Position Summary
The Chief Information Security Officer (CISO) will be key member of the ANSI IT executive leadership reporting to the Chief Digital Officer. The CISO is responsible for establishing and maintaining the organization's information security strategy, policies, and procedures to protect digital assets, data, and IT infrastructure.
Essential Functions
- Develop, implement, and maintain a practical, risk-based information security program aligned with the non-profit's mission and budget. This includes an overall strategy and related policies.
- Conduct regular risk assessments to identify vulnerabilities and prioritize remediation efforts.
- Create, test, and lead the incident response plan to handle security breaches, ransomware, or data leaks.
- Ensure adherence to relevant data protection regulations (e.g., GDPR, HIPAA, PCI-DSS) and member privacy requirements.
- Implement employee awareness training to mitigate risks from phishing and social engineering.
- Assess and monitor the security posture of third-party vendors (e.g., cloud fundraising platforms)
- Provide regular updates on security posture and risk to senior leadership and the Board of Directors.
ANSI Enterprise Information Security Responsibilities
- Attend/complete assigned information security training by the designated completion date.
- Read and adhere to published ISMS policies and procedures.
- Report timely any observed violations of ISMS policy - or known encroachments on information security - to your department leader and/or the Information Technology Department.
Education and Experience
- Minimum 7-10 years of experience in IT and security, with at least 5 years in management capacity.
- Bachelor's degree in Management Information System (MIS), Computer Science, Information Technology or related field preferred.
- Experience in a fast-paced non-profit or professional services environment strongly preferred.
Other Qualifications
- Familiarity with network security, cloud security (e.g., Office 365), and endpoint protection.
- Working knowledge of security frameworks such as NIST CSF, CIS Controls and ISO 27001.
- Ability to translate complex technical risks into business impact for non-technical stakeholders.
- CISSP (Certified Information Systems Security Professional) or CISM (Certified Information Security Manager) are highly preferred.
- Ability to leverage free or low-cost tools and prioritize the "80/20" rule (20% of effort that mitigates 80% of risk).
- Ability to define and build a team that fits the ANSI Enterprise size, risk and budget.
- Exceptional organizational and time-management skills with a strong attention to detail
- Superior verbal and written communication skills; ability to represent senior leaders professionally.
- Proficiency in Microsoft Office Suite (Outlook, Word, Excel, PowerPoint) and collaboration platforms (Teams, Zoom, WebEx).
- Strong interpersonal skills and the ability to build relationships across all organizational levels.
- Knowledge of standards industry, manufacturing or process-oriented business preferred.
Starting compensation will be in the $198,100 to $225,800range, depending on education, experience, and other qualifications.
This job description is not designed to cover or contain a comprehensive listing of activities, duties or responsibilities that are required of the employee. Duties, responsibilities and activities may change or new ones may be assigned at any time with or without notice.
ANSI provides equal employment opportunities to all employees and applicants for employment, and prohibits discrimination of any type because of race, gender identity or expression, color, national origin or ancestry, religion, creed, age, marital status, sex, sexual orientation, citizenship or authorized alien status, genetics, disability status, protected veteran status, or any other consideration protected by federal, state, or local laws. ANSI policy also prohibits unlawful discrimination based on the perception that anyone has any of those characteristics. This policy applies to all terms and conditions of employment, including recruiting, hiring, placement, promotion, termination, layoff, recall, transfer, leaves of absence, compensation and training.
Important Notice for Job Seekers: Protect Yourself from Fraudulent Job Postings
We are aware of fraudulent job postings falsely claiming to represent our company. These scams may mirror our legitimate job listings and direct candidates to fake interview links or request personal information. Here's how to spot legitimate opportunities:
- Verify jobs at www.ansi.org
- Apply through our official Workday system at https://ansi.wd1.myworkdayjobs.com/ANSI_Careers
- We won't ask for an interview via Zoom links or texts.
- We would never ask for payment
- We won't ask for sensitive, personal information early in an application process.
- All communication comes from official company emails (@ansi.org).
We prioritize your security and use only official channels. If you see a suspicious posting, please report it to the job board.
|