About Us: Winsor Consulting Group is a leading Managed Service Provider (MSP) committed to delivering exceptional IT solutions to our clients. We are seeking a strategic and experienced Chief Information Security Officer (CISO) to lead our security initiatives. Job Description: As the Chief Information Security Officer (CISO) at Winsor Consulting, you will be responsible for developing and implementing a comprehensive cybersecurity strategy to protect Winsor and our clients' sensitive data and systems. You will provide strategic leadership and direction for all information security functions, ensuring the confidentiality, integrity, and availability of information assets. This includes developing security policies, managing risks, ensuring compliance, and leading incident response efforts. You will be responsible for the overall security posture and security programs of Winsor and its client(s). Job Duties: • Develop and implement a comprehensive information security strategy aligned with business objectives, regulatory requirements, and industry best practices. • Provide leadership and direction to the team members, fostering a culture of security awareness and accountability. • Oversee the assessment of security risks, vulnerabilities, and threats, and implement appropriate mitigation strategies. • Establish and maintain information security policies, standards, procedures, and guidelines. • Direct the design, implementation, and management of security technologies and controls, including network security, endpoint protection, data loss prevention, cloud security, and identity and access management. • Oversee security monitoring, incident response, and threat intelligence operations, ensuring timely detection, analysis, and resolution of security incidents. • Ensure compliance with relevant laws, regulations, and industry standards, such as CMMC, NIST, ISO 27001, and others. • Provide strategic guidance to clients on cybersecurity best practices, compliance requirements, and risk management. • Collaborate with clients in the strategic design process to translate business requirements into secure technical designs. • Manage the Information Security Risk Platform, including remediation tracking, progress reporting, and risk communication to stakeholders. • Develop and manage the information security budget, ensuring cost-effective allocation of resources. • Serve as the primary point of contact for security-related matters, including audits, assessments, and regulatory inquiries. • Communicate security risks and issues to senior management and the board of directors, providing clear and concise reports on the organization's security posture. • Maintain current knowledge of emerging security threats, technologies, and trends, and proactively identify opportunities to enhance the organization's security posture. • Lead the strategy and execution of event, incident response, and post-mortem analysis in partnership with legal, internal audit, and other stakeholders. Preferred Skills: • Extensive knowledge of cybersecurity principles, best practices, frameworks, and standards (e.g., NIST, ISO 27001, CMMC). • Proven experience in developing and implementing comprehensive information security strategies and programs. • Strong understanding of risk management methodologies, security governance, and compliance requirements. • Excellent leadership, communication, and interpersonal skills, with the ability to effectively communicate complex technical information to both technical and non-technical audiences. • Demonstrated ability to build and lead high-performing security teams. • Strong analytical and problem-solving skills, with the ability to assess complex situations and make sound decisions. • Experience in managing security budgets and resources effectively. • In-depth knowledge of security technologies and tools, including firewalls, intrusion detection/prevention systems, SIEM, vulnerability management, and endpoint protection. • Knowledge of networking monitoring tools and protocols. • Strong understanding of IP networking including DNS, messaging, and routing. • Experience with cloud security and securing cloud environments (e.g., AWS, Azure, GCP). • Knowledge and configuration of data-searching platforms such as OpenSearch or Elastic. Experience: • Minimum of 7-10 years of progressive experience in information security, with at least 5 years in a senior leadership role (e.g., CISO, Director of Security). • Significant experience in developing and implementing security policies, standards, and procedures. • Demonstrated experience in managing security incidents, conducting investigations, and leading incident response efforts. • Experience working with or for a Managed Security Services Provider (MSSP) is highly desirable. • Extensive experience with security toolsets. • Strong background in information security governance, risk management, and compliance. • Experience with the controls and concepts within the NIST Cybersecurity Framework. • Proven experience in driving risk-based decisions and aligning security initiatives with business objectives. Education: • 4-Year degree in Computer Science, Information Security, or a related field. • Advanced degree (Master's) preferred. • Relevant professional certifications such as CISSP, CISM, or CISO certifications are required.
Job Type
Fulltime role
Skills required
No particular skills mentioned.
Location
Tucson, Arizona
Salary
No salary information was found.
Date Posted
April 10, 2025
Winsor Consulting Group is seeking a Chief Information Security Officer (CISO) to lead cybersecurity initiatives and protect sensitive data. The role involves developing security strategies, managing risks, and ensuring compliance with industry standards.