Apply Edge Start your job search

Chief Information Security Officer

RED SKY Consulting · New York City Metropolitan Area

Apply & track with Apply Edge
Division OverviewThe Information Technology organization drives technology solutions that supports global businesses and clients while ensuring the security, resilience and efficiency of the firm's technology environment. Information Security operates within a highly matrixed global model, partnering closely with technology, business, risk, compliance and regional leadership.Role OverviewThe Managing Director, Americas Regional CISO & Global Head of Security Engineering is a dual-mandate executive role within the Global CISO organization.As Americas Regional CISO, this leader will serve as the senior Information Security executive for the Americas, representing the security organization with regional executives, Boards, regulators, technology leadership and the business. The role will translate global security strategy into regional priorities and strengthen alignment between the Americas and the client’s global, Japan-centered operating model.As Global Head of Security Engineering, this leader will own the strategy, roadmap and continued development of the firm's global Security Engineering capability. The individual will partner closely with CIOs, CTOs, application development, infrastructure, architecture and global security leaders to translate security requirements and risk priorities into scalable technical solutions.The successful candidate must combine executive presence and regulatory credibility with strong technical depth, while operating effectively through both direct leadership and influence in a complex global matrix.Key ResponsibilitiesAmericas Regional CISOServe as the senior Information Security leader for the Americas and represent the Global CISO organization with C-suite executives, Boards, regulators and senior business and technology leadership.Translate global CISO strategy into a clear, measurable Americas security agenda aligned with regional business and regulatory requirements.Partner closely with CIO/CTO organizations, application development, infrastructure, business continuity and disaster recovery, compliance, legal, risk and the lines of business.Maintain visibility into regional cyber risk, control effectiveness, regulatory requirements and remediation priorities, ensuring issues and bad news are surfaced early and transparently.Lead or support regulatory examinations, significant cybersecurity incidents and executive-level security escalations.Strengthen alignment between the Americas security organization and global leadership, acting as an effective bridge between US and Japanese teams.Influence regional priorities and investment decisions across global security pillars, recognizing that many functional teams and budgets remain owned by their respective global leaders.Global Head of Security EngineeringDefine and lead the firm's global Security Engineering strategy, operating model and multi-year roadmap.Build, mature and scale the Security Engineering capability, including organizational structure, talent, standards, governance and delivery.Establish scalable security engineering standards, patterns and technical controls across applications, infrastructure, cloud and hybrid environments.Partner with security architecture, application development, infrastructure and technology leadership to embed security into technology design and delivery.Drive the development and implementation of engineering-led security solutions, using automation, orchestration, analytics and modern tooling to improve security effectiveness and efficiency.Evaluate emerging security technologies and approaches and work with technology teams, vendors and cybersecurity startups to identify and test new solutions.Own the Security Engineering investment agenda and assigned budget, prioritizing initiatives based on risk, regulatory requirements and business value.Strategic Leadership & TransformationDevelop multi-year security roadmaps and translate strategic objectives into measurable initiatives, investment cases and business outcomes.Lead complex, cross-functional security transformation programs across regional and global organizations.Simplify and evolve security policies, standards and controls to improve effectiveness and operational adoption.Apply strong commercial judgment to balance security risk reduction with business enablement, cost and operational realities.Use meaningful metrics to measure security effectiveness, control maturity, remediation progress and program outcomes.Build and develop high-performing teams while fostering a culture of transparency, accountability, collaboration and knowledge sharing.Regulatory, Risk & Executive EngagementMaintain strong knowledge of US and global financial-services cybersecurity regulations and evolving regulatory expectations.Engage regulators and examiners and drive appropriate remediation of regulatory, audit and assurance findings.Communicate complex security risks and technical concepts clearly to Boards, executives and technical and non-technical stakeholders.Build trusted relationships across business, technology, risk, compliance and global security organizations.Secure alignment and executive sponsorship through strong negotiation and influence rather than relying solely on direct reporting authority.Candidate ProfileThe successful candidate will bring:Significant senior Information Security leadership experience within a complex global financial institution or similarly regulated environment.Experience as a CISO, Deputy CISO, Regional CISO, Global Head of Security Engineering/Architecture or comparable senior security executive.Demonstrated experience building, leading or materially transforming a Security Engineering and/or Security Architecture capability.Strong technical understanding across enterprise security architecture, applications, infrastructure, cloud and modern security engineering practices.Experience leading enterprise-scale cybersecurity programs and organizational transformation.Strong knowledge of security frameworks and standards such as NIST, ISO 27001, CIS and COBIT.Experience engaging Boards, C-suite executives, regulators and senior technology and business leadership.Proven ability to operate successfully within a complex global matrix where influence is as important as direct authority.Experience working across global and cross-cultural teams; experience engaging Japanese corporate stakeholders is highly valuable.Executive-level security certifications such as CISSP or CISM strongly preferred.Leadership StyleThe client is seeking a collaborative change agent who can help advance a security organization with meaningful transformation ahead.This individual should be transparent, low-ego and comfortable surfacing problems early. They must be technically credible enough to challenge CIOs, CTOs, application development and infrastructure leaders while remaining an effective relationship-builder rather than a command-and-control security executive.The successful candidate will be able to motivate and connect the Americas team to the broader global organization, navigate different US and Japanese ways of working, and achieve results in an environment where they will not directly own every team or budget.Organizational Context & Success MeasuresThe Americas security organization has historically included approximately 25 professionals, while many security functions and budgets reside within global security pillars. The Security Engineering capability is comparatively small today and represents an opportunity for this leader to professionalize, mature and grow the function.Success will include:Advancing the maturity and effectiveness of the Americas security program.Establishing and executing a clear global Security Engineering strategy and roadmap.Improving security controls, remediation timelines and engineering-led security capabilities.Successfully addressing regulatory, audit and assurance priorities.Strengthening alignment between Americas leadership, global security functions and Japanese headquarters.Building trusted relationships with Boards, regulators, business leaders and technology executives.Developing and retaining high-performing security talent.Working PatternThis is a New York-based hybrid Managing Director role requiring meaningful senior leadership presence in the office. International travel to Japan, London and other locations will occur as business needs require.The role combines the external and executive leadership expected of an Americas Regional CISO with direct global ownership of Security Engineering. The ideal candidate will be equally credible in a Board or regulatory discussion and in a technical conversation with CIO, CTO, architecture, infrastructure and application-development leadership.