1

Chief Information Security Officer Jobs (NOW HIRING)

Chief Information Security Officer (CISO) Position at GVW Group, LLC Job Title: Chief Information Security Officer (CISO) Location: Birmingham, AL or Chicago, IL Onsite, in office-based position ...

As a key member of the leadership team, the Chief Information Security Officer (CISO) will lead the cybersecurity strategy that supports this vision by strengthening cyber resilience, managing ...

Chief Information Security Officer Job Title: Director VI Agency: Health & Human Services Comm Department: CHIEF INFO SECURITY OFFICE Posting Number: 19093 Closing Date: 09/14/2026 Posting Audience:

NY · On-site

Chief Information Security Officer page is loaded## Chief Information Security Officerlocations: FL - State-wide Remoteposted on: Posted Todayjob requisition id: R-100797**CHIEF INFORMATION SECURITY ...

This role will collaborate and interact with the Chief Risk Officer (CRO) and the Office of Enterprise Risk Management (OERM) on information security risk related topics. Responsibilities

next page

Showing results 1-20

Chief Information Security Officer information

See salary details

$70K

$148.7K

$232.5K

How much do chief information security officer jobs pay per year?

As of Aug 16, 2026, the average yearly pay for chief information security officer in the United States is $148,746.00, according to ZipRecruiter salary data. Most workers in this role earn between $118,000.00 and $167,500.00 per year, depending on experience, location, and employer.

What are the main challenges a chief information security officer faces when aligning security initiatives with overall business objectives?

A CISO often faces the challenge of balancing robust security measures with the need for business agility and innovation. This involves translating complex technical risks into business terms that resonate with executive leadership, ensuring security investments support organizational goals without hindering workflow or productivity. Additionally, CISOs must foster a culture of security awareness while collaborating closely with IT, legal, compliance, and business units to address evolving threats and regulatory requirements. Successfully navigating these challenges requires strong communication skills and a strategic mindset.

What is a chief information security officer?

A Chief Information Security Officer (CISO) is a senior executive responsible for establishing and maintaining an organization’s information security strategy and programs. The CISO oversees the protection of sensitive data, manages cybersecurity risks, and ensures compliance with security regulations. They work closely with other executives to align security initiatives with business goals, respond to security incidents, and lead security awareness training across the organization. Ultimately, the CISO plays a critical role in safeguarding the organization’s digital assets and reputation.

What is the work of a chief information security officer?

A Chief Information Security Officer (CISO) is responsible for developing and implementing an organization’s cybersecurity strategy, managing security policies, and overseeing security teams. They assess risks, ensure compliance with regulations, and coordinate incident response efforts to protect digital assets and information systems.

What is the difference between Chief Information Security Officer vs Security Manager?

AspectChief Information Security OfficerSecurity Manager
CredentialsCertifications like CISSP, CISM, CISACertifications like CISSP, Security+, sometimes CISM
Work EnvironmentStrategic, executive-level, company-wide security policiesOperational, team management, implementing security measures
Employer & Industry UsageLarge corporations, finance, healthcare, techVarious organizations, including mid-sized and large companies
Search & Comparison IntentUnderstanding executive security rolesManaging day-to-day security operations

The Chief Information Security Officer (CISO) focuses on strategic security leadership and policy development at an executive level, while the Security Manager handles daily security operations and team management. Both roles require similar certifications but differ in scope and responsibilities within organizations.

Are Chief Information Security Officer jobs in high demand?

Chief Information Security Officer (CISO) roles are in high demand due to increasing cybersecurity threats and the need for organizations to protect sensitive data. The position requires strong leadership, technical expertise, and often industry certifications, with job growth expected to remain strong as cybersecurity becomes a top priority for businesses across sectors.

What does a chief information security officer do?

A chief information security officer (CISO) is an IT executive who manages and oversees the cybersecurity needs of an organization. Job responsibilities include data and network security, security policy, and security strategy. Their duties involve security operations, cyber-risk and cyber intelligence, data loss prevention, fraud prevention, identity and access management, investigations, and governance. A chief information security officer needs an in-depth understanding of information security, solid comprehension of the organization’s overarching vision, and the ability to combine the two into an actionable strategy.

What cities are hiring for Chief Information Security Officer jobs?

Cities with the most Chief Information Security Officer job openings:

What are the most commonly searched types of Chief Information Security Officer jobs?

The most popular types of Chief Information Security Officer jobs are:

Who are the top companies hiring for Chief Information Security Officer jobs?

The top employers for Chief Information Security Officer jobs are:

What states have the most Chief Information Security Officer jobs?

States with the most job openings for Chief Information Security Officer jobs include:

What job categories do people searching Chief Information Security Officer jobs look for?

The top searched job categories for Chief Information Security Officer jobs are:

Infographic showing various Chief Information Security Officer job openings in the United States as of August 2026, with employment types broken down into 1% As Needed, 74% Full Time, 22% Part Time, and 3% Contract. Highlights an 94% Physical, 2% Hybrid, and 4% Remote job distribution, with an average salary of $148,746 per year, or $71.5 per hour.

Chief Information Security Officer

Lancaster County

Lancaster, PA • On-site

$103K - $154K/yr

Full-time

Medical, Retirement, PTO

Posted 3 days ago

New


Job description

Compensation Range:
$103,077.00 - $154,596.00
Our full-time positions come with an array of excellent benefits including comprehensive healthcare coverage, a pension plan, flexible spending accounts and even a tuition reimbursement program.
At Lancaster County, we understand the importance of work-life balance. That's why we offer paid time off for sick, vacation and holidays, an employee assistance program, and family medical leave.
If you're passionate about making a difference, apply today to join us in serving the community!
Job Description:
JOB SUMMARY
  • The Chief Information Security Officer (CISO) provides strategic leadership and oversight of the County's enterprise cybersecurity, information security, risk management, and cyber resilience programs. Working closely with the CIO and Deputy CIO, the CISO is responsible for protecting County information, technology systems, networks, applications, cloud services, and other digital assets from cybersecurity threats and ensuring appropriate safeguards are established across County operations.
  • The CISO develops and maintains Countywide cybersecurity policies, standards, and security architecture; assesses and manages cybersecurity risk; oversees vulnerability management and security monitoring; directs cybersecurity incident response; evaluates third-party and emerging technology risks; and advises County leadership regarding cybersecurity threats, risks, regulatory requirements, and recommended mitigation strategies.
  • The position provides leadership and oversight for compliance with applicable cybersecurity, privacy, and information-protection requirements, including CJIS, HIPAA, and other federal, state, and local requirements. The CISO also develops and oversees the Countywide security awareness and training program and coordinates cybersecurity activities with County departments, technology providers, government partners, law enforcement, and other external organizations.
  • The CISO provides cybersecurity oversight for the County's business continuity and disaster recovery programs and coordinates with County departments to promote organizational resilience and continuity of critical technology services.
  • This position is designated essential and may be required to respond to cybersecurity incidents, technology outages, natural disasters, or other emergencies outside normal business hours and when County offices are closed.

REPORTING RELATIONSHIPS
  • The Chief Information Security Officer supervises a staff of Security Technicians, Systems & Security Engineers, and IT Security Analysts.
  • The Chief Information Security Officer reports directly to the Chief Information Officer.

ESSENTIAL JOB FUNCTIONS
  • Develop, implement, maintain, and enforce Countywide cybersecurity and information security policies, standards, procedures, and technical security requirements consistent with the strategic direction established by the CIO.
  • Lead the County's cybersecurity and information security program, including security governance, risk management, security architecture, vulnerability management, threat detection, incident response, identity and access security, data protection, and security awareness.
  • Identify, assess, prioritize, and communicate cybersecurity risks and vulnerabilities and coordinate appropriate mitigation, remediation, or risk acceptance with IT leadership, County departments, and other stakeholders.
  • Direct and coordinate the County's response to cybersecurity incidents, including investigation, containment, recovery, documentation, notification, and coordination with executive leadership, law enforcement, government partners, insurers, and other external organizations as appropriate.
  • Provide leadership and oversight for compliance with applicable cybersecurity, privacy, and information-protection requirements, including CJIS, HIPAA, and other federal, state, and local requirements.
  • Develop, implement, and maintain a Countywide cybersecurity, privacy, and HIPAA security awareness and training program, including phishing preparedness and role-based security education.
  • Establish security requirements and provide cybersecurity review and guidance for new systems, applications, cloud services, infrastructure, integrations, and emerging technologies, including artificial intelligence.
  • Oversee third-party cybersecurity risk, including security assessments of vendors, contractors, hosted services, and technology providers and the development and review of appropriate contractual security requirements.
  • Develop and maintain cybersecurity incident response plans and provide security oversight and coordination for IT disaster recovery, business continuity, and cyber-resilience planning.
  • Monitor the County's cybersecurity posture through security monitoring, vulnerability assessments, audits, penetration testing, threat intelligence, and other appropriate security assessments.
  • Establish cybersecurity metrics and reporting and regularly advise the CIO, Deputy CIO, and other County leadership regarding cybersecurity posture, significant risks, threats, incidents, compliance, and remediation efforts.
  • Coordinate cybersecurity initiatives and information sharing with federal, state, and local government partners and other appropriate cybersecurity and law-enforcement organizations.
  • Evaluate emerging cybersecurity threats, technologies, industry practices, and regulatory changes and recommend appropriate changes to County security strategy, architecture, policies, and controls.
  • Provide leadership, direction, mentoring, and technical guidance to cybersecurity personnel and other IT staff and promote security awareness and accountability throughout the organization.
  • Develop and administer cybersecurity-related budgets, contracts, services, and technology investments consistent with organizational priorities and available resources.
  • Manage and direct cybersecurity contractors, consultants, service providers, and vendors and monitor their performance and compliance with County requirements.
  • Participate in strategic planning and collaborate with IT leadership to ensure cybersecurity requirements are appropriately incorporated into County technology strategy, projects, and operations.
  • Perform other duties as assigned and provide leadership during cybersecurity incidents, technology emergencies, and other events requiring an IT security response.

OTHER SPECIFIC TASKS OR DUTIES
  • Perform other duties, tasks and special projects as required.

MINIMUM QUALIFICATIONS
  • Completion of a Bachelor's Degree in Computer Science, or related field, and a minimum of seven (7) years experience in the Information Technology field or;
  • Associate's Degree in Computer Science, or related field, and a minimum of nine (9) years experience in Information Technology field or;
  • Any equivalent combination of relevant education, experience, and training is acceptable.
  • At least one (1) year of management/leadership experience that included strategic planning, resource allocation, production methods, and coordination of people and resources, or; Any equivalent combination of education and experience.

KNOWLEDGE, SKILLS AND ABILITIES
  • Comprehensive knowledge of information security principles, frameworks, controls, and risk management practices, including the NIST Cybersecurity Framework (CSF) and other recognized government and industry cybersecurity standards.
  • Knowledge of applicable cybersecurity, privacy, and regulatory requirements and standards, including NIST guidance, CJIS Security Policy, HIPAA, and other federal, state, and local government requirements.
  • Knowledge of security architecture, identity and access management, network security, endpoint security, vulnerability management, incident response, and data protection.
  • Knowledge of business continuity, disaster recovery, and cyber incident preparedness and response.
  • Knowledge of current and emerging technologies, cybersecurity threats, vulnerabilities, and attack techniques.
  • Strong analytical, risk-assessment, problem-solving, and decision-making skills.
  • Ability to develop and maintain information security policies, standards, procedures, and security awareness programs.
  • Ability to appropriately manage highly confidential, sensitive, and security-related information.
  • Ability to communicate complex cybersecurity risks and recommendations effectively to technical staff, executive leadership, elected officials, department leadership, and other non-technical stakeholders.
  • Ability to lead, mentor, and provide technical and strategic direction to staff.
  • Ability to coordinate cybersecurity activities across County departments and with vendors, contractors, law enforcement, and external partners.
  • Ability to independently prioritize competing security risks and operational requirements while supporting County business needs.
  • Strong written and verbal communication, organizational, leadership, and interpersonal skills.

REQUIRED LICENSES/CERTIFICATIONS/CLEARANCES
  • Valid driver's license and acceptable driving record in accordance with County policy
  • Acceptable pre-employment criminal background check.
  • CISM (or equivalent - Preferred after 1 year of employment)

PHYSICAL REQUIREMENTS/WORK ENVIRONMENT
  • Work is primarily sedentary in nature.
  • No special demands are required.

The County of Lancaster offers comprehensive benefits to our employees. Read more about our benefits here.
Lancaster County Government provides Equal Employment Opportunity for all persons regardless of race, religion, age, sex, national origin, genetic information or disability. The County also observes all applicable laws regarding Veterans status. The County reflects this action in all areas of employment and compensation practices and policies. Employment with the County is based upon the ability to perform the job as well as dependability and reliability once an individual is hired.