Information Security Officer
Shaw Systems Associates
Chief Information Security Officer (CISO)
Shaw Systems is a leading national software provider serving the consumer lending and financial services industry. We are seeking a Chief Information Security Officer (CISO) to lead the protection of corporate and client information assets and drive a secure, scalable technology environment.
This role owns enterprise security strategy, operations, compliance, and risk management while enabling secure adoption of AI, cloud, and automation platforms. The ISO serves as Shaw's primary authority on information security, partnering across business, technology, and client teams to strengthen security posture and support growth.
Organizational Scope
- Direct Reports: Service Operations Manager, Senior Security Engineers, Security/InfoSec Analysts
- Team Size: ~8 FTEs + contractors + SOC partner
- Enterprise Reach: Full client portfolio (financial services focus)
- Cross-Functional Influence: AI Committee; DevOps, Cloud, Implementation
Responsibilities
1. Security Strategy & Program Leadership
- Define and mature enterprise information security strategy, policies, and standards
- Own and evolve Shaw's Information Security Program and SOC 2 Type II compliance
- Serve as primary security representative for clients, auditors, and executives
- Lead risk identification, mitigation, and enterprise security roadmap
- Oversee access controls, third-party risk, and security readiness exercises (DR, incident tabletop)
- Present security posture, risks, and compliance status to leadership and external stakeholders
- Hold named accountability for security representations in client agreements (including MSAs and processing agreements); present security posture and risk to clients, prospects, auditors, and executive forums as required
2. Security Operations (SecOps)
- Oversee 24/7 SOC operations (via partner) and incident response lifecycle
- Manage threat detection, monitoring, vulnerability management, and remediation
- Lead response to authentication threats, phishing, and unauthorized access events
- Maintain and enhance security tooling across the stack, including Microsoft Defender, FortiClient VPN, Arctic Wolf MDR, Keeper, KnowBe4, PAM solutions, and data protection technologies (e.g., DLP)
- Ensure endpoint, identity, and infrastructure security across cloud and on-prem environments
- Drive network, cloud, and infrastructure hardening initiatives
3. AI Governance & Security Architecture
- Lead enterprise AI security strategy and rollout (Copilot, LLMs, AI tools)
- Design and enforce AI governance framework (usage policies, data protection, access controls)
- Architect secure AI/LLM environments (mitigating data leakage, prompt injection, etc.)
- Own Microsoft Purview strategy (DLP, labeling, information protection)
- Represent AI security posture to clients, auditors, and leadership
- Manage strategic vendor relationships, including Microsoft, Anthropic, Arctic Wolf, Fortinet, Keeper, and other security and AI partners, ensuring enterprise value and risk alignment
4. Service Operations Oversight
- Provide leadership oversight to Service Operations (infrastructure, endpoints, support)
- Ensure reliability, patching, identity governance, and cloud operations (M365/Azure)
- Drive SLA performance, operational efficiency, and automation initiatives
- Ensure operational rigor through established tooling and cadences, including patch management (e.g., WSUS), endpoint monitoring, and environment audits
5. Compliance, Risk & Audit
- Co-own SOC 2 Type II audit lifecycle and evidence management
- Maintain enterprise risk register and mitigation tracking
- Lead client/vendor security assessments and regulatory readiness
- Ensure alignment with frameworks (ISO 27001, NIST, FFIEC, GLBA, SOX)
- Ensure third-party vendor due diligence, security requirements, and contractual obligations are aligned with Shaw's Information Security Program and documented appropriately
- Monitor regulatory developments (including AI and privacy laws)
- Own security representations in client agreements and audit responses
- Provide security review, guidance, and approval on security-related representations in client, regulatory, and third-party engagements, in partnership with executive leadership, Legal, and Compliance
6. Leadership & Culture
- Lead, mentor, and develop InfoSec and Service Ops teams
- Manage vendors, contractors, and partner performance
- Promote enterprise-wide security awareness and training programs
- Partner with HR on hiring, workforce planning, and organizational design
7. Strategic & Cross-Functional Collaboration
- Advise executive leadership on security and AI risk strategy
- Partner with DevOps, Cloud, and Implementation teams on secure design practices
- Support business development (security questionnaires, client discussions)
- Translate technical risk into business impact for diverse stakeholders
Requirements
Education
- Bachelor's or Master's degree in Computer Science, Engineering, or related field
Experience & Expertise
- 10+ years in information security leadership
- 5+ years securing cloud environments (Azure preferred, AWS acceptable)
- Strong experience with SOC 2, ISO 27001, NIST, OWASP, FFIEC, GLBA, SOX
- Deep technical background across DevOps, infrastructure, and security tooling
- Expertise in network security, IAM, DLP, SIEM, and vulnerability management
- Experience with Microsoft security stack (Defender, Purview, Intune, Entra ID, Azure)
- Demonstrated experience with AI platforms and governance (e.g., Copilot, LLMs)
- Financial services or lending industry experience preferred
Certifications
- CISSP (required)
- CCSP (required)
- ISSAP (preferred)
Leadership Competencies
- Strategic security leadership and business alignment
- AI governance and emerging technology risk management
- Operational execution and compliance discipline
- Strong communication, stakeholder influence, and executive presence
- Analytical problem-solving and results orientation
- Vendor and partner management expertise
Performance Expectations (First 12 Months)
- SOC 2 Type II audit completed with no material findings
- Enterprise AI governance framework fully implemented
- Microsoft Purview DLP and labeling deployed enterprise-wide
- Mature security operations cadence with measurable SLAs
- Updated BCP/DR program tested
- Improved phishing awareness and security training outcomes
Supervisory Responsibility
- Leads a team of internal, contractor, and external partners supporting security operations and enterprise infrastructure.
Location
- Hybrid: Within 75 miles of Houston, TX
- Remote (eligible states): TX, VA, FL, GA, ID, LA, MI, MN, NJ, NC, PA, UT
- Travel: 10–25% as needed
Work Environment
- Full-time, Monday–Friday; standard business hours with occasional after-hours support as needed.
$120k - $187.5k
About the job Who We Are Looking For The VP, Information Security Officer, provides cyber risk management advisory services across all lines of business within State Street. This role is responsible for working closely with the development teams and aligned cybersecurity...SuggestedTemporary work- ...Chief Information Security Officer (CISO) About the Company Leading provider of cloud-based software for financial institutions Industry Computer Software Type Privately Held, Private Equity-backed About the Role The Company is seeking a Chief Information...Suggested
- ...Chief Information Security Officer (CISO) About the Company Accomplished executive search firm Industry Staffing and Recruiting Type Privately Held About the Role The Company is seeking a Chief Information Security Officer (CISO) to oversee and...Suggested
$125k - $160k
...Information Security Manager Key Responsibilities Responsible for delivering the programme/plans to ensure the Firm's information assets are adequately protected. Duties will include some or all of the following: Act as a trusted advisor on Information Security...Suggested- ...re building a smarter, faster, and more secure financial future by revolutionizing the... .... About the team The Security & Information Technology organization is the backbone... ...Global CTO, the Chief Information Security Officer (CISO) & Head of Information Technology...SuggestedFull timeContract workTemporary workWork at officeWorldwideHome officeFlexible hours
- ...for building great products. Join us on our mission and shape the future! The Opportunity Cohere seeks a Chief Information Security Officer who can help shape Cohere's security strategy & the broader conversation around securing AI at scale. You know how to...Full timeWork at officeRemote workFlexible hours
$150k - $200k
...Chief Information Security Officer (CISO) Vistrada is looking to hire strong Chief Information Security Officers (CISO). The CISO will provide strategic cybersecurity guidance and oversight to Vistrada clients by leading and managing their cybersecurity programs to...Work experience placementRemote workFlexible hours$350k - $400k
...Job Summary The Chief Information Security Officer (CISO) will lead and oversee the Information Security program across the entire organization. The role will be responsible for developing, implementing, and maintaining a unified enterprise security strategy that...Contract workLocal areaShift work$300k - $400k
...principles grounded in accountability, teamwork, integrity, and solutions built to scale. Join us! About the Role As Chief Information Security Officer, you will be responsible for leading and strengthening the company’s entire security function across four key domains:...Work at officeLocal areaWorldwide- JOB SUMMARY Specialty Systems, Inc. has an opening for an Information Security Officer (ISO) with the below described skills and experience to join our team of technical professionals supporting our Department of Defense customer at the Joint Base MDL. In this position...Work experience placementLocal areaWeekend work3 days per week
$100k - $120k
Job Description Job Description SportsMed Physical Therapy is seeking a Chiropractor to work full-time, handling coverage needs throughout our New Jersey clinics. SportsMed Physical Therapy is fortunate to be one of the fastest growing multidisciplinary practices...Full time- ...Information System Security Officer (ISSO) Employment Type: Full-Time, Mid-Level Department: Administrative and Logistics Support As a FSR ISSO, you will be embedded on-site with U.S. Government customers to ensure the secure, compliant operation of a production...Full timeFlexible hours
- ...Information Systems Security Officer (ISSO) Employment Type: Full-Time, Experienced Department: Information Technology CGS is seeking an Information Systems Security Officer (ISSO) with DIACAP and/or RMF experience who has deep expertise in security assessment...Full timeLocal areaFlexible hours
- ...Virtual Chief Information Security Officer (CISO) About the Company Flourishing provider of market research & business intelligence services Industry Market Research Type Privately Held About the Role The Company is in need of a Virtual Chief Information...Part time
$160k - $275k
...Job Description What is the opportunity? As a Technical Information Security Officer, you will provide US regional cybersecurity leadership ensuring operational security capabilities for US LOBs meet regulatory expectations and security standards. You will strengthen...Full timeFlexible hours$167.57k
...Information Security Officer, Affiliate Technology Services New York, New York, United States; Washington, District of Columbia, United States About The Job The ACLU seeks applicants for the full-time position of Information Security Officer, Affiliate Technology...Full timeWork at office2 days per week$160k - $275k
...Job Description What is the opportunity? Royal Bank of Canada is seeking a Technical Information Security Officer to provide US regional cybersecurity leadership and ensure our operational security capabilities meet regulatory expectations and industry security...Full timeFlexible hours- Koitecc Solutions is seeking an Information Security Officer (ISO) to support our Department of Defense customer at Joint Base MDL. This role involves ensuring cybersecurity compliance and assisting with risk management. Ideal candidates will have security engineering...
$160k - $275k
...Business Information Security Officer (BISO) (Global Security) Join RBC's newly established US Cyber Security & Resilience function as a strategic leader responsible for implementing corporate cyber security standards and initiatives across our US business units. As...Flexible hours- ...Reporting to the Chief Executive Officer, the IT Director provides strategic and operational leadership for all Information Technology systems, infrastructure, and services.... ...renewals, and alignment with organizational, security, and budget requirements. Develop,...Full timeContract workWork at officeMonday to Friday
- ...These careers bring the expertise in all facets of Information Operations, making sure our fleet is capitalizing on... ...related to intelligence. INTELLIGENCE AND INFORMATION SECURITY CAREERS IN THE NAVY INTELLIGENCE OFFICER Analyze top-secret information, interpret spy...Full timePart timeWorldwide
$99.2k
...Minimum Education Required BACHELOR'S DEGREE IN INFORMATION SECURITY POLICY & MANAGEMENT Compensation $99,195.00 - $99,195.00 / Yearly Hours Per Week 40 Number Of Positions 1 Job Description Under close supervision of the Manager, install, configure...Full timeLocal area$85k - $105k
A leading physical therapy practice in New Jersey is seeking a Chiropractor to join their multidisciplinary team. This opportunity offers no weekends, competitive salary (ranging from $85,000 to $105,000) plus bonuses, and generous benefits including medical insurance, ...$130k - $150k
...the summer sunshine! Chief Growth Officer Northeast Family Services is a... ...Expansion ~ Identify, cultivate, and secure partnerships with healthcare systems, community... ...and payer trends across states to inform growth strategy. ~ Collaborate with...Contract workTemporary workSummer workWork visa- ...National Retail Transportation, Inc. is seeking a Director of Cybersecurity based in Lyndhurst, NJ. This role involves enhancing security across the software development lifecycle, leading a skilled team, and executing the organization's cybersecurity strategy. Candidates...
- ...A prestigious educational institution is seeking an Associate Vice President for Technological Innovation and Chief Information Officer. This role requires a visionary leader to advance the technology strategy, ensuring that technology services meet the needs of students...
$45 - $55 per hour
...as well as ensuring that you have the financial stability and security to think long term. Underpinning all of this is a clear set of... ...an innovative force, where healthcare meets retail. For more information, visit Business Structure The Joint Corp. is a franchisor...Full timePart time- A healthcare organization is seeking a Chief Nursing Officer (CNO) to lead nursing practice and patient care at Mountainside Medical Center in Montclair, NJ. The CNO will oversee clinical responsibilities, implement innovative care delivery models, and ensure compliance...Full time
- ...leadership team at Mountainside Medical Center as the Chief Nursing Officer. The Chief Nursing Officer (CNO) is responsible for providing... ...national benchmark statistics. Allocate financial, information, and human capital for improvement activities to ensure cost-effective...Local area
$45k - $50k
Job Description Job Description Job description: Join a Leading Chiropractic & Wellness Team in Manhattan! Location: Upper West Side, NYC (Directly Across from Central Park) Job Type: Part-time with the ability to move to Full Time. Base Salary: $45,000 –...Full timePart timeFlexible hours2 days per week3 days per week
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Information Security Officer. Be the first to apply!
- information security lead Passaic, NJ
- information security Passaic, NJ
- remote ciso
- chief information security officer
- business information security officer biso
- information security officer iso
- ciso
- information systems security officer sso
- chief information security officer ciso
- information systems security officer



