorship
    Relocation package

    DLA Piper

    New York, NY
    3 days ago
  •  ...Join to apply for the Chief Information Security Officer role at ButterflyMX Get AI-powered advice on this job and more exclusive features. Our Mission ButterflyMX is on a mission to empower people to open and manage doors & gates from a smartphone. Our products are installed... 
    Full time
    Remote work
    Worldwide
    Flexible hours

    ButterflyMX

    New York, NY
    3 days ago
  •  ...multifaceted engagements, formal training and informal mentoring. At KPMG, we put our culture...  ...our Global Executive & Private Client Group practice in Tax. Responsibilities:...  ...intelligence (AI), Alteryx and Power BI, MS Office Applications including Excel, PowerPoint,... 
    Summer work
    Internship
    Private practice
    Local area
    Visa sponsorship
    Work visa

    KPMG LLP

    New York, NY
    1 day ago
  • $225k - $250k

     ...range of investment banking, securities, investment management and wealth...  ...from more than 1,200 offices in 43 countries. As a market...  ...Division Securitized Products Group is seeking a VP/ED Structurer...  ...perspectives, and experiences.For more information, please visit: .Employment... 
    Temporary work
    Worldwide

    Morgan Stanley

    New York, NY
    15 hours ago
  •  ...Chief Information Security Officer (CISO) About the Company Influential environmental agency Industry Environmental Services Type Government Agency Founded 1977 Employees 5001-10,000 About the Role The Company is seeking a Chief Information... 

    Confidential

    New York, NY
    3 days ago
  •  ...Chief Information Security Officer (CISO) About the Company Large public accounting & advisory firm Industry Accounting Type Privately Held Founded 1986 Employees 1001-5000 Categories Consulting & Professional Services Accounting Accounting... 

    Confidential

    New York, NY
    1 day ago
  •  ...Chief Information Security Officer (CISO) About the Company A global financial institution Industry Banking Type Privately Held About the Role The Company is in search of a Chief Information Security Officer (CISO) to take on a pivotal role in leading... 

    Confidential

    New York, NY
    4 days ago
  • $250k

     ...The New York, NY office of Lewis Brisbois, a full-service AmLaw 100 firm, is seeking a Chief Information Security Officer. The Chief Information Security Officer (CISO) is a senior executive responsible for developing, implementing, and overseeing a comprehensive, enterprise... 
    Work at office

    Jobleads-US

    New York, NY
    2 days ago
  • $350k - $400k

     ...exceptional service to seller and buyer clients. Executive Summary Compass International Holdings is seeking a seasoned Chief Information Security Officer to own and evolve the enterprise security program. This is an executive & highly technical role at the intersection... 
    Flexible hours

    Jobleads-US

    New York, NY
    3 days ago
  • $150k - $200k

     ...Virtual Chief Information Security Officer (vCISO)Vistrada is looking to hire strong Virtual Chief Information Security Officers (CISOs). The vCISO will provide strategic cybersecurity guidance and oversight to Vistrada clients by leading and managing their cybersecurity... 
    Work experience placement
    Remote work
    Flexible hours

    VISTRADA

    New York, NY
    2 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Group Chief Information Security Officer. Be the first to apply!