Description
The Chief Information Security Officer (CISO) at Pathify is a director level position responsible for establishing and maintaining a comprehensive, enterprise-wide information security and risk management program. The CISO's primary objective is to ensure that the organization's information assets and associated technologies are adequately protected. This role involves identifying, evaluating, and reporting on legal, regulatory, and IT security risks to support the organization's strategic goals and protect its brand and reputation. The CISO is responsible for developing and implementing policies, procedures, and controls to manage and mitigate these risks.
Key Responsibilities
1. Strategy & Governance :
- Develop, implement, and monitor a strategic, comprehensive enterprise information security and IT risk management program.
- Establish and lead an information security governance framework, including management of the information security steering committee.
- Create and manage a unified and flexible control framework to integrate and normalize the requirements of information security policies and regulations.
Develop and maintain a security-conscious culture through ongoing training and awareness programs for all employees.
2. Risk Management & Compliance :
Lead the information security risk assessment process, identifying potential threats and vulnerabilities to the organization's information assets.Ensure compliance with all applicable data protection laws, regulations, and industry standards (e.g., GDPR, CCPA, HIPAA, PCI-DSS, ISO 27001).Work directly with business units to facilitate IT risk assessment and risk management processes, and identify acceptable levels of residual risk.Provide regular reports on the status of the information security program to enterprise risk teams, senior business leaders, and the board of directors.
3. Security Operations & Incident Response :
Oversee the continuous monitoring and protection of information processing facilities, networks, and data.Develop and manage a robust Security Operations Center (SOC) function, either in-house or through a managed service provider.Create, implement, and maintain a comprehensive incident response plan to address security breaches in a timely and effective manner.Lead and coordinate all incident response activities, including investigation, containment, eradication, and recovery. Conduct post-mortem analyses to prevent future incidents.
4. Technology & Architecture :
Provide strategic guidance and oversight for the design and implementation of security architecture for all IT projects.Evaluate and recommend new security technologies and practices to protect the organization against emerging threats.Specifically evaluate and recommend threat analysis and defense against AI enabled vectors.Oversee identity and access management (IAM), vulnerability management, and data loss prevention (DLP) programs.Ensure the security of cloud environments (IaaS, PaaS, SaaS) and third-party vendor systems.
5. Leadership & Team Management :
Lead the information security function across the company, including hiring, training, staff development, and performance management. Note that in the first iteration this role is a team of 1.Create a budget for the information security program and manage it effectively.Serve as a key liaison between the information security team and other departments, including IT, legal, HR, and business units.Communicate security concepts and risks to both technical and non-technical audiences.Skills, Knowledge and Expertise
Education :
Bachelor's degree in Information Security, Computer Science, Information Technology, or a related field.Master's degree (e.g., MBA, Master's in Cybersecurity) is highly preferred.Experience :
Minimum of 10-15 years of experience in information security and / or IT risk management.At least 5-7 years in a senior leadership or management role within a complex organization.Proven track record of developing and implementing successful information security programs.Experience with contract and vendor negotiations and management.Experience in education or a similarly regulated industry (e.g., finance, healthcare) is a plus.
Certifications (one or more preferred) :
Certified Information Systems Security Professional (CISSP)Certified Information Security Manager (CISM)Certified Information Systems Auditor (CISA)Certified in Risk and Information Systems Control (CRISC)Technical Skills :
In-depth knowledge of security frameworks (e.g., NIST, ISO 27001 / 27002, COBIT).Strong understanding of network security, cryptography, application security, cloud security, and IAM.Familiarity with security technologies such as firewalls, intrusion detection / prevention systems (IDS / IPS), SIEM, and endpoint protection.
Key Competencies :
Strategic Thinking : Ability to align security initiatives with business objectives.
Leadership : Strong leadership, communication, and interpersonal skills to build consensus and influence change.
Business Acumen : Understanding of organizational mission, values, and goals.
Risk Management : Expertise in identifying and mitigating security risks.
Problem-Solving : Excellent analytical and problem-solving abilities.
Communication : Ability to effectively communicate complex security concepts to all levels of the organization.
Full-time, work from home position.May require occasional travel to other company locations or for industry conferences.Availability to respond to security incidents and emergencies, which may occur outside of standard business hours.Benefits
401(K)Employee stock purchase planCompany-sponsored outingsCompany-sponsored happy hoursHome-office stipend for remote employeesContinuing education stipendJob training & conferencesOnline course subscriptions availablePromote from withinDental insuranceDisability insuranceFlexible Spending Account (FSA)Health insuranceLife insurancePet insuranceVision insuranceWellness programsMental health benefitsVolunteer in local communityOpen door policyRemote work programTeam based strategic planningOKR operational modelEmployee resource groupsFamily medical leaveGenerous parental leavePaid volunteer timePaid holidaysPaid sick daysUnlimited vacation policyIt’s time to change the way we think about the higher ed digital ecosystem. The truth is, there’s a massive void at the center of the higher ed digital ecosystem because there’s no centralized user experience unifying everything. Pathify is an innovative engagement hub that delivers a dynamic, personalized, and centralized experience to every user on any device. No more searching aimlessly for the right information. Pathify actively surfaces the personalized info and tools each user needs, from any school system. Create a clear path to student success and enrich your school identity with a meaningful and engaging digital campus experience — for the entire student lifecycle. Better technology and a better experience = happier students.