What are the responsibilities and job description for the VP, Chief Information Security Officer position at Dunn Belmont Limited?
FlightSafety International is the world’s premier professional aviation training company and supplier of flight simulators, visual systems and displays to commercial, government and military organizations. The company provides training for pilots, technicians and other aviation professionals from 167 countries and independent territories. FlightSafety operates the world’s largest fleet of advanced full-flight simulators and award-winning maintenance training at Learning Centers and training locations in the United States, Canada, France and the United Kingdom.
Find out if this opportunity is a good fit by reading all of the information that follows below.
Purpose of Position
The VP, CISO is a key leadership role responsible for the enterprise Information Security & Risk program. This position leads all Information Security efforts in support of end-to-end security strategy, design, and operational support. The Information Security leader serves as the principal and accountable representative for the enterprise security roadmap and related matters, while building and delivering a highly collaborative working relationship with the end-user community as well as fellow technology and engineering teams. This role is both strategic and tactical, demonstrating strong technical capabilities in the risk / security arena while also exhibiting strong leadership skills within the team and across adjacent functions. This role partners closely with Information Technology while providing leadership and guidance on security implementations, purpose and priority. This position reports to the Chief Information Officer.
Tasks and Responsibilities
- Oversee the development, implementation, and maintenance of the security strategy, risk and governance framework, based on National Institute of Standards and Technology (NIST), that can scale across multiple regulatory controls, geographies, and internal business units to enable a culture of security throughout the enterprise.
- Create a metrics-driven culture using the appropriate methodologies, tools and communications practices.
- Translate technical risks into interpretable organizational risks for a wide range of business and leadership audiences, including the Board and Senior Leadership Team (SLT).
- Partner closely with the business and IT leadership to continually communicate on prioritized industry trends, threat groups / actors as well as emerging risks.
- Collaborate with IT teams within both FSI & NetJets to ensure that security practices are integrated into all systems and processes, balancing security requirements with business agility.
- Develop and implement security policies, protocols, and procedures to safeguard the company’s data, intellectual property, and systems from internal as well as external cyber threats.
- Monitor the external threat environment for emerging threats, advising relevant stakeholders, and coordinating with external agencies, such as law enforcement and other advisory bodies, to ensure that the organization maintains a strong security posture.
- Define and implement 1st and 3rd party risk assessment processes and controls for new technology platforms.
- Lead third-party security assessments for future and existing business partners.
- Work with cyber insurance carriers to implement long term strategic initiatives that comply with external industry / insurance requirements.
- Liaise with business control teams (i.e. Legal, Compliance, HR, Finance, etc.) and IT groups in the security analysis, design, and planning phases of IT and business-related projects to ensure practices are in line with organizational and regulatory policies.
- Partner on security tactics across DevOps, Architecture, and Engineering to ensure robust security engineering practices are in place.
- Establish a strong set of controls for SaaS solutions, enterprise cloud environments and cloud service provider platforms – such as Microsoft Azure, and others – and their embedded security as well as multi-cloud security management technologies.
- Ensure all security incidents are properly investigated, remediated and appropriately communicated.
- Lead internal and external security audits using a rigorous and repeatable methodology, security questionnaires, and provide consistent reporting of results.
- Interact with government regulators and auditors across multiple jurisdictions domestically or globally.
- Build and lead a high-performing Information Security team; provide feedback & coaching to help team develop professionally and grow their skills.
- Travel as required.
- May perform other duties as assigned.
Minimum Requirements
Experience
Knowledge, Skills, Abilities
FlightSafety is an Equal Opportunity Employer / Vet / Disabled. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, or disability.
J-18808-Ljbffr