empty

Chief Information Security Officer

Constant Contact

Job Description

Posted on: 
September 19, 2024

Summary and company overview

Chief Information Security Officer

at Constant Contact

Location: Hybrid from Waltham, MA

At Constant Contact, we are seriously awesome people who take ownership and make an impact by operating with the mindset, integrity and courage of a small business owner. There’s something so profoundly rewarding about knowing that your work is empowering people everywhere to pursue their dreams. Here, we all play an integral part in helping business owners, entrepreneurs, non-profits and individuals to succeed by giving them all the help and tools they need to grow online. We’re energized by new challenges and new possibilities-and we’re just getting started!

As a technical and hands-on Chief Information Security Officer (CISO) reporting to the CIO, you will be responsible for establishing and executing the strategic enterprise vision and proactive program to ensure all of Constant Contacts information assets, employees, customers, and technologies are adequately protected.

Responsibilities

  • Strategy and Leadership:
  • Develop and communicate the organization's cybersecurity strategy, vision, and goals to executive management, board members, and employees
  • Provide leadership and guidance to the information security team, fostering a culture of accountability, transparency, and proactive continuous improvement in cybersecurity practices
  • Collaborate on the overall business technology plan with Engineering, Product, Legal and Revenue, providing a current knowledge and future vision of security technology and systems
  • Oversee a team of Security Professionals to execute on the security roadmap
  • Risk Management:
  • Identify, assess, prioritize, and manage cybersecurity risks to the organization's information assets
  • Develop and maintain the organization's risk management framework, policies, procedures, and standards
  • Security Operations:
  • Oversee the operation of the enterprise's security solutions, including the deployment, monitoring, and maintenance of infrastructure, intrusion detection/prevention systems, endpoint security solutions, etc.
  • Lead Security incident response planning and execution to mitigate potential threats and minimize impact
  • Develop and achieve individual and team focused Security OKRs
  • Compliance and Audit:
  • Ensure the organization's compliance with relevant regulations, laws, and standards pertaining to information security
  • Collaborate with internal and external auditors to conduct regular security assessments, audits and successful recertification of SOC2
  • Training and Awareness:
  • Promote security awareness and coordinate security training programs for employees at all levels of the organization.
  • Foster a culture of proactive cybersecurity awareness and accountability throughout the organization
  • Vendor and Third-Party Risk Management:
  • Evaluate, monitor, and manage risks associated with third-party vendors and service providers
  • Ensure contracts include appropriate security requirements and conduct regular assessments of vendor security practices
  • Budget Management:
  • Develop and manage the information security budget, ensuring optimal allocation of resources and investments in line with organizational priorities

Job Requirements

Required Qualifications:

  • Proven experience (8+ years) in a senior-level information security management role
  • Degree in Computer Science, Information Technology, or a related field
  • Professional Security certifications such as CISSP, CISM, or CISA
  • Experience with certification of common information security management frameworks, such as SOC2, ISO/IEC 27001 and NIST
  • Strong understanding of cybersecurity technologies, risk management frameworks, and global regulatory requirements (GDPR, CCPA, etc)
  • Experience in a SAAS company
  • Experience with cloud and hybrid security principles and practices
  • Track record of successfully building and leading high-performing global cybersecurity teams
  • Innovative thinking and leadership with an ability to lead and motivate cross-functional, interdisciplinary teams
  • Experience with contract and vendor negotiations and management, including managed services

Preferred Qualifications:

  • Advanced degree in Computer Science, Information Technology, or a related field

Additional commentary

NA

Summary and company overview

Chief Information Security Officer

at Constant Contact

Location: Hybrid from Waltham, MA

At Constant Contact, we are seriously awesome people who take ownership and make an impact by operating with the mindset, integrity and courage of a small business owner. There’s something so profoundly rewarding about knowing that your work is empowering people everywhere to pursue their dreams. Here, we all play an integral part in helping business owners, entrepreneurs, non-profits and individuals to succeed by giving them all the help and tools they need to grow online. We’re energized by new challenges and new possibilities-and we’re just getting started!

As a technical and hands-on Chief Information Security Officer (CISO) reporting to the CIO, you will be responsible for establishing and executing the strategic enterprise vision and proactive program to ensure all of Constant Contacts information assets, employees, customers, and technologies are adequately protected.

Apply now