Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Information Security Officer

Shaw Systems Associates

Chief Information Security Officer (CISO)

Shaw Systems is a leading national software provider serving the consumer lending and financial services industry. We are seeking a Chief Information Security Officer (CISO) to lead the protection of corporate and client information assets and drive a secure, scalable technology environment.

This role owns enterprise security strategy, operations, compliance, and risk management while enabling secure adoption of AI, cloud, and automation platforms. The ISO serves as Shaw's primary authority on information security, partnering across business, technology, and client teams to strengthen security posture and support growth.

Organizational Scope

  • Direct Reports: Service Operations Manager, Senior Security Engineers, Security/InfoSec Analysts
  • Team Size: ~8 FTEs + contractors + SOC partner
  • Enterprise Reach: Full client portfolio (financial services focus)
  • Cross-Functional Influence: AI Committee; DevOps, Cloud, Implementation

Responsibilities

1. Security Strategy & Program Leadership

  • Define and mature enterprise information security strategy, policies, and standards
  • Own and evolve Shaw's Information Security Program and SOC 2 Type II compliance
  • Serve as primary security representative for clients, auditors, and executives
  • Lead risk identification, mitigation, and enterprise security roadmap
  • Oversee access controls, third-party risk, and security readiness exercises (DR, incident tabletop)
  • Present security posture, risks, and compliance status to leadership and external stakeholders
  • Hold named accountability for security representations in client agreements (including MSAs and processing agreements); present security posture and risk to clients, prospects, auditors, and executive forums as required

2. Security Operations (SecOps)

  • Oversee 24/7 SOC operations (via partner) and incident response lifecycle
  • Manage threat detection, monitoring, vulnerability management, and remediation
  • Lead response to authentication threats, phishing, and unauthorized access events
  • Maintain and enhance security tooling across the stack, including Microsoft Defender, FortiClient VPN, Arctic Wolf MDR, Keeper, KnowBe4, PAM solutions, and data protection technologies (e.g., DLP)
  • Ensure endpoint, identity, and infrastructure security across cloud and on-prem environments
  • Drive network, cloud, and infrastructure hardening initiatives

3. AI Governance & Security Architecture

  • Lead enterprise AI security strategy and rollout (Copilot, LLMs, AI tools)
  • Design and enforce AI governance framework (usage policies, data protection, access controls)
  • Architect secure AI/LLM environments (mitigating data leakage, prompt injection, etc.)
  • Own Microsoft Purview strategy (DLP, labeling, information protection)
  • Represent AI security posture to clients, auditors, and leadership
  • Manage strategic vendor relationships, including Microsoft, Anthropic, Arctic Wolf, Fortinet, Keeper, and other security and AI partners, ensuring enterprise value and risk alignment

4. Service Operations Oversight

  • Provide leadership oversight to Service Operations (infrastructure, endpoints, support)
  • Ensure reliability, patching, identity governance, and cloud operations (M365/Azure)
  • Drive SLA performance, operational efficiency, and automation initiatives
  • Ensure operational rigor through established tooling and cadences, including patch management (e.g., WSUS), endpoint monitoring, and environment audits

5. Compliance, Risk & Audit

  • Co-own SOC 2 Type II audit lifecycle and evidence management
  • Maintain enterprise risk register and mitigation tracking
  • Lead client/vendor security assessments and regulatory readiness
  • Ensure alignment with frameworks (ISO 27001, NIST, FFIEC, GLBA, SOX)
  • Ensure third-party vendor due diligence, security requirements, and contractual obligations are aligned with Shaw's Information Security Program and documented appropriately
  • Monitor regulatory developments (including AI and privacy laws)
  • Own security representations in client agreements and audit responses
  • Provide security review, guidance, and approval on security-related representations in client, regulatory, and third-party engagements, in partnership with executive leadership, Legal, and Compliance

6. Leadership & Culture

  • Lead, mentor, and develop InfoSec and Service Ops teams
  • Manage vendors, contractors, and partner performance
  • Promote enterprise-wide security awareness and training programs
  • Partner with HR on hiring, workforce planning, and organizational design

7. Strategic & Cross-Functional Collaboration

  • Advise executive leadership on security and AI risk strategy
  • Partner with DevOps, Cloud, and Implementation teams on secure design practices
  • Support business development (security questionnaires, client discussions)
  • Translate technical risk into business impact for diverse stakeholders

Requirements

Education

  • Bachelor's or Master's degree in Computer Science, Engineering, or related field

Experience & Expertise

  • 10+ years in information security leadership
  • 5+ years securing cloud environments (Azure preferred, AWS acceptable)
  • Strong experience with SOC 2, ISO 27001, NIST, OWASP, FFIEC, GLBA, SOX
  • Deep technical background across DevOps, infrastructure, and security tooling
  • Expertise in network security, IAM, DLP, SIEM, and vulnerability management
  • Experience with Microsoft security stack (Defender, Purview, Intune, Entra ID, Azure)
  • Demonstrated experience with AI platforms and governance (e.g., Copilot, LLMs)
  • Financial services or lending industry experience preferred

Certifications

  • CISSP (required)
  • CCSP (required)
  • ISSAP (preferred)

Leadership Competencies

  • Strategic security leadership and business alignment
  • AI governance and emerging technology risk management
  • Operational execution and compliance discipline
  • Strong communication, stakeholder influence, and executive presence
  • Analytical problem-solving and results orientation
  • Vendor and partner management expertise

Performance Expectations (First 12 Months)

  • SOC 2 Type II audit completed with no material findings
  • Enterprise AI governance framework fully implemented
  • Microsoft Purview DLP and labeling deployed enterprise-wide
  • Mature security operations cadence with measurable SLAs
  • Updated BCP/DR program tested
  • Improved phishing awareness and security training outcomes

Supervisory Responsibility

  • Leads a team of internal, contractor, and external partners supporting security operations and enterprise infrastructure.

Location

  • Hybrid: Within 75 miles of Houston, TX
  • Remote (eligible states): TX, VA, FL, GA, ID, LA, MI, MN, NJ, NC, PA, UT
  • Travel: 10–25% as needed

Work Environment

  • Full-time, Monday–Friday; standard business hours with occasional after-hours support as needed.
Vacancy posted 1 day ago
Similar jobs that could be interesting for youBased on the Information Security Officer in Salt Lake City, UT vacancy
  • $35 - $40 per hour

     ...programs, which may vary.  Ready to Join the Movement?  Apply today and start moving your career in the direction you want. For more information, visit  or follow the brand on Facebook, Instagram, Twitter, YouTube and LinkedIn.  Powered by JazzHR hfNKYI3w1Y... 
    Suggested
    Hourly pay
    Full time
    Part time
    Immediate start
    Weekend work

    The Joint Chiropractic

    Bountiful, UT
    1 day ago
  • $80k - $100k

     ...as well as ensuring that you have the financial stability and security to think long term. Underpinning all of this is a clear set of...  ...an innovative force, where healthcare meets retail. For more information, visit     Business Structure The Joint Corp. is a franchisor... 
    Suggested
    Part time

    The Joint Chiropractic

    Sandy, UT
    13 days ago
  • A growing organization is seeking a Director or VP of IT/Technology to lead IT operations and shape the technology vision. The ideal candidate will possess over 10 years of experience in IT, have strong expertise in infrastructure and cybersecurity, and be comfortable ...
    Suggested
    Full time

    DASH2

    Salt Lake City, UT
    3 days ago
  •  ...Description Job Description IT Operations & Security Manager We are a 45-year-old company...  ...software business. *This is an in-office position in either of our offices in...  ...Position Preferences ~ Bachelor’s in Information Technology, Computer Science, or a related... 
    Suggested
    Work at office
    Remote work
    Flexible hours

    FairCom

    Sandy, UT
    14 days ago
  •  ...Sr. Manager, IT Security Operations KēSTA I.T. is actively seeking a Sr. Manager, IT Security Operations for an immediate full-time...  ...Requirements ~ Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related field ~8+ years of... 
    Suggested
    Permanent employment
    Full time
    Temporary work
    Immediate start

    Kesta IT

    Salt Lake City, UT
    15 hours ago
  •  ...and environments and be able to conduct network and application security vulnerability analysis. The candidate will analyze both...  ...communication skills ~ BS (or equivalent) in Cybersecurity, Information Security, IT, EE, Network Engineering, Computer Science, or related... 
    Full time

    Dark Wolf Solutions

    Salt Lake City, UT
    5 days ago
  •  ...and its mission. Position Summary: DMBA is looking for an Information Security SOC Manager to join the Information Security Team. The Information Security Team reports to the Chief Technology Officer and is responsible for the Information security program. This role... 
    Work at office
    Remote work

    Deseret Mutual Benefit Administrators

    Salt Lake City, UT
    24 days ago
  •  ...applications. This role requires someone who can effectively manage vendor relationships while ensuring operational excellence and security compliance within the organization. The position is fully remote, targeting candidates with strong leadership skills and over 10... 
    Remote work

    Confluent

    Salt Lake City, UT
    7 days ago
  •  ...Chief People Officer – Salt Lake City, Utah Reporting to the CEO, the Chief People Officer plays a key role on the leadership team in building a highly engaged team and supporting a culture that will fuel our growth and support our mission to build a Seriously Nice... 
    Remote work

    Professional Recruiters

    Salt Lake City, UT
    1 day ago
  • $87.7k - $164k

     ...these qualities. Today’s world is fuelled by vast amounts of information. Data is more valuable than ever before. Protecting data and...  ...is central to doing business, and everyone in EY Information Security has a critical role to play. Join a global team of almost 950... 
    Summer holiday
    Local area
    Flexible hours

    EY

    Salt Lake City, UT
    4 days ago
  •  ...Chief Growth Officer Job Category: Senior Leadership Full-Time Meridian, ID 8364...  ...the company. In this position, you will secure client relationships that are aligned in...  ...evolving client and market demands. Data informs smarter growth decisions. Uses market intelligence... 
    Full time
    Contract work
    Remote work
    Flexible hours

    Thomas Cuisine

    Salt Lake City, UT
    1 day ago
  •  ...Chief Innovation Officer Academic Affairs University of Utah Salt Lake City, UT The Chief Innovation Officer for Academic Affairs (CIOAA) is responsible for centralizing, accelerating, and scaling innovation across the University's Academic Affairs ecosystem. This... 
    Work at office

    EXACTO Inc

    Salt Lake City, UT
    14 hours ago
  •  ...Commerz Ventures, Pale Blue Dot, Deloitte, and other world-class investors. We’re a wonderfully diverse, growing team with physical offices in London and New York City. Climate X is on a mission to revolutionize how the world manages assets, property, and... 
    Work at office
    Remote work
    Night shift
    3 days per week

    CLIMATEX

    Salt Lake City, UT
    3 days ago
  • $115k - $150k

     ...leading emergency management and homeland security consulting firm. Known for its public...  ...experts). Strong proficiency with MS Office products, databases, and other software...  ...marital status, military status, genetic information, or any other status, characteristic or... 
    Permanent employment
    Temporary work
    Local area
    Immediate start
    Remote work
    Flexible hours

    Hagerty Consulting

    Salt Lake City, UT
    1 day ago
  • $186.9k - $220.4k

     ...ll Make Define and lead product security strategy across web, mobile, API, cloud...  ...'ll Join ~ You will join a growing Information Security team at Recursion, focused on enabling...  ...scale. Recursion also maintains offices in New York, Montréal, and London, three... 
    Local area
    Remote work
    Work from home
    Shift work

    RECURSION CO

    Salt Lake City, UT
    3 days ago
  •  ...Description Description: Due to continuing growth, we are seeking a Security Engineer focused on securing and monitoring a Microsoft 365–...  ...sized businesses and their owners. We currently have 50+ offices across 15 states with much more growth on the horizon. Enjoy a... 
    Work at office

    PT&C Group LLC

    Salt Lake City, UT
    21 days ago
  • AlediumHR is seeking a Director of People for a regional hospital in northeastern Nevada. This executive role will influence workforce strategy and employee engagement directly partnering with the CEO. The ideal candidate will have extensive HR leadership experience and...
    Relocation package

    AlediumHR

    Salt Lake City, UT
    3 days ago
  • $120.1k - $251.6k

     ...(Engineering, Capacity Planning, Construction, Supply Chain, Security, NOC/Operations, and vendors/carriers), and drive rapid risk mitigation...  ...and occupational health mandates. Range and benefit information provided in this posting are specific to the stated locations... 
    Temporary work
    Flexible hours
    Night shift

    Oracle

    Salt Lake City, UT
    8 days ago
  • $104k - $156k

     ...Posting Type Remote/Hybrid Job Overview As an Advanced Security Engineer focused on Endpoint Security, you will design, build,...  ...qualifications: ~ Bachelor's in Computer Science, Information Security, or equivalent experience. ~2+ years of... 
    Remote work

    Relativity

    Salt Lake City, UT
    4 days ago
  •  ...Summary Sunwest Bank is seeking a qualified candidate to assist the VP, Information Security Officer in the continued development, management, and optimization of the Sunwest Bank Information Security Program with an emphasis on Cybersecurity components. The qualified... 
    Work experience placement
    Local area
    Shift work

    Sun West Bank

    Sandy, UT
    5 days ago
  • $82.5k - $199.5k

     ...customers, client services, sales, support, engineering, design, QA, security, privacy, compliance, and operations to identify needs and...  .... Conduct market research and competitive analysis to inform product direction. Collaborate with design teams to create intuitive... 
    Temporary work
    Flexible hours

    Oracle

    Salt Lake City, UT
    9 days ago
  •  ...This is a 3rd shift position 12AM-9AM EST Bachelor's Degree from four-year college or university in Information Technology, Information Security/Assurance, Engineering or similar area of study required. Prefer 1-2 years SOC/ Information Security experience... 
    Night shift

    The Dignify Solutions LLC

    Salt Lake City, UT
    5 days ago
  •  ...is a hybrid schedule with some weekly in office expectation, based on business need....  ...and quality control for technology and security related Key Risk Indicators (KRIs). Improve...  ...Experience ~ Bachelor's degree in Information Security, Computer Science, Information... 
    Full time
    Work experience placement
    Work at office
    Remote work

    Mountain America Credit Union

    Sandy, UT
    3 days ago
  • $144.9k - $265.8k

     ...solutions using Microsoft Entra, Okta, Ping, Saviynt Design cloud security and IAM architectures for Azure, AWS, GCP, and hybrid...  ...those living in California, please click here for additional information. EY focuses on high-ethical standards and integrity among... 
    Work experience placement
    Summer holiday
    Flexible hours

    EY

    Salt Lake City, UT
    3 days ago
  • $120k - $230k

     ...technology you need to thrive - in our offices or yours. Job Summary The Pre-Sales...  ...Solutions Engineer is a customer-facing security professional who provides consultative technical...  ...communicate complex ideas and information to diverse audiences and can facilitate... 
    Work at office
    Remote work
    Worldwide
    Flexible hours

    SHI GmbH

    Salt Lake City, UT
    5 days ago
  •  ...Management to clarify requirements, prioritize work, and deliver secure, high-quality releases. The role also ensures development...  ...including prioritization, coverage, and coordination across in-office and remote schedules. ~ Develop and maintain clear policies... 
    Work at office
    Remote work

    Feditc LLC

    Salt Lake City, UT
    1 day ago
  • $122.5k - $355.4k

     ...developing,troubleshooting, and operating mission-critical cloud security services. This role supports the OCI Crypto organization ,...  ..., and/or drug testing requirements. Range and benefit information provided in this posting are specific to the stated locations... 
    Temporary work
    Flexible hours

    Oracle

    Salt Lake City, UT
    5 days ago
  • $120k - $140k

     ...to our HQ in San Diego, CA. Other onsite office locations include: Las Vegas, NV,...  ...enterprise-wide solutions with a focus on security, performance, continuous integration and...  ...age, protected medical condition, genetic information, physical disability, mental disability,... 
    Work at office
    Local area
    Remote work

    axosbank.com

    Salt Lake City, UT
    4 days ago
  • $122.5k - $291.8k

     ...functional teams. Establish best practices for scalable, secure, and robust deployment of data services, ensuring seamless...  ...mandates, and/or drug testing requirements. Range and benefit information provided in this posting are specific to the stated locations... 
    Temporary work
    Flexible hours

    Oracle

    Salt Lake City, UT
    4 days ago
  • $110.1k - $264.1k

     ...and Access Management organization provides the foundational security capabilities that protect sensitive healthcare data and enable...  ...responsibility that comes with securing sensitive healthcare information. You should be comfortable operating in a fast-moving environment... 
    Temporary work
    Flexible hours

    Oracle

    Salt Lake City, UT
    15 hours ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Information Security Officer. Be the first to apply!