1

Assistant Ciso Jobs (NOW HIRING)

Cyber Security Manager

Chicago, IL · On-site

$114K - $154K/yr

... CISO with prestigious organizations nationwide Reports to CISO and works with a team of ... Articulate technical and security requirements to departments/business groups Assist in the ...

Cyber Security Manager

San Francisco, CA

$130K - $176K/yr

... CISO with prestigious organizations nationwide Reports to CISO and works with a team of ... Articulate technical and security requirements to departments/business groups Assist in the ...

... CISO with prestigious organizations nationwide Reports to CISO and works with a team of ... Assist with the maintenance of application and operating system software in the Service Delivery ...

Cyber Security Analyst

Manhattan, NY · On-site

$125K - $150K/yr

... - Assist the Agency CISO in ensuring cybersecurity-related change management and CI/CD processes align with NIST separation of duties requirements. - Support the CISO with agency cyber awareness ...

Showing results 21-40

Assistant Ciso information

See salary details

$9

$52

$120

How much do assistant ciso jobs pay per hour?

As of Aug 6, 2026, the average hourly pay for assistant ciso in the United States is $52.06, according to ZipRecruiter salary data. Most workers in this role earn between $17.55 and $84.38 per hour, depending on experience, location, and employer.

What is the difference between Assistant Ciso vs Security Analyst?

AspectAssistant CisoSecurity Analyst
CredentialsOften requires certifications like CISSP, CISM, or CISATypically holds certifications such as Security+, CISSP, or GIAC
Work EnvironmentSupports Ciso in strategic security planning, policy development, and executive communicationFocuses on monitoring security systems, incident response, and vulnerability assessments
Employer & Industry UsageUsed in organizations with dedicated security leadership, often in finance, healthcare, or techCommon in IT teams across various industries for operational security tasks

The Assistant Ciso primarily supports the Chief Information Security Officer in strategic and managerial security functions, while the Security Analyst handles technical security operations and incident response. Both roles require relevant certifications, but their focus and responsibilities differ significantly.

What are the key skills and qualifications needed to thrive as an Assistant CISO, and why are they important?

To thrive as an Assistant CISO, you need expertise in cybersecurity frameworks, risk management, and a solid background in IT, often supported by a bachelor's degree and certifications such as CISSP or CISM. Familiarity with security information and event management (SIEM) tools, vulnerability assessment platforms, and compliance management systems is typically required. Strong leadership, strategic communication, and problem-solving skills help you effectively coordinate security initiatives and collaborate across departments. These competencies are vital for safeguarding organizational assets, ensuring regulatory compliance, and enabling a proactive security posture.

What is an Assistant CISO?

Assistant CISOs, or Assistant Chief Information Security Officers, are senior professionals who support the Chief Information Security Officer in managing an organization's information security program. They help develop and implement security policies, oversee risk management initiatives, and ensure compliance with relevant regulations. Assistant CISOs also coordinate incident response efforts and may supervise teams of security analysts or specialists. Their role is critical in protecting sensitive data and maintaining the organization's cybersecurity posture.

What are some common challenges an Assistant CISO faces when balancing security initiatives with business objectives?

An Assistant CISO often faces the challenge of aligning robust security measures with the organization’s business goals. Balancing risk mitigation with enabling business agility can require careful negotiation and prioritization. The role frequently involves collaborating with various departments to ensure security policies are practical and don’t impede productivity. Effective communication and the ability to translate technical risks into business language are essential, as is staying updated on evolving threats while supporting company growth.
More about Assistant Ciso jobs
What cities are hiring for Assistant Ciso jobs? Cities with the most Assistant Ciso job openings:
What are the most commonly searched types of Ciso jobs? The most popular types of Ciso jobs are:
What states have the most Assistant Ciso jobs? States with the most job openings for Assistant Ciso jobs include:
Infographic showing various Assistant Ciso job openings in the United States as of August 2026, with employment types broken down into 1% As Needed, 75% Full Time, 21% Part Time, 1% Temporary, and 2% Contract. Highlights an 98% Physical, 1% Hybrid, and 1% Remote job distribution, with an average salary of $108,286 per year, or $52.1 per hour.

Chief Information Security Office-Strategy, Programs & GRC AVP

Bank of China Limited, New York Branch

Manhattan, NY • On-site

$65K - $150K/yr

Full-time

Re-posted 28 days ago


Job description

Introduction
Established in 1912, Bank of China is one of the largest banks in the world, with over $3 trillion in assets and a footprint that spans more than 60 countries and regions. Our long-term outlook, institutional weight and global breadth provide our clients with a stable and reliable financial partner, whether in Corporate or Personal Banking or our Trade Services, Commodities, Financial Institutions and Global Markets lines of business.
Overview
This incumbent will provide Strategy, Programs, Governance, Risk and Compliance functions as required to fulfill BOCNY information security program requirements. This incumbent will provide Strategy Coordination, CISO Projects Management, Training & Culture, Metrics & Reporting, Governance, Risk Assessments, Compliance, Data Privacy and Identity functions as detailed below.
Responsibilities
Strategy
  • Coordinate Information Security strategy in alignment with the BOCNY branch strategy.
  • Maintain strategic initiatives tracking and associated KRIs to track progress and execution of the objectives.
  • Conduct quarterly strategy reviews with the CISO team to ensure alignment and momentum continue. Adjust strategy as necessary.
  • Provide end-to-end project management function for all CISO led projects.

Programs
  • Manage all CISO programs, including but not limited to: Information Security Program, Data Privacy Program, and Training & Culture Program including Security Training, Phishing Campaigns, and Tabletop Exercises.

Governance
  • Establish and maintain Information Security policies and procedures.
  • Ensure CISO roles and responsibilities are clearly delineated and documented to ensure efficiency, create synergies and ensure TISR is being properly managed across first and second lines.
  • Periodically refresh and update TISR controls guidance in relevant policies and supporting procedures with detailed implementation guidance.
  • Develop, monitor, and track CISO policy adherence measures and metrics.
  • Provide all administrative functions for the Information Security Committee and all its sub-committees.

Risk
  • Establish and enhance a TISR framework that consists of the appropriate components to effectively manage TISR.
  • Conduct risk assessments of TISR for Projects, Third-Party, New Activities and Applications.
  • Develop and execute an TISR annual work plan of risk identification, assessment, and control evaluation and testing activities.
  • Review and contribute to the development and maintenance of the taxonomy for Risk, Process and Controls for TISR domains.
  • Catalog and oversee remediation of TISR issues include those arising from Audit and Regulatory exams, ITRM deep dives, root cause analyses and control testing.
  • Track observed control gaps and root causes and annually refresh CISO policy and procedures to reflect new and enhanced controls.

Compliance
  • Prepare and submit Audit Requests for evidence.
  • Anticipate audit requests and prepare comprehensive approach to for CISO policy and standards and associated implementation.
  • Prepare response evidence for IT/IS related regulatory exams.
  • Recommend changes to policy, process or procedures to align with OCC and other federal guidelines and regulations.
  • Evaluate and provide evidence of compliance for BOCNY Branch.
  • Liaison with LCD/RAO/IAD to ensure collaboration and partnership so that CISO can meet regulatory IT/IS requirements.

Data Privacy
  • Develop and implement strategies to ensure compliance with relevant privacy laws and regulations.
  • Stay up-to-date with changes in data privacy legislation and industry best practices.
  • Assist in the development and maintenance of privacy policies, standards and procedures.
  • Provide oversight and monitoring of privacy risk assessments by the FLUs.
  • Ensure all relevant processes reflect privacy requirements and comply with laws and regulations.
  • Plan and implement privacy training programs and communications.
  • Identify and assess privacy risks within the organization.

Metrics & Reporting
  • Manage all metrics and reporting for CISO, including: Operational, Executive & Board, Budget & Headcount, Dashboards.

Identity & Access Management
  • Establish and periodically update policies, procedures, and guidelines related to access recertification, incorporating industry best practices.
  • Manage the end-to-end process of user access reviews, including planning, execution, tracking, and resolution of identified issues.
  • Conduct periodic User Recertification & Access Reviews throughout all BOC applications to ensure consistency and accuracy.
  • Collaborate with cross-functional teams, including IT, OSD, and business units, to align access governance with broader organizational goals.
  • Conduct periodic assessments of user access governance processes, identifying opportunities for improvement and implementing necessary enhancements.

Qualifications
  • Bachelor's Degree in Business, Risk, Data, Computer Science, Management Information Systems, Engineering, Mathematics, or related field
  • Minimum 5 years of work experience in Risk Management, Audit, IT/IS Operations, or other relevant functions
  • Minimum 3 years of experience in developing and executing IT/IS Risk programs, projects, and policies
  • Minimum 1 year of experience working with US Banking Regulations, financial industry standards, and industry standard IT/IS Risk Frameworks
  • Strong program, frameworks, project management development, implementation, and maintenance skills
  • Strong writing skills, especially in the context of governing documents, such as policies and standards
  • Strong verbal and interpersonal skills when working with a diverse group of stakeholders that can include senior management, business staff, and technical staff
  • Creative problem-solving skills
  • Strong organizational understanding and ability to navigate complex organizations
  • Results oriented and metrics driven
  • Understanding of financial services business and related processes and IT/IS risks and how to mitigate with well-designed, commercially sound controls
  • Operational and IT/IS risk assessment and management skills in first, second, and/or third line capacity
  • Sound and practical IT/IS risk management and program knowledge
  • Financial / banking industry, business line, and product knowledge
  • Familiarity with IT/IS Risk Management regulations, standards, and frameworks including NIST, ISO27002, FFIEC Guidelines, etc.
  • Risk identification and assessments of different types that are commensurate with the size and complexity of the financial institution
  • IT/IS risk management and audit principles and industry standard practices
  • CISSP/CRISC/ or IT related certifications preferred

Pay Range
Actual salary is commensurate with candidate's relevant years of experience, skillset, education and other qualifications.

USD $65,000.00 - USD $150,000.00 /Yr.