Deputy CISO
E
EthosLife insurance technology
Location: Remote USFull-TimeExecutive
Salary185,000 - 327,000 USD per year
Apply NowOpens the employer's application page
Job Details
- Experience
- 12+ years of experience in security engineering, security architecture, or technical security leadership roles
- Required Skills
- RESTful APIsMicroservices
Requirements
- 12+ years of experience in security engineering, security architecture, or technical security leadership, including hands-on technical work.
- Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or a related field.
- Deep, hands-on expertise in AWS cloud security architecture, including infrastructure-as-code.
- Strong background in application security, secure software development, and modern architecture patterns.
- Experience with microservices, containers, APIs, and zero-trust.
- Ability to read and evaluate system architecture and code at a technical level.
- Experience leading technical incident response and root-cause analysis for complex, multi-system incidents.
- Demonstrated experience building and leading technical security teams.
- Ability to communicate technical risk in business terms to executives and the board.
- Preferred: prior experience as a CISO, Deputy CISO, or Head of Security Engineering at a comparable organization.
- Preferred: CISSP.
- Preferred: AI/ML security experience, including familiarity with OWASP LLM Top 10, MITRE ATLAS, or NIST AI RMF.
- Preferred: experience in regulated industries such as fintech, healthcare, or SaaS at scale.
Responsibilities
- Partner with the CISO to define and execute the security strategy, roadmap, and priorities.
- Represent security leadership in the CISO's absence, including with executives and the board when needed.
- Provide oversight across the security organization and lead security engineers and architects.
- Own security budget planning, vendor and tool evaluation, and resourcing decisions with the CISO.
- Review security architecture across cloud platforms, applications, APIs, and infrastructure.
- Lead threat modeling and architecture reviews for major systems and new initiatives.
- Drive secure-by-design practices into the SDLC and CI/CD pipelines with DevOps and engineering teams.
- Lead or oversee major security incident response, technical root-cause analysis, and remediation planning.
- Translate technical risk into clear terms for non-technical stakeholders and executives.
View Full Description & ApplyYou'll be redirected to the employer's site