> Markdown version of [/jobs/ext/239689-chief-information-security-officer](https://www.wearedevelopers.com/jobs/ext/239689-chief-information-security-officer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Chief Information Security Officer - **Company:** Sciens Building Solutions - **Location:** Tallahassee, FL, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Software System Penetration Testing, Microsoft Azure, Backup Devices, Software as a Service, Cloud Computing Security, Cyber Security, Disaster Recovery, Identity and Access Management, Network Security, PCI Data Security Standards, Phishing, Security Information and Event Management, Systems Integration, Software Vulnerability Management, Google Cloud, Information Technology - **Published:** May 19, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=563988c1d4f68db4 ## About the Role * Bachelor's degree in Computer Science, Information Technology, or a related field (or equivalent work experience). * 10+ years in information security, IT risk, or cybersecurity leadership * Experience in SMB, PE-backed, or high-growth environments * Strong working knowledge of: + Cloud security (AWS, Azure, GCP, SaaS) + Identity & access management + Endpoint and network security + Incident response and ransomware defense + Proven ability to communicate cyber risk to non-technical executives and investors * Experience with at least one recognized security framework (NIST, ISO, CIS) * Excellent problem-solving and analytical skills. * Strong communication and interpersonal abilities. * Ability to manage multiple projects and meet deadlines in a fast-paced environment., * Prior experience supporting private equity portfolios or M&A * Experience standing up a security program from scratch * CISSP, CISM, or equivalent certification ## Description Sciens is seeking a Chief Information Security Officer (CISO), who will be responsible for establishing and operating a right-sized, risk-based cybersecurity program that protects the company, supports growth initiatives, and aligns with value-creation objectives. This role balances hands-on execution with strategic oversight, ensuring security enables business performance and mergers & acquisitions (M&A) activity. The key objectives of the role will be to: * Reduce cyber risk that could impact valuation * Establish repeatable, scalable security controls across the company * Support due diligence, integrations, and audits * Build a roadmap that will improve cyber maturity without enterprise-level cost or complexity * Provide clear, board-level visibility into risk posture * Deliver measurable reduction in critical vulnerabilities and incident risk * Perform successful audits and customer security assessments * Improve/reduce cyber insurance terms and premiums WHAT YOU'LL BE DOING (and doing well!) 1. Security Strategy & Governance * Develop and maintain a pragmatic cybersecurity strategy and roadmap aligned to business objectives * Define security policies, standards, and procedures appropriate for a fast growing SMB environment * Establish cybersecurity governance, risk appetite, and reporting mechanisms * Present cyber risk updates to executive leadership and private equity (PE) stakeholders in plain business terms 2. Risk Management & Compliance * Identify, assess, and prioritize cyber risks using a risk-based approach * Oversee vulnerability management, penetration testing, and remediation efforts * Lead compliance initiatives, such as SOC 2, ISO 27001, NIST, CMMC, HIPAA, PCI-DSS * Ensure third-party and vendor risk management processes are in place 3. Incident Response & Resilience * Own the incident response plan, tabletop exercises, and breach readiness * Lead response to security incidents, ransomware events, or data breaches * Coordinate with legal, insurance, forensics, and external advisors as needed * Oversee backup, disaster recovery, and business continuity planning 4. Technology & Operations * Oversee core security tooling (IAM, endpoint security, SIEM/MDR, email security, cloud security) * Ensure secure configuration of cloud, SaaS, and on-prem environments * Partner closely with IT and operations teams to embed security into operations * Make cost-effective build vs. buy decisions 5. M&A Support * Support cybersecurity due diligence for acquisitions * Assess security posture of acquisition targets and provide risk summaries * Lead or advise on post-acquisition security integration and remediation * Align security maturity with PE exit strategy (strategic buyer or IPO readiness) 6. Culture & Awareness * Build a security-aware culture through training and phishing simulations * Act as a business-friendly security advisor * Educate leadership on cyber risk, insurance implications, and regulatory exposure ## Related Videos - [Passkeys: Truly Phishing-Resistant? Implementation and Pitfalls](https://www.wearedevelopers.com/videos/100156-passkeys-truly-phishing-resistant-implementation-and-pitfalls) - [Hate organising your photos? Try it with 5 Terabytes](https://www.wearedevelopers.com/videos/79-hate-organising-your-photos-try-it-with-5-terabytes) - [The Cloud is Calling: Answer with In-Demand Skills](https://www.wearedevelopers.com/videos/945-the-cloud-is-calling-answer-with-in-demand-skills) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [Cloud Run- the rise of serverless and containerization](https://www.wearedevelopers.com/videos/106-cloud-run-the-rise-of-serverless-and-containerization) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)