empty

Chief Information Security Officer

Navan

Job Description

Posted on: 
November 18, 2024

Summary and company overview

About the job

The Chief Information Security Officer (CISO) is responsible for developing, implementing, and managing the organization’s security vision, strategy, and programs. This dynamic executive role involves leading proactive measures to protect all assets, information, and personnel from potential threats, both defined and undefined. The CISO will collaborate closely with other executive team members to ensure a comprehensive security posture that aligns with the organization's objectives, balancing rapid product innovation with effective risk management.

Responsibilities

  • Develop and Implement Security Strategies: Design and execute comprehensive security strategies and policies to protect the organization’s assets, including products, platforms, digital, and human resources.
  • Proactive Threat Monitoring: Establish and lead a 24/7 Security Operations Center (SOC) for continuous monitoring and real-time threat intelligence, enabling rapid response to emerging threats.
  • Bug Bounty and Ethical Hacking Programs: Launch and manage bug bounty programs and regular ethical hacking exercises to identify and remediate vulnerabilities in applications and infrastructure.
  • Risk Management and Mitigation: Partner with Risk leadership to develop and implement a comprehensive risk management framework. This includes assessing, prioritizing, and mitigating risks across the organization, with a focus on data protection, fraud prevention, and product features that protect customers.
  • Balancing Security and Product Functionality: Work closely with product development teams to integrate security into the product development lifecycle. Ensure that security measures are designed to protect data and systems while enabling product innovation and functionality.
  • Cross-Functional Coordination: Collaborate with IT, legal, compliance, and other departments to ensure a unified and agile response to security threats, fostering cross-functional collaboration and alignment.
  • Leadership and Empowerment: Provide leadership, direction, and guidance to the security team, fostering a culture of security awareness and continuous learning. Empower team members to take decisive action in response to uncertain threats.
  • Real-Time Data Analytics: Leverage advanced analytics and threat intelligence to drive informed decision-making and prioritize security actions based on potential risk.
  • Incident Response and Crisis Management: Develop, test, and lead incident response plans and exercises to ensure the organization is prepared for all potential security incidents, including undefined threats.
  • Security Awareness and Training: Foster a culture of security awareness through the development and delivery of regular training programs for employees, emphasizing agility in response to evolving threats.
  • Innovation and Continuous Improvement: Encourage innovative solutions to complex security challenges and promote a culture of continuous improvement through feedback loops and learning from experience.

Job Requirements

Required Qualifications:

  • Bachelor's degree in Computer Science, Cybersecurity, or a related field.
  • Deep understanding of information security, risk management, and compliance.
  • Proven track record in managing teams, developing security strategies, and collaborating with cross-functional teams.
  • Knowledge of regulatory requirements such as GDPR, DPDP, and PCI-DSS.

Preferred Qualifications:

  • Previous experience leading a technical/engineering organization.
  • MBA or related advanced degree.
  • Certifications such as CISSP, CISM, CISA, or similar.
  • Master’s degree in a related field.
  • Experience with security frameworks like NIST or ISO 27001.
  • Understanding of AI and other emerging technologies and their security implications.

Additional commentary

The posted pay range represents the anticipated low and high end of the compensation for this position and is subject to change based on business need. To determine a successful candidate’s starting pay, we carefully consider a variety of factors, including primary work location, an evaluation of the candidate’s skills and experience, market demands, and internal parity.

For roles with on-target-earnings (OTE), the pay range includes both base salary and target incentive compensation. Target incentive compensation for some roles may include a ramping draw period. Compensation is higher for those who exceed targets. Candidates may receive more information from the recruiter.

Pay Range

$255,000—$415,000 USD

Summary and company overview

About the job

The Chief Information Security Officer (CISO) is responsible for developing, implementing, and managing the organization’s security vision, strategy, and programs. This dynamic executive role involves leading proactive measures to protect all assets, information, and personnel from potential threats, both defined and undefined. The CISO will collaborate closely with other executive team members to ensure a comprehensive security posture that aligns with the organization's objectives, balancing rapid product innovation with effective risk management.

Apply now