Deputy CISO (SVP Security)
CyberApt Recruitment · Wilmington, DE
Apply & track with Apply EdgeSVP of Security Technology3-4x a week on-site in Wilmington DE - Non-NegotiableGlobal Financial Services Firm$350,000-$410,000 + Bonus + Benefits + RSU+ Re-location Package*No sponsorship provided* THIS ROLE REQUIRES DEEP TECHNICAL KNOWLEDGE AROUND TECHNOLOGY/ SECURITY ARCHITECTURE AND SECURITY ENGINEERINGThe SVP, Head of Security Technology, leads the modernization and delivery of the enterprise's core cybersecurity technology capabilities through an AI-enabled, automation-first, engineering-led model. This role reports to the CISO.This Role Is Accountable For Evolving And Integrating:Security ArchitectureSecurity EngineeringIdentity and Access Management (IAM)Continuous Threat and Exposure Management (CTEM)The Position Transforms Legacy, Siloed Security Functions (e.g., Vulnerability Management, Attack Surface Management, Application Security) Into a Scalable, Intelligence-driven Security Ecosystem That:Reduces enterprise risk through engineering and automationEmbeds security into enterprise architecture and technology platformsStrengthens identity lifecycle governance and complianceEnables continuous, risk-based exposure managementImproves efficiency, control effectiveness, and compliance readinessDrives alignment between cybersecurity capabilities and business risk priorities, ensuring security investments directly support enterprise resilience, customer trust, and growth objectivesSecurity ArchitectureDefine enterprise security architecture strategy, standards, and roadmapsEmbed secure-by-design principles across cloud, applications, data, and AIEstablish reusable design patterns and reduce exception-based approvalsIntegrate security into transformation and modernization effortsLead Zero Trust security architecture strategy and adoption across identity, network, application, and data layersEstablish reference architectures for multi-cloud and hybrid environments, including CNAPP, CIEM, and data protection controlsSecurity EngineeringLead engineering and lifecycle management of security platforms and controlsEstablish automation-first operations (API, orchestration, policy-as-code)Standardize tooling and reduce manual processes through automationImprove platform resilience, telemetry, and service performanceTransition to a product and platform-based security engineering model with defined service ownership, SLAs, and performance metricsDrive rationalization of security tools and vendors to reduce cost and complexity while improving capability coverageIdentity and Access Management (IAM) - User Administrative Lifecycle ScopeLead and own overarching IAM strategy and lifecycle governance, including:Provisioning (joiners), Access changes (movers), De-provisioning (leavers)Enhance user access reviews and certificationsImplement, enhance and automate segregation of duties (SoD) monitoring and governanceDesign and implement role and entitlement management capabilitiesEnable access-related compliance and audit readiness in preparation for continuous control monitoring and assessment in alignment with Governance Risk and Control FunctionEnsure least privilege, timely access removal, and reduction of orphaned accountsIntegrate IAM with HR, applications, and enterprise platformsEnhance privileged access management and management of non-human identities in preparation for advanced agentic AI capabilitiesAdvance privileged access, machine identity, and non-human identity security in support of automation, cloud, and AI use casesImplement identity-centric Zero Trust controls and continuous authentication modelsContinuous Threat and Exposure Management (CTEM) Transform vulnerability, attack surface, and application security into a unified CTEM functionImplement continuous, threat-informed prioritization of exposuresAlign findings to asset criticality and business riskImprove remediation effectiveness and reduce exploitable attack pathsEnhance asset visibility, ownership clarity, and dependency mappingPartner with Security Operations and Security Incident and Response functions to coordinate a unified approach across teamsEstablish attack path analysis and exploitability-based risk prioritization to reduce material exposureDefine measurable outcomes such as reduction in attack surface, time-to-remediation, and control effectivenessAI and Automation EnablementDeploy AI and analytics to improve prioritization and decision-makingAutomate repetitive security processes and control validationEnhance reporting, telemetry, and audit evidence generationPartner with Head of Security AI to establish secure AI lifecycle practices, including model governance, data protection, prompt security, and third-party AI risk managementPartner with Head of Security Operations to leverage AI to enhance threat detection, anomaly identification, and predictive risk analyticsDevSecOps and Secure DevelopmentEmbed security into the software development lifecycle (SDLC), CI/CD pipelines, and developer workflowsPartner with engineering teams to implement scalable DevSecOps practices and developer-friendly security toolingOperating Model, Leadership And Other Requirements Establish a global operating model with clear accountability, service ownership, and capability maturity roadmapsDevelop business cases tied to measurable risk reduction, operational efficiency, and cost optimizationPartner with executive leadership and provide board-level reporting on security posture, risk trends, and investment impactTechnology first leader with very strong interpersonal skills with demonstrated ability to build and maintain strong relationships and partnerships vertically and horizontally across a mix of business, technology, legal, HR, risk and audit leaders and practitionersEstablish a product- and platform-based security technology operating modelDefine core requirements that evidence demonstrable risk reduction and can be measured using KPIs/KRIs in conjunction with the metrics and analytics programDrive roadmap, investment prioritization, and tool rationalizationDrive budgetary discipline through management of finances, including the build of defendable business casesLead and develop high-performing, multi-disciplinary teams in a positive and respectful capacity leading to high engagement across all disciplinesOrganically improve the security posture of the organization by ensuring the incorporation of secure principles into every phase of the design, development, deployment, and operation of systems and solutionsAssess current environment and design a target state architecture with all accompanying diagrams and documentation as required by architecture teamsProvide top-level support as needed on security and operational related issuesRepresent information security interests on various project teams and special assignments as directedActive in a continuous improvement of the existing process, methodologies, technologies and practicesProvide top-level on-call support as required for this type of role, which is factored into the compensation for this roleResilience and Risk IntegrationPartner with Security Operations and Incident Response to improve cyber resilience, recovery readiness, and crisis response integrationEnsure alignment with enterprise risk management and regulatory expectations through continuous control monitoringQualifications 15 + years’ experience in a cybersecurity role with at least 5 as head of senior most security architectPrevious and progressive experience in a technical security leadership position.Demonstrated experience modernizing security organizations (tool consolidation, automation, operating model redesign)Strongexpertisein cloud-native security, Zero Trust, IAM, and CTEM practicesExperience integrating cybersecurity with AI/ML technologies and governance frameworksStrong strategic thinking and decision-making capabilitiesExperience managing budgets, vendors, and large-scale programsTrack record of delivering measurable improvements in risk reduction, efficiency, and security postureDisciplined thinker with structured approach to security architecture and strategic planningInherent intellectual capability and curiosity to learn complex processes.Proven thought leadership, strategic thinking and decision-making.Must have strong analytical and problem-solving skills with the capability to identify solutions to unusual and complex problems.CISSP certification is strongly preferredDirect security related AI, networking , infrastructure , cloud, operating system, development , cloud, database experience is requiredMust be able to demonstrat e proficiency in a wide range of security technologies, embedded security, and network platforms – in a global institutionMust be willing to travel (Domestic and International) as required , but not to exceed 30-40%