Deputy Chief Information Security Officer (Deputy CISO)
Description
Deputy Chief Information Security Officer (Deputy CISO)
Location: [Remote]
Reports to: EVP, CIO & CISO — Harold Rivas
Department: Security, Risk & Compliance (SRC)
Why Absolute
Absolute empowers mission‑critical performance with advanced cyber resilience. We combine endpoint-to-network visibility with self‑healing controls so customers can keep working—no matter where risk shows up. This role advances that mission by maturing our security operations, incident response, and data protection capabilities while representing Absolute with customers, partners, and the market—especially across North and South America.
The Opportunity
As Deputy CISO, you will be the operational right hand to the CISO—driving day‑to‑day security excellence, uplifting incident response readiness, strengthening data protection, and ensuring our security architecture scales with the business. You’ll also partner with Marketing and Sales to support campaigns, customer briefings, and field events across North and South America, helping translate our resilience story into customer value.
What You’ll Do
1) Operational Security Leadership
- Lead the security operations rhythm (SOC/SIEM/EDR/DLP/identity), driving continuous improvement in detection, response, and recovery KPIs (e.g., MTTD/MTTR, containment time, dwell time).
- Own the major incident process end‑to‑end—war‑room leadership, executive/board‑level communications, post‑incident reviews, corrective actions, and tabletop exercises.
- Establish clear runbooks, playbooks, and on‑call processes; test frequently via purple‑team and crisis simulations.
2) Incident Response & Resilience Uplift
- Design and implement a multi‑layer IR strategy: threat intel integration, automation/SOAR, crisis communications alignment, and validated recovery procedures.
- Drive secure-by-default hardening and control health monitoring to reduce repeat incidents and minimize blast radius.
- Partner with Product/Engineering for product security incident handling and coordinated disclosure.
3) Data Protection & Privacy Enablement
- Mature data protection capabilities (data discovery/classification, DLP, encryption, key/cert governance, secrets management) with measurable coverage and efficacy.
- Embed privacy‑by‑design practices and align with SRC and Legal/Privacy on policy, standards, and control assurance in accordance with Absolute’s Information Security Policy. (Policy and org responsibility alignment)
4) Security Architecture & Risk
- Serve as a hands‑on security architecture leader—partnering with Enterprise Architecture, IT, Cloud/Platform, and Product to guide reference architectures, threat modeling, and zero‑trust patterns.
- Translate business initiatives into risk‑informed security requirements; track exceptions and risk treatments with SRC/GRC.
5) Go‑to‑Market (GTM) & Field Support — NA & LATAM
- Support field marketing and sales campaigns (CISO roundtables, executive briefings, key pursuits) as a credible security executive, connecting customer pain to Absolute’s resilience outcomes. (Examples: CISO roundtables and executive alignment motions)
- Participate in customer briefings (C‑suite, boards, public sector) and partner initiatives; tailor messaging to regional regulations, risk drivers, and buying centers across North America and South America.
6) Governance, Standards & Compliance
- Champion alignment to Absolute’s security policy framework; ensure standards, baselines, and metrics are current and effective.
- Partner with GRC on audits/assessments, issues management, and reporting to executive stakeholders and the board.
- Nice‑to‑have: familiarity with FedRAMP/GovRAMP expectations and public sector procurement nuances.
What You’ll Bring
Required
- 10+ years in cybersecurity with increasing leadership responsibility; 5+ years leading Security Operations/IR and/or data protection at scale.
- Demonstrated success running major incidents, orchestrating cross‑functional response, and driving post‑incident improvements.
- Practical security architecture experience across identity, endpoint, cloud (IaaS/SaaS), network/SASE/SD‑WAN, and data controls.
- Strong communicator who can brief executives/boards and engage credibly with customers and partners in sales/marketing contexts.
- Experience building metrics and operational dashboards that show control health, readiness, and risk reduction over time.
Preferred
- Experience supporting public sector customers (federal/civilian/SLG) and familiarity with FedRAMP/StateRAMP expectations.
- Bilingual or professional proficiency in Spanish and/or Portuguese for LATAM engagements.
- Track record partnering with field marketing & sales on thought leadership, customer reference programs, executive briefings, and competitive pursuits.
Certifications
- CISSP strongly preferred; other relevant certifications (e.g., CISM, CCSP, GIAC GCIA/GCIR, GCCC, GCSA) are a plus.
Education
- Bachelor’s in Computer Science, Information Security, Engineering, or related field.
- Advanced degree (e.g., MBA or Master’s in Cybersecurity) desired.
Work Style & Travel
- Ability to operate in a fast‑moving, global environment; occasional travel, team leadership, and field events across NA & LATAM.
How You’ll Measure Success
- MTTD/MTTR reductions and improved containment/recovery outcomes.
- Increased control health and data protection coverage.
- Documented IR readiness: tested playbooks, exercise outcomes, and audit‑ready evidence.
- Positive impact on GTM activities: customer win support, executive briefings, and campaign participation.
Equal Opportunity
Absolute is an equal opportunity employer. We celebrate diversity and are committed to creating an inclusive environment for all employees.
Absolute Security is proud to be an Equal Employment Opportunity and Affirmative Action employer. We do not discriminate based upon race, religion, color, national origin, gender (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender identity, gender expression, age, status as a protected veteran, status as an individual with a disability, or other applicable legally protected characteristics. If you need assistance or an accommodation due to a disability, you may contact us at [email protected]