> Markdown version of [/jobs/ext/2941445-chief-information-security-officer-ciso](https://www.wearedevelopers.com/jobs/ext/2941445-chief-information-security-officer-ciso). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Chief Information Security Officer (CISO) - **Company:** Seneca Resources - **Location:** Birmingham, AL, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Data Analysis, Systems Engineering, Cloud Computing, Cloud Computing Security, CompTIA Security+, Cyber Security, Information Systems, Information Leak Prevention, Decision Support Systems, Identity and Access Management, Intrusion Detection and Prevention, Information Systems Security Architecture Professional, Network Security, Automation of Marketing, PCI Data Security Standards, Cloud Services, Zero Trust Network Access, Software Vulnerability Management, Software Security, Cyber Threat Analysis, Customer Identity Access Management, Information Technology, Cybercrime, Cyber Warfare - **Published:** September 16, 2026 - **Apply:** https://senecahq.com/wp-content/plugins/bullhorn-oscp/#/jobs/48030 ## About the Role * Bachelor's degree in Cybersecurity, Computer Science, Information Systems, Information Technology, or a related field. * Master's degree preferred., * 15+ years of progressive cybersecurity, information security, risk management, or technology leadership experience. * Experience serving in a senior cybersecurity leadership role within a publicly traded, highly regulated, or large-scale enterprise environment. * Demonstrated success leading enterprise cybersecurity transformations across multiple business units, subsidiaries, or geographic regions. * Proven experience presenting to executive leadership teams, Boards of Directors, Audit Committees, and regulators. Preferred Expertise The ideal candidate will have demonstrated expertise in: * Enterprise Cybersecurity Strategy * Information Security Leadership * Cyber Risk Management * Governance, Risk & Compliance (GRC) * Identity & Access Management (IAM) * Privileged Access Management (PAM) * Customer Identity & Access Management (CIAM) * Security Operations (SOC) * Incident Response & Crisis Management * Cloud Security * Application Security * Data Protection & Privacy * Zero Trust Security Architecture * Third-Party Risk Management * Cyber Resilience & Business Continuity * AI Security & Governance * Regulatory Compliance (SOX, PCI-DSS, GDPR) * M&A Cybersecurity Integration * Executive & Board Communications Leadership Competencies * Exceptional executive presence and communication skills. * Ability to influence and drive strategic decisions across business and technology functions. * Strong financial acumen and experience managing large cybersecurity investments and budgets. * Proven ability to build high-performing teams and develop future leaders. * Effective collaborator capable of aligning security initiatives with business growth, customer experience, operational excellence, and innovation. * Demonstrated success translating complex technical challenges into practical business solutions. Preferred Certifications One or more of the following certifications are highly desirable: * CISSP (Certified Information Systems Security Professional) * CISM (Certified Information Security Manager) * CRISC (Certified in Risk and Information Systems Control) * CISA (Certified Information Systems Auditor) * CCSP (Certified Cloud Security Professional) * Equivalent executive cybersecurity certifications ## Description We are seeking a Chief Information Security Officer (CISO) to lead and evolve our global cybersecurity, identity, risk, compliance, and resilience capabilities. This executive will serve as a trusted advisor to senior leadership and the Board, ensuring cybersecurity is embedded into business strategy, operational excellence, digital innovation, and long-term growth., Enterprise Cybersecurity Strategy & Leadership * Develop and execute the enterprise-wide information security and cybersecurity strategy aligned with business objectives, growth initiatives, and risk tolerance. * Lead and continuously mature the Information Systems Security (ISS) operating model, including governance, architecture, cyber defense, identity and access management, compliance, privacy, data protection, application security, and incident response. * Serve as the organization's senior cybersecurity advisor to executive leadership, Board members, and key stakeholders. * Establish cybersecurity priorities, investment strategies, and roadmaps that balance risk reduction with business agility. Cyber Risk Management & Governance * Design and maintain enterprise cybersecurity governance frameworks, including risk appetite, control ownership, exception management, executive escalation, and board reporting. * Create risk prioritization methodologies that connect cybersecurity remediation activities to business impact, customer commitments, regulatory requirements, and operational resilience. * Translate technical vulnerabilities and cyber threats into business-focused risk assessments and investment decisions. * Ensure audit readiness through effective controls, evidence management, and governance processes. Board, Executive & Regulatory Engagement * Provide executive-level reporting that clearly communicates cyber risk, financial exposure, operational impact, customer trust implications, and compliance obligations. * Lead cybersecurity readiness and governance activities supporting public company reporting requirements. * Oversee SEC cybersecurity disclosure readiness, including incident materiality assessments, executive decision support, legal partnership, disclosure documentation, and post-incident reviews. * Advise leadership during significant cyber events and business continuity situations. Security Operations & Cyber Defense * Oversee enterprise cyber defense capabilities including threat detection, incident response, vulnerability management, security operations, and security engineering. * Drive continuous improvement of enterprise security monitoring and defensive controls. * Lead cross-functional response efforts during cybersecurity incidents, partnering with Legal, Communications, HR, Finance, Operations, and Technology teams. * Strengthen ransomware preparedness, cyber resilience, crisis management, and recovery planning capabilities. Identity & Access Management (IAM) * Define and execute enterprise IAM strategy, including Privileged Access Management (PAM), Customer Identity and Access Management (CIAM), access governance, identity lifecycle management, and least-privilege principles. * Modernize identity controls to support cloud platforms, digital experiences, acquisitions, and emerging technologies. * Improve access certification, entitlement management, and account governance processes. Compliance, Privacy & Risk * Lead global compliance programs and regulatory requirements including SOX, PCI-DSS, GDPR, privacy regulations, and other applicable frameworks. * Oversee third-party risk management, vendor security assessments, contractual cybersecurity requirements, and supply chain security practices. * Maintain enterprise security policies, standards, procedures, and controls aligned with industry best practices. Cloud, Data Protection & Emerging Technology Security * Partner with business and technology leaders to secure critical platforms including eCommerce, supply chain, cloud services, analytics environments, engineering systems, and customer-facing technologies. * Define enterprise security requirements for AI-enabled technologies, automation platforms, and emerging digital capabilities. * Lead initiatives focused on data protection, data loss prevention (DLP), secure cloud adoption, and privacy protection. * Establish governance for responsible AI usage, model security, vendor risk management, monitoring, and data safeguards. Mergers & Acquisitions (M&A) * Define cybersecurity requirements for acquisition due diligence, integration planning, and post-close risk management. * Establish security baselines for newly acquired entities, including network security, endpoint protection, identity governance, vulnerability management, and regulatory compliance. * Support business expansion while maintaining consistent enterprise security standards. Talent Leadership & Organizational Development * Build, develop, and retain a high-performing, diverse cybersecurity organization. * Lead and mentor cybersecurity leaders, technical specialists, and strategic partners across global operations. * Foster a security-first culture that encourages collaboration, accountability, continuous learning, and innovation. ## Related Videos - [Fighting the Next Wave of Cybercrime](https://www.wearedevelopers.com/videos/100331-fighting-the-next-wave-of-cybercrime) - [Data Science in Retail](https://www.wearedevelopers.com/videos/586-data-science-in-retail) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Deep Fakes: The Lies We Can’t See](https://www.wearedevelopers.com/videos/1187-deep-fakes-the-lies-we-can-t-see) - [Data Science on Software Data](https://www.wearedevelopers.com/videos/162-data-science-on-software-data) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [What’s the Difference between a Junior, Mid, and Senior Developer?](https://www.wearedevelopers.com/magazine/238-what-s-the-difference-between-a-junior-mid-and-senior-developer)