Chief Information Security Officer
$275k - $300kBPM LLP
BPM – where caring and community is in our company DNA; we are always striving to be our best selves; and we’re compelled to ask the questions that lead to innovation.
Working with BPM means using your experiences, broadening your skills, and reaching your full potential in work and life—while also making a positive difference for your clients, colleagues, and communities. Our shared entrepreneurial spirit drives us to see and do things differently. Our passion for people makes BPM a place where everyone feels welcome, valued, and part of something bigger. Because People Matter.
What you get:
Total rewards package: from flexible work arrangements to personalized benefit structures and financial compensation options that give you choice and flexibility Well-being resources: interactive wellness platform and incentives, an employee assistance program and mental health resources, and Colleague Resource Groups (CRGs) Balance & flexibility: 14 Firm Holidays including 2 floating, Flex PTO, paid family leave, winter break, summer hours, and remote work options, so you can balance challenging yourself with taking care of yourself Professional development opportunities : A learning culture with CPA exam resources and bonuses, a coach program, and live classes, workshops, and seminars through BPM University Who is successful at BPM:
Caring people who put others first Self-starters who embody the BPM entrepreneurial spirit Authentic individuals with a diverse point of view Lifelong learners with a drive to excel Resilient people who rise to the occasion The Chief Information Security Officer (CISO) provides vision, leadership, and strategic direction for BPM's enterprise information security, cyber risk, privacy, and trust programs. The CISO partners closely with the CIO and technology organization while maintaining independent responsibility for information security risk, governance, compliance, and assurance across the firm. The role partners with firm leadership, business units, legal, risk management, and technology teams to ensure security is integrated into business strategy, client service delivery, and emerging technologies, including artificial intelligence (AI).
Strategy & Planning:
Participate as a member of the senior management team in governance processes of the organization’s security strategies. Lead strategic security planning to achieve business goals by prioritizing defense initiatives and coordinating the evaluation, deployment, and management of current and future security technologies using a risk-based assessment methodology. Develop and communicate security strategies and plans to executive team, staff, partners, customers, and stakeholders. Assist with the design and implementation of disaster recovery and business continuity plans, procedures, audits, and enhancements. Develop, implement, maintain, and oversee enforcement of policies, procedures, and associated plans for system security administration and user system access based on industry-standard best practices. Acquisition & Deployment:
Establish security architecture, governance, and risk management standards for the evaluation, acquisition, implementation, and operation of technology solutions across the firm. Ensure security, privacy, compliance, and resiliency requirements are incorporated into the selection and deployment of enterprise applications, cloud services, infrastructure, and emerging technologies. Provide security oversight and risk assessment for major technology initiatives, vendor relationships, and strategic business investments. Define security requirements and approval processes for new technologies to ensure alignment with BPM's risk appetite, client commitments, and regulatory obligations. Operational Management:
Partner with technology leadership to ensure security, privacy, and risk management requirements are integrated into enterprise architecture, applications, infrastructure, and business processes. Establish and oversee enterprise physical security, access control, and facility protection standards to safeguard BPM personnel, facilities, and information assets. Develop and manage the information security operating and capital budgets. Assess and advise on information security, privacy, and technology risks associated with strategic initiatives, technology investments, and third-party relationships. Lead the development and performance of the information security team. Develop and maintain strategic relationships with clients, regulators, vendors, and industry partners. Advise executive leadership on cybersecurity, privacy, AI, and emerging technology risks and opportunities. Requirements/Qualifications:
Bachelor's degree in Computer Science, Information Security, Business Administration, or related field. CISSP, CISM, CRISC, CCSP, or similar certifications preferred. 10+ years leading information security and cyber risk programs. Experience in professional services, public accounting, financial services, legal, healthcare, or other highly regulated industries preferred. Deep knowledge of cybersecurity, risk management, cloud security, privacy, identity, and regulatory compliance. Experience presenting to executive leadership and boards. Experience leading incident response and crisis management. Experience with ISO 27001, SOC 2, privacy regulations, and client security assessments. Experience securing cloud, SaaS, ERP, and other business-critical platforms. Experience with AI governance and emerging technology risk management. Incident Response and Resilience
Serve as executive leader for cybersecurity incident response and crisis management activities. Ensure BPM maintains and regularly tests incident response, cyber recovery, disaster recovery, and business continuity plans. Lead executive communications and stakeholder engagement during significant security events. Conduct post-incident reviews and drive continuous improvement of security capabilities. Executive and Board Engagement
Serve as BPM's principal advisor on cybersecurity, information risk, privacy, and emerging technology risks. Provide regular security and risk reporting to executive leadership, firm committees, and the Board of Directors. Translate technical risks into business impact, decision-making guidance, and measurable security outcomes. Client Trust and Regulatory Assurance
Serve as executive sponsor for BPM's client trust and security assurance programs. Oversee security responses, attestations, and trust-center content for prospective and existing clients. Partner with legal, risk, and business development teams to support client requirements and revenue opportunities impacted by cybersecurity. AI and Emerging Technology Governance
Establish governance frameworks for artificial intelligence, automation, and emerging technologies. Ensure security, privacy, and compliance requirements are integrated into AI-enabled business processes. Assess emerging technology risks and enable responsible innovation across the firm. Third-Party and Vendor Risk Management
Oversee BPM's third-party risk management program. Establish security requirements and risk review processes for vendors, cloud providers, and outsourced services. Partner with procurement and legal teams to evaluate contractual security obligations and technology risks. Personal Attributes:
Ability to set and manage priorities judiciously. Excellent written and oral communication skills. Excellent interpersonal skills. Strong negotiating skills. Ability to present ideas in business-friendly and user-friendly language. Exceptionally self-motivated and directed. Keen attention to detail. Superior analytical, evaluative, and problem-solving abilities. Exceptional service orientation. Ability to motivate in a team-oriented, collaborative environment. Physical Demands and Work Environment:
General office assignments-(typing), which lends itself to repetitive motion. Sitting in a stationary position for several hours within the day. On-call availability and periodic overtime. Dexterity of hands and fingers to operate a computer keyboard, mouse, and other computing equipment. We hope you find this opportunity to be in line with your background and interests, and look forward to receiving your application!
\n\n $275,000 - $300,000 a year
The salary range provided is intended for candidates in the San Francisco Bay Area who meet the minimum requirements of the position. Candidates who do not reside in the San Francisco Bay Area, do not meet the minimum requirements, or exceed the requirements are encouraged to apply and a recruiter will provide you with a range specific to your location and qualifications.
\n Wondering if you should apply?
At BPM we are people who value people. We are progressive and purposeful. We are a firm with flexibility. Our shared entrepreneurial spirit drives us to see and do things differently. And our passion for people makes BPM a place where everyone feels welcome, valued, and part of something bigger.
***************
BPM provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws. BPM welcomes and encourages applications from people with disabilities. Accommodations are available on request for candidates taking part in all aspects of the selection process.
For positions based in San Francisco, consideration of qualified candidates with arrest and conviction records will be in a manner consistent with the San Francisco Fair Chance Ordinance.
Please note - this posting is for prospective candidates only. Unsolicited third-party resume submissions will be considered property of BPM and will not be acknowledged or returned.
We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.
Vacancy posted 14 hours ago
Similar jobs that could be interesting for youBased on the Chief Information Security Officer in Remote vacancy
- ...is a place you can engage in meaningful work and grow your career. Let’s see what we can achieve. Together.SummaryThe Chief Information Security Officer (CISO), working in collaboration with and in support of the firm’s strategic initiatives, is a senior executive...SuggestedFull timeWork at officeRemote workRelocationVisa sponsorshipRelocation package
- SUMMARY The Chief Information Security Officer oversees planning and implementation of the organization’s data security programs. This includes strategy development, risk assessments and mitigation efforts and associated processes, and compliance with relevant laws and...SuggestedRemote work
- ...of the nation’s leading public institutions, seeks an experienced, dynamic, and mission-driven leader to be the next Chief Information Security Officer (CISO). Reporting to the Vice President and Chief Information Officer (CIO), the CISO will provide strategic leadership...SuggestedContract workRemote work
- The Chief Information Security Officer (CISO) is a director level role responsible for establishing and maintaining the information security program to ensure that information assets and associated technology, applications, systems, infrastructure and processes are adequately...SuggestedFull timeWork at officeWork from homeHome office
$300k - $380k
Obsidian Security is the leading SaaS security platform, trusted by global enterprises... ...market. This role reports to the Chief Legal and Trust Officer.ResponsibilitiesSecurity Strategy & Executive... ...thought leadership positioning and inform messaging around trust and security....SuggestedWork from home- ...Seeking a hands-on Chief Information Security Officer, the full-time remote role will build and lead the internal security program, ensuring the protection of people, systems, infrastructure, and company data while collaborating with cross-functional teams to implement...Full timeRemote work
- ...Chief Information Security Officer (CISO)Location: Houston, TX (On-Site)Type: Full-TimeAbout Us:Our client is a leading provider specializing in laboratory testing services, dedicated to delivering accurate, timely, and high-quality diagnostic results. Their commitment...Remote work
- ...About the job TOGETHER, WE SAVE LIVES Summary The Chief Information Security Officer oversees planning and implementation of the organization’s data security programs. This includes strategy development, risk assessments and mitigation efforts and associated...Remote work
$162.74k
Hiring Agency: Office of the Secretary of the Interior Department of the Interior... ...position is located in the Office of the Chief Information Officer (OCIO) at the Department of the... ...responsibilities: Set enterprise security strategy. Define company-wide security...Work at officeRemote work- ...Role Description This full-time remote Chief Information Security Officer (CISO) role is responsible for leading Nova Infra Invest’s information security strategy and operations. The CISO oversees the design, implementation, and continuous improvement of security policies...Full timeRemote work
- ...Chief Information Security OfficerThe Chief Information Security Officer provides enterprise leadership for the company's cybersecurity, risk management, compliance, IT infrastructure, end-user technology operations, and enterprise data governance. This executive role...Hourly payTemporary workWork at officeWork from homeHome office2 days per week3 days per week
- ...Chief Information Security Officer (CISO) / Head of Information Security Overview We are seeking an experienced Information Security Leader to define and execute a comprehensive enterprise security strategy. This role is responsible for safeguarding systems, data, and...Work at officeRemote work3 days per week
- ...Always hire up, never down. We partner with organizations of all sizes to explore, design, and implement AI strategies that are secure, scalable, and human-centered. We believe AI should amplify human potential, not replace it, and we build with that conviction in every...Full timeFor contractorsRemote workDay shift
- ...Lineation is building the security and governance layer for the agentic enterprise. As AI agents increasingly act across... ...friction. The Opportunity We are seeking a forward-thinking Chief Information Security Officer (CISO) to help define what security leadership looks...Remote workShift work
- ...Information Security Strategy LeaderProvide leadership for the development and implementation of a comprehensive Information Security strategy for the University of Akron. Manage a team of information security staff, and work with members of Information Technology and...Contract work
- ...Chief Information Security Officer (CISO) **Department:**Information Technology & Security Reporting to: Chief Technology Officer **Location:**New York, NY (One State Street Plaza) **Role Type:**Hybrid, Full-Time About IPC IPC is a global fintech company delivering cloud...Full timeWork at officeRemote workWorldwideFlexible hours
- ...Job Description and Duties The California Department of Developmental Services (DDS) is seeking a Chief Information Security Officer (Information Technology Manager II) to lead the department’s enterprise information security program at its Sacramento headquarters....Remote work
- ...NVISO is a pure‑play European cyber‑security consulting firm: our team of security professionals... ..., with clients in 16 countries, and offices in Brussels, Frankfurt, Munich, Vienna,... ...We are looking for an experienced Chief Information Security Officer to join our growing...Work experience placementWork at officeWork from homeHome officeFlexible hours
- ...Chief Information Security Officer (CISO) Organization: Nymbus Location: Fully remote; occasional travel may be required for client meetings and team gatherings. Description: About the job ABOUT NYMBUS: Nymbus is a modern fintech company delivering...Contract workRemote workNight shift
- ...CISO Role at UpGuardAt UpGuard, we are replacing manual security bottlenecks with AI-driven precision. Fresh off a US$75M Series C, we... ...workspaces. Technology and physical security services for our offices — two today, potentially four by the end of 2027 across Australia...Remote work
- ...Job Description The Chief Information Security Officer (CISO) is responsible for developing, implementing, and leading the enterprise cybersecurity, information risk management, and compliance strategy across a multi-site manufacturing organization. CISO partners with...Contract workRemote work
- The Chief Information Security Officer will be responsible for defining, leading, and advancing Spring Health’s enterprise-wide information security, technology risk, compliance, and IT strategy This leader will ensure the protection of company assets, customer data, member...Remote workFlexible hours
- ...Join to apply for the Chief Information Security Officer role at ButterflyMX Get AI-powered advice on this job and more exclusive features. Our Mission ButterflyMX is on a mission to empower people to open and manage doors & gates from a smartphone. Our products are installed...Full timeRemote workWorldwideFlexible hours
- ...Chief Information Security Officer (CISO) About the Company Large e-commerce payment solutions company Industry Financial Services Type Public Company Founded 2005 Employees 1001-5000 Funding $200+ million Categories E-Commerce Payments...
- ...Chief Information Security Officer (CISO) About the Company Innovative cybersecurity ratings platform Industry Information Technology and Services Type Privately Held, VC-backed Founded 2012 Employees 201-500 Funding $26-$50 million Categories...Remote work
- ...Chief Information Security Officer (CISO) About the Company Innovative provider of online banking payment solutions Industry Financial Services Type Privately Held, VC-backed Founded 2008 Employees 1001-5000 Specialties fintech e-commerce...
- ...incidents become more extreme and confidential information about models and frontier AI labs... ...METR’s CISO, you will own METR’s overall security posture, proactively planning against... ...Stipend for moving to the Bay Area The office: Catered lunch and dinner daily; in-office...H1bWork at officeWork from homeHome officeRelocation package3 days per week
- ...Job Description and Duties Under the general direction of the Chief Information Officer (CIO), the Chief Information Security Officer (CISO) serves as a high level executive authority for cybersecurity policy, strategy, and IT security governance. The CISO provides...Full timeWork at officeRemote work
- ...Deputy Chief Information Security OfficerApplication materials must be submitted online. Review of applications will begin immediately and will... ...Resources Act (EHRA). The Deputy Chief Information Security Officer (DeputyCISO) reports to the Chief Information Security &...Permanent employmentFixed term contractWork at officeLocal areaImmediate start
$100k - $140k
...’ll make an Impact As a vCISO, you will serve as a fractional security leader and trusted advisor to Ntiva’s GovCon clients, owning the... ...and process procedures Ability to effectively present information and respond to questions from groups of managers, clients, and...Contract workTemporary workRemote workWork visaMonday to Friday
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Chief Information Security Officer. Be the first to apply!
Related searches
- ciso Remote
- senior director information security Remote
- director information security Remote
- information security compliance analyst Remote
- sr information security engineer Remote
- information technology security engineer Remote
- information security lead Remote
- information security Remote
- information security analyst Remote
- senior information security analyst Remote



