Search Remote Jobs

Head of Information Security

Job not on LinkedIn

🔥 0 minutes ago

⛰️ Colorado – Remote

infoinfo

đź’µ $127.5k - $204k / year

⏰ Full Time

đź”´ Lead

👮‍♂️ Cybersecurity / Security Engineer

🦅 H1B Visa Sponsor

infoinfo

đź‘» Ghost score 0%

infoinfo
Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Fiserv

Fiserv

10,000+ employees

Founded 1984

đź’Ľ Consulting

📦 Logistics

📣 Marketing

Consulting • Logistics • Marketing

Fiserv is a leading global provider of financial services technology solutions. The company offers a wide range of services including payments and financial services technology for individuals, businesses, and financial institutions. Fiserv supports various sectors such as large enterprises, small businesses, financial institutions, credit unions, and the public sector with digital banking, payment processing, and commerce solutions. Their platforms enable fintech and software providers to integrate and monetize payments effectively. Additionally, Fiserv is committed to corporate social responsibility and has initiatives to support diverse and small businesses.

đź“‹ Description

• Establish and lead MoneyPass Group's information security, cyber risk, and security governance capabilities as it builds an independent technology environment • Define the security strategy, security control environment, cyber risk program, and security responsibilities across MPG and technology partners • Establish security governance across corporate technology, payment and ATM environments, cloud services, software platforms, data platforms, and third-party technology • Define security roles and responsibilities across MPG, MSP/MSSP providers, software partners, and critical vendors • Maintain the cyber risk register and communicate material risks, remediation priorities, and security posture to the CIO and executive leadership • Develop security metrics and executive reporting covering risk trends, vulnerabilities, incidents, control effectiveness, third-party risk, and remediation progress • Oversee security operations including monitoring, SIEM, MDR, EDR, vulnerability management, threat intelligence, identity monitoring, cloud security monitoring, email and collaboration security, and incident response • Hold MSSPs and security providers accountable to SLAs, security requirements, escalation procedures, and performance metrics • Lead cyber incident response, including plans, escalation procedures, tabletop exercises, forensic coordination, notification support, and post-incident reviews • Serve as primary security leader during significant cybersecurity incidents • Establish and oversee identity and access management and implement least-privilege and Zero Trust principles • Establish security architecture principles and review technology implementations and architecture changes • Integrate security into cloud architecture, networks, endpoints, applications, APIs, integrations, and data platforms • Establish software development lifecycle security practices • Evaluate new technologies, including AI and generative AI, for security, privacy, data protection, access, and third-party risks • Own the technology security control environment supporting compliance and customer assurance requirements • Coordinate security audits and drive remediation of findings through closure • Establish and lead third-party technology and cybersecurity risk management • Define vendor security requirements, oversee critical vendor assessments, and maintain responsibility matrices • Ensure contracts include cybersecurity, incident notification, data protection, audit, continuity, and security-control requirements • Establish data protection controls and reduce unnecessary retention and exposure of sensitive information • Operationalize privacy obligations, support data inventories and mapping, and conduct privacy and data protection impact assessments • Embed privacy-by-design principles into architecture reviews and the software development lifecycle • Enable fulfillment of consumer and data subject rights requests • Ensure incident response addresses privacy breach notification obligations • Lead MPG's AI governance program, including acceptable-use policies, AI inventories, risk tiering, approvals, and data controls

🎯 Requirements

• Security leadership, technical depth, risk management, compliance expertise, and vendor governance experience • Ability to personally drive execution in a lean organization • Experience establishing information security strategy, governance, policies, standards, and control frameworks • Experience overseeing security operations, SIEM, MDR, EDR, vulnerability management, threat intelligence, identity monitoring, cloud security monitoring, email and collaboration security, and incident response • Experience managing MSSPs and other security providers against SLAs, security requirements, escalation procedures, and performance metrics • Experience leading cyber incident response, tabletop exercises, forensic coordination, regulatory/customer notification support, and post-incident reviews • Experience establishing identity and access management programs, including SSO, MFA, PAM, joiner/mover/leaver processes, role-based access, access certification, service and privileged account governance, third-party access, and segregation of duties • Experience with security architecture, cloud architecture, networks, endpoints, applications, APIs, integrations, and data platforms • Experience embedding security practices into the software development lifecycle, including code scanning, dependency management, secrets management, application security testing, and remediation • Experience evaluating AI and generative AI solutions for security, privacy, data protection, access, and third-party risks • Experience with SOC 1, SOC 2, PCI DSS where applicable, NIST Cybersecurity Framework, CIS Controls, and customer, contractual, regulatory, and privacy requirements • Experience establishing third-party technology and cybersecurity risk management programs • Experience with vendor security assessments, SOC reports, penetration testing results, certifications, control exceptions, and remediation plans • Experience establishing controls for data classification, encryption, key management, data access, retention and destruction, data loss prevention, secure data transfer, and sensitive-data monitoring • Experience operationalizing GLBA, CCPA/CPRA, applicable U.S. state privacy laws, and GDPR requirements where applicable • Experience with privacy-by-design, data inventories, data mapping, records of processing, and privacy/data protection impact assessments • Experience establishing and leading AI governance programs • No explicit education credential or minimum years of experience stated

🏖️ Benefits

• Annual incentive opportunity, potentially delivered as a cash bonus and equity awards • Equal opportunity employment • Reasonable accommodation during the application and hiring process

Apply Now

Similar Jobs

đź•’ 2 days ago

CACI International Inc

10,000+ employees

🎖️ Defense

🏛️ Government

đź”’ Cybersecurity

Information System Security Officer securing CACI’s DHS mission-critical information systems. Managing RMF, ATO, FISMA, NIST compliance, security controls, assessments, and remediation.

🇺🇸 United States – Remote

đź’µ $90.3k - $189.6k / year

🔥 Funding within the last year

đź’° $500M Post-IPO Debt on 2026-02

⏰ Full Time

đźź  Senior

đź”´ Lead

👮‍♂️ Cybersecurity / Security Engineer

đź•’ 2 days ago

CACI International Inc

10,000+ employees

🎖️ Defense

🏛️ Government

đź”’ Cybersecurity

Information security officer securing CACI’s DHS systems through RMF, ATO, FISMA, and NIST compliance. Leading ATO documentation, assessments, controls, and remediation planning.

🇺🇸 United States – Remote

đź’µ $90.3k - $189.6k / year

🔥 Funding within the last year

đź’° $500M Post-IPO Debt on 2026-02

⏰ Full Time

đźź  Senior

đź”´ Lead

👮‍♂️ Cybersecurity / Security Engineer

đź•’ 2 days ago

The Browser Company

11 - 50

đź’Ľ Consulting

📣 Marketing

Staff Security Researcher conducting offensive research and automated vulnerability discovery for The Browser Company’s agentic Dia browser. Shaping AI red teaming, threat modeling, and durable security fixes.

đź•’ 2 days ago

GE Vernova

10,000+ employees

đź’Ľ Consulting

📦 Logistics

🏭 Manufacturing

Principal Cyber Security Architect securing GE Vernova’s wind turbines, SCADA systems, and digital platforms. Leading IEC 62443 assessments, threat modeling, and product security strategy.

đź•’ 2 days ago

Newell Brands

10,000+ employees

📣 Marketing

📦 Logistics

🍽️ Food & Beverage

Cybersecurity director advancing AI security, governance, budgeting, and CISO initiatives for Newell Brands’ global consumer-goods portfolio. Driving enterprise strategy, transformation, and executive execution.