Left arrow iconBack to search

VP of Information Security

CU Student Choice Partners LLC
Posted 3 months ago, valid for 9 days
Salary

$130,000 per year

Contract type

Full Time

By applying, a Sonicjobs account will be created for you. Sonicjobs's Privacy Policy and Terms & Conditions will apply.

SonicJobs' Terms & Conditions and Privacy Policy also apply.

Sonic Summary

info
  • The Vice President of Information Security oversees a comprehensive security program within a Microsoft-based environment, blending security leadership with cloud architecture principles.
  • Candidates should have approximately 7 to 12 years of experience in information security or related fields, particularly with Azure and Microsoft 365.
  • The position requires a salary of $180,000 to $220,000, reflecting the seniority and responsibilities involved.
  • Key responsibilities include managing security controls, incident response, and vendor relationships to ensure effective security practices.
  • The role emphasizes a culture of continuous improvement and collaboration across various teams to achieve measurable outcomes.

Title:Ā  Ā Ā VP, Information SecurityĀ 

Standard Hours:Ā  Ā Ā 40

Primary Location:Ā  Ā Ā Home Office

Reports to:Ā  Ā Ā CIO


Position Summary

The Vice President of Information Security leads a modern, business-aligned security program across the organization’s Microsoft-based environment.

This role blends security leadership with cloud architecture and reliability principles, ensuring systems are not only protected, but also resilient, observable, and continuously improving.

The VP will work closely with internal teams, vendors and a managed service provider (MSP), maintaining accountability for outcomes while enabling efficient, scalable operations.

________________________________________

Core Responsibilities

Security Program Leadership

•  Ā Ā Manage and maintain a risk-based, right-sized security program aligned to business prioritiesĀ 

•  Ā Ā Manage security controls that balance protection, usability, and system performanceĀ 

•  Ā Ā Translate risk into clear, actionable decisions for leadershipĀ 

________________________________________

Cloud Security, Architecture & Reliability

•  Ā Ā Working with our vendors, ensure systems are architected with:Ā 

oĀ  Ā Ā Strong identity and access controlsĀ 

oĀ  Ā Ā Secure configurationsĀ 

oĀ  Ā Ā High availability and resilienceĀ 

•  Ā Ā Partner with MSP and IT to build secure, scalable, and fault-tolerant systemsĀ 

•  Ā Ā Promote infrastructure consistency and automationĀ 

________________________________________

Observability, Monitoring & Metrics

•  Ā Ā Manage and enhance monitoring, logging, and alerting across all platformsĀ 

•  Ā Ā Define and track key security and reliability metrics, such as:Ā 

oĀ  Ā Ā Incident detection and response timesĀ 

oĀ  Ā Ā Vulnerability remediation timelinesĀ 

oĀ  Ā Ā System availability and performanceĀ 

•  Ā Ā Improve visibility into system behavior to support faster, more effective decision-makingĀ 

________________________________________

Incident Response & Continuous Improvement

•  Ā Ā Lead all aspects of incident response, including coordination with MSP, COO, and CIO

•  Ā Ā Conduct root cause analysis and implement corrective actionsĀ 

•  Ā Ā Drive a culture of continuous improvement, reducing repeat incidents over timeĀ 

•  Ā Ā Ensure systems and processes evolve based on lessons learnedĀ 

________________________________________

MSP Management & Operations

•  Ā Ā Manage the MSP relationship, ensuring accountability and performanceĀ 

•  Ā Ā Oversee:Ā 

oĀ  Ā Ā Security monitoringĀ 

oĀ  Ā Ā Alert triage and responseĀ 

oĀ  Ā Ā Vulnerability managementĀ 

oĀ  Ā Ā Desk top maintenance and issue resolutionĀ 

•  Ā Ā Define SLAs and ensure operational effectivenessĀ 

________________________________________

Risk, Compliance & Audit

•  Ā Ā Working with internal and external resources, lead SSAE 18 / SOC audits, including preparation and remediation coordination. Ā 

•  Ā Ā Maintain existing policies, standards, and documentation aligned to actual riskĀ 

•  Ā Ā Create new policies as identified

________________________________________

Business Continuity & Resilience

•  Ā Ā Co-Own business continuity and disaster recovery programs across the organizationĀ 

•  Ā Ā Participate in testing and improvement recommendations

________________________________________

Vendor & Partner Security

•  Ā Ā Assess and monitor third-party security postureĀ 

•  Ā Ā Integrate vendor risk into broader risk management practicesĀ 

•  Ā Ā Work with and manage other vendor partners to ensure best security practices and successful audits. Ā  ________________________________________

Security Culture & Awareness

•  Ā Ā Promote a practical, accountable security cultureĀ 

•  Ā Ā Deliver targeted training and awareness programs to staff

•  Ā Ā Stay current on threats and evolving best practicesĀ 

________________________________________

Qualifications

•  Ā Ā ~7–12 years in information security, cloud security, or related rolesĀ 

•  Ā Ā Experience with Azure and/or Microsoft 365 security and architecture

•  Ā Ā Experience with monitoring, incident response, and cloud operationsĀ 

•  Ā Ā Familiarity with automation and modern infrastructure practicesĀ 

•  Ā Ā Experience working with MSPs or external service providersĀ 

•  Ā Ā Exposure to SOC/SSAE 18 and regulated environmentsĀ 

________________________________________

Leadership Profile

•  Ā Ā Hands-on and accountable, with both strategic and technical capabilityĀ 

•  Ā Ā Focused on measurable outcomes and continuous improvementĀ 

•  Ā Ā Pragmatic—balances security, reliability, and business needsĀ 

•  Ā Ā Strong collaborator across technology, operations, and leadershipĀ 

•  Ā Ā Growth-oriented and eager to expand leadership scopeĀ 

________________________________________

Work Conditions

•  Ā Ā Sitting for extended periods of time

•  Ā Ā Dexterity of hands and fingers to operate a computer keyboard, mouse, and other devices

•  Ā Ā Physically able to participate in training sessions, presentations and meetings

•  Ā Ā Some travel is required for the purpose of meeting with management, employees, and occasional credit union client meetings

AA EEO




Learn more about this Employer on their Career Site

Apply now in a few quick clicks

By applying, a Sonicjobs account will be created for you. Sonicjobs's Privacy Policy and Terms & Conditions will apply.

SonicJobs' Terms & Conditions and Privacy Policy also apply.