1

Assistant Chief Information Security Officer Jobs

Title: Chief Information Security Officer (CISO) Location: Remote - USA Reports to: Chief Technology Officer The Role: JD Power is seeking an enterprise-level security leader to serve as Chief ...

CHIEF INFORMATION SECURITY OFFICER

Reno, NV · On-site

$129K - $181K/yr

As a key member of the leadership team, the Chief Information Security Officer (CISO) will lead the cybersecurity strategy that supports this vision by strengthening cyber resilience, managing ...

The CISO, in collaboration with business leaders, will guide and assist with the development and implementation of a security program, facilitate information security governance, advise the CIO on ...

NY · On-site

Chief Information Security Officer page is loaded## Chief Information Security Officerlocations: FL - State-wide Remoteposted on: Posted Todayjob requisition id: R-100797**CHIEF INFORMATION SECURITY ...

next page

Showing results 1-20

Assistant Chief Information Security Officer information

See salary details

$70K

$148.7K

$232.5K

How much do assistant chief information security officer jobs pay per year?

As of Jul 30, 2026, the average yearly pay for assistant chief information security officer in the United States is $148,746.00, according to ZipRecruiter salary data. Most workers in this role earn between $118,000.00 and $167,500.00 per year, depending on experience, location, and employer.

What is an Assistant Chief Information Security Officer?

An Assistant Chief Information Security Officer (Assistant CISO) is a senior-level executive who supports the Chief Information Security Officer (CISO) in managing and overseeing an organization's information security programs. They help develop security policies, coordinate risk management efforts, and ensure compliance with relevant regulations. The Assistant CISO often leads security teams, manages incident response, and assists in creating strategies to safeguard the organization's digital assets. This role is critical in maintaining the security posture of an organization and responding effectively to cybersecurity threats.

What are the key skills and qualifications needed to thrive as an Assistant Chief Information Security Officer, and why are they important?

To thrive as an Assistant Chief Information Security Officer, you need deep expertise in information security, risk management, and regulatory compliance, often supported by a bachelor’s or master’s degree in a related field and certifications such as CISSP or CISM. Familiarity with security frameworks (e.g., NIST, ISO 27001), threat intelligence platforms, and incident response tools is vital. Strategic leadership, communication, and problem-solving skills help you guide teams and influence organizational security culture. These competencies are critical for effectively safeguarding sensitive data and ensuring organizational resilience against evolving cyber threats.

What are some common challenges faced by an Assistant Chief Information Security Officer when implementing new security protocols across departments?

Assistant Chief Information Security Officers often encounter challenges such as resistance to change from staff, varying levels of cybersecurity awareness across departments, and the need to balance strong security measures with operational efficiency. Effective communication and collaboration with department heads are crucial to address concerns and ensure smooth adoption of new protocols. Additionally, the role requires staying updated on the latest threats and ensuring that security standards comply with regulatory requirements, all while managing limited resources and competing priorities.
What cities are hiring for Assistant Chief Information Security Officer jobs? Cities with the most Assistant Chief Information Security Officer job openings:
What are the most commonly searched types of Chief Information Security Officer jobs? The most popular types of Chief Information Security Officer jobs are:
What states have the most Assistant Chief Information Security Officer jobs? States with the most job openings for Assistant Chief Information Security Officer jobs include:
Infographic showing various Assistant Chief Information Security Officer job openings in the United States as of July 2026, with employment types broken down into 1% As Needed, 76% Full Time, 20% Part Time, 1% Temporary, and 2% Contract. Highlights an 98% Physical, 1% Hybrid, and 1% Remote job distribution, with an average salary of $148,746 per year, or $71.5 per hour.

Chief Information Security Officer

JD Power

Remote

Full-time

Re-posted 4 days ago


Job description

Job Description:
Title: Chief Information Security Officer (CISO)
Location: Remote - USA
Reports to: Chief Technology Officer
The Role:
JD Power is seeking an enterprise-level security leader to serve as Chief Information Security Officer (CISO). As a member of the Technology Leadership Team, the CISO is the enterprise-wide owner of global cyber security, information risk, and resilience, providing strategic leadership across all regions to protect clients, systems, data, intellectual property, and brand reputation.
The CISO defines and executes the global security strategy, leads security operations and governance, ensures compliance with international regulations and standards, and acts as the organization's senior authority on cyber risk
The Impact You Will Have in This Role:
As Chief Information Security Officer, you will be the driving force behind protecting JD Power's clients, systems, data, and brand across every region. By defining and executing the global security strategy, maturing governance and security operations, and embedding a strong security culture, you will reduce enterprise risk while enabling the business to innovate and grow with confidence. You will serve as the organization's senior authority on cyber risk-providing the CTO, Operating Team, Board, regulators, and customers with assurance that security is a strategic enabler rather than a barrier.
What You'll Be Doing in This Role:
Global Security Strategy & Leadership
  • Own Global Security Strategy: Define and own the global cyber security strategy, aligned to business objectives and risk appetite.
  • Advise Senior Leadership: Provide senior-level leadership and act as a trusted advisor to the CTO, Operating Team, Board Cybersecurity Committee, and senior leaders.
  • Lead Planning & Investment: Lead global planning, budgeting, capability development, and vendor strategy for all security domains.
  • Build a Security Culture: Promote a strong security culture across all regions, embedding secure behaviors and accountability.

Governance, Risk Management & Compliance
  • Operate the ISMS: Lead the design, implementation, operation, and continuous improvement of the Information Security Management System (ISMS) aligned to ISO 27001, SOC2, TISAX, and other relevant frameworks.
  • Manage Enterprise Risk: Oversee global risk management, including risk assessments, control selection, and enterprise risk reporting.
  • Compliance: Ensure compliance with global cyber security regulations and industry standards.
  • Maintain Policies & Standards: Lead the development and maintenance of global security policies, standards, and guidelines.
  • Govern Third-Party Risk: Oversee third-party and supply-chain security, including vendor assessments and due diligence.

Security Operations, Threat Management & Incident Response
  • Lead Security Operations: Lead global Security Operations (SecOps), including monitoring, detection, threat intelligence, and vulnerability management.
  • Mature CSIRT/CSOC Capabilities: Establish and mature global CSIRT/CSOC capabilities, ensuring 24/7 coverage where required.
  • Command Major Incidents: Act as executive incident commander for major cyber events, ensuring effective response, communication, and recovery.
  • Drive Continuous Improvement: Maintain incident playbooks, escalation paths, and post-incident reviews to drive continuous improvement.

Cloud, Application & Product Security
  • Define Secure Architecture: Define and oversee secure architecture, cloud security standards, and identity & access management (IAM).
  • Embed Security in the SDLC: Embed security into the software development lifecycle (SDLC), including secure coding, DevSecOps, and product security reviews.
  • Partner with Engineering: Partner with Engineering and Technology teams to ensure secure design, encryption, and access controls across all platforms.

Regulatory, Customer & External Engagement
  • Represent Security Externally: Act as the senior representative for cyber security with regulators, auditors, customers, and partners.
  • Manage Security Assessments: Oversee responses to customer and partner security assessments and due-diligence requests.
  • Track Regulatory Change: Monitor global regulatory developments and translate them into actionable controls and programs.

People Leadership & Organizational Development
  • Lead Global Teams: Lead and develop global teams across security operations, governance, risk, compliance, and resilience.
  • Build Organizational Capability: Build organizational capability, succession planning, and specialist talent pipelines.
  • Foster High Performance: Foster a collaborative, high-performance culture across regions and functions.

Qualifications of this Role:
  • 10+ years of experience in information security, cybersecurity, with at least 5+ years in a senior leadership role
  • Proven track record of incident response leadership and crisis management.
  • Relevant certifications such as CISSP, CISM, CISA, ISO 27001 Lead Auditor
  • Experience leading large-scale enterprise security programs and managing global teams, including leaders of leaders.
  • Strong knowledge of modern enterprise security practices, including identity and access management, cloud security, endpoint security, DevSecOps, threat detection, and vulnerability management.
  • Understanding of emerging AI security risks and controls, including securing AI-enabled workflows and enterprise AI platforms.
  • Experience securing modern cloud and development environments across platforms such as AWS, Azure, or GCP.
  • Familiarity with modern security frameworks and standards such as NIST, ISO 27001, PCI, or OWASP.
  • Demonstrated ability to communicate complex security topics to executive leadership and nontechnical stakeholders.
  • Experience with risk management, compliance, and regulatory requirements relevant to enterprise software companies.
  • Strong business acumen, particularly in aligning security investments with financial and operational priorities.

This position has a starting salary range of $250,000 - $275,000 USD per year. This is the range we reasonably and in good faith expect to pay for the role at the time of posting. An employee's pay within the range is determined by a number of factors, including relevant skills, education, qualifications, experience, performance, business or organizational needs, and geographic location.
Company Mission
Our mission in the market we serve is clear. To power every auto-related decision through proprietary data, advanced analytics, deep industry expertise, and seamless workflows that connect insight to action.
Our Values
We POWER Our Customer's Success
We are Innovative, Collaborative and Grounded in Data
We Make Things Easy
We Get It Done
We Start with Trust & Prove it Everyday
JD Power is committed to employing a diverse workforce. Qualified applicants will receive consideration without regard to race, color, religion, sex, national origin, age, sexual orientation, gender identity, gender expression, veteran status, or disability.
Should you require accommodations during the recruitment and selection process, please reach out to tarecruitment@jdpa.com.
JD Power does not disclose your personal data to unauthorized third parties. However, as a global corporation consisting of multiple affiliated companies in various countries, JD Power has international sites and JD Power uses resources located throughout the world. JD Power may from time to time also use third parties to act on JD Power's behalf. You agree to the fact that to the extent necessary your personal data may be transferred and/or disclosed to any company within JD Power group of companies as well as to third parties acting on JD Power's behalf, including also transfers to servers and databases outside the country where you provided JD Power with your personal data. Such transfers may include for example transfers and/or disclosures outside the European Economic Area and in the United States of America. If you are a California or United Kingdom resident, additional disclosures about the information we collect and how we use that information can be found by clicking here.
To all recruitment agencies: JD Power does not accept unsolicited agency resumes and we are not responsible for any fees related to unsolicited resumes.