Chief Information Security Officer and Privacy Officer
Summary
The CISO & Privacy Officer leads enterprise-wide cybersecurity, privacy, risk management, and compliance programs for a ~1,400-person IT provider, overseeing ISO 27001/PCI/SOC audits, security operations, incident response, and executive advisory.
What You'll Do:
Lead Enterprise Security Strategy
- Develop and execute Long View's enterprise-wide information security strategy and roadmap.
- Establish and maintain security governance frameworks, policies, standards, and controls.
- Monitor emerging cybersecurity threats and translate risks into actionable business recommendations.
- Serve as the executive sponsor for cybersecurity initiatives and investments.
- Lead enterprise security risk assessments and risk treatment planning.
- Ensure ongoing compliance with applicable privacy, security, and regulatory requirements.
- Maintain and continually improve Long View's Information Security Management System (ISMS).
- Support contractual reviews and provide guidance regarding security obligations for clients, vendors, and partners.
- Lead coordination of external audit programs, including ISO 27001, ISO 27018, ISO 42001, PCI, SOC 1, and SOC 2 Type II.
- Support internal control assessments and audit activities in partnership with Finance and executive leadership.
- Ensure continuous readiness for certification and compliance activities.
- Oversee cybersecurity policies, controls, incident response planning, and breach investigations.
- Review security incidents, assess organizational impact, and recommend corrective actions.
- Conduct security awareness initiatives, privacy education, and phishing simulation programs.
- Partner across business units to embed security into technology and operational initiatives.
- Act as a trusted advisor to the CEO, executive leadership team, and Board of Directors.
- Present security strategy, program effectiveness, risk posture, and investment recommendations.
- Collaborate with leaders across Sales, Professional Services, Internal Systems, and Global Operations.
- Represent Long View externally with clients, prospects, partners, auditors, and industry stakeholders.
Drive Risk Management & Compliance
Oversight of Audit & Assurance Programs
Security Operations & Incident Response
Executive Leadership & Business Partnership
What You Bring:
- 15+ years of progressive experience in cybersecurity, information security, risk management, or related disciplines.
- Significant leadership experience in enterprise information security programs.
- Deep expertise with security frameworks and standards, including ISO 27001 and PCI.
- Proven experience designing, implementing, and maintaining an Information Security Management System (ISMS).
- Demonstrated ability to evaluate and mitigate cybersecurity risks within complex organizations.
- Experience working across multiple business functions and influencing executive stakeholders.
- Strong understanding of security governance, remediation planning, compliance, and audit programs.
- Post-secondary education in Information Technology, Cybersecurity, Computer Science, or a related field.
- Certifications such as CISSP, CISM, CRISC, and/or CISA are highly valued.
- ISO 27001 Auditor and PCI ISA certifications are considered strong assets.
- Experience supporting global IT operations is an asset.
Who You Are:
You are a strategic and collaborative leader who combines technical expertise with business acumen. You understand how to balance risk, innovation, and operational needs while building trust across all levels of an organization.
- A strong communicator who can translate complex security concepts into meaningful business decisions.
- Passionate about protecting organizations and enabling client success.
- Comfortable influencing executives, technical teams, and business stakeholders alike.
- Self-directed, highly organized, and capable of thriving in a fast-paced environment.
- Committed to fostering a culture of accountability, continuous improvement, and security awareness.
- Aligned with Long View's core values of Integrity, Competence, Value, and Fun.