1

Deputy Ciso Jobs (NOW HIRING)

... CISO, Deputy CISO, VP of Security, or equivalent) • Experience as the named cybersecurity executive at a public company, or senior exposure to SEC cybersecurity disclosure, audit-committee ...

... Deputy CISO, or equivalent. Desired Qualifications: * Demonstrated ability to influence without direct authority and lead cross-functional initiatives in a complex, matrixed environment.

Showing results 41-60

Deputy Ciso information

See salary details

$31K

$99.3K

$187K

How much do deputy ciso jobs pay per year?

As of Sep 3, 2026, the average yearly pay for deputy ciso in the United States is $99,338.00, according to ZipRecruiter salary data. Most workers in this role earn between $66,500.00 and $128,500.00 per year, depending on experience, location, and employer.

What is a Deputy CISO?

Deputy CISOs, or Deputy Chief Information Security Officers, are senior leaders who assist the Chief Information Security Officer in managing and overseeing an organization's information security program. They help develop security strategies, manage risk, lead incident response efforts, and ensure compliance with relevant regulations. Often, Deputy CISOs act as second-in-command and may represent the CISO in meetings or during their absence. Their role is crucial in maintaining the organization's cybersecurity posture and supporting the security team's daily operations.

What are the primary challenges a Deputy CISO faces when balancing strategic leadership with operational cybersecurity duties?

A Deputy CISO often navigates the challenge of aligning day-to-day incident response and operational security tasks with broader organizational cybersecurity strategies. This role requires balancing immediate risk mitigation with long-term initiatives, such as developing policies, overseeing compliance, and fostering a security-conscious culture. Deputy CISOs frequently collaborate with IT, legal, and executive teams to ensure security objectives support business goals, making strong communication and prioritization skills essential. Adapting to evolving threats while maintaining alignment with overall business direction is a common and rewarding aspect of the position.

What are the key skills and qualifications needed to thrive as a Deputy CISO, and why are they important?

To thrive as a Deputy CISO, you need deep expertise in cybersecurity, risk management, and information security frameworks, typically supported by a bachelor's or master's degree in a related field and certifications like CISSP or CISM. Familiarity with tools such as SIEM platforms, vulnerability management systems, and compliance management software is crucial. Strong leadership, strategic thinking, and effective communication are essential soft skills for guiding teams and influencing stakeholders. These skills ensure robust protection of organizational assets and effective alignment of security strategies with business objectives.

What is the difference between Deputy Ciso vs Security Manager?

AspectDeputy CisoSecurity Manager
CertificationsCISSP, CISM, CISACISSP, Security+
Work EnvironmentCorporate, enterprise-level security teamsVarious, including corporate and smaller organizations
ResponsibilitiesSupports Ciso, strategic planning, policy developmentImplementing security measures, managing security teams
Search IntentRoles supporting Ciso, senior security rolesOperational security management, team leadership

The Deputy Ciso typically supports the Chief Information Security Officer with strategic planning and policy development, often requiring advanced certifications like CISSP or CISM. Security Managers focus on implementing security measures and managing security teams. While both roles are vital in organizational security, the Deputy Ciso is more strategic and senior, whereas the Security Manager handles day-to-day security operations.

More about Deputy Ciso jobs

What cities are hiring for Deputy Ciso jobs?

Cities with the most Deputy Ciso job openings:

What states have the most Deputy Ciso jobs?

States with the most job openings for Deputy Ciso jobs include:

Infographic showing various Deputy Ciso job openings in the United States as of August 2026, with employment types broken down into 100% Full Time. Highlights an 59% In-person, 8% Hybrid, and 33% Remote job distribution, with an average salary of $99,338 per year, or $47.8 per hour.

Deputy Chief Information Security Officer - Bank

Mercury

San Francisco, CA • On-site

Full-time

Re-posted yesterday


Job description

The role:
You will be the operating second to the CISO and own the bank-entity scope of Mercury's 2LOD Information Security program. You'll be the person who keeps the program examiner-ready by default: coherent policy architecture, evidenced controls, a credible gap-remediation track record, and a tested incident response program with documented exercise history.
This is not a research or strategy role. It is a build-and-defend role. You will sit across the table from OCC examiners, FFIEC IT audit teams, our Chief Risk Officer, and the board's risk committee, and you will be expected to answer for every line in our policies and every status in our control inventory.
*Mercury is a fintech company, not an FDIC-insured bank. Banking services provided through Choice Financial Group and Column N.A., Members FDIC
What you'll own:
  • Bank-entity 2LOD InfoSec program. Governance, policy, risk, and oversight scoped to the chartered bank.
  • Examiner posture. OCC, FFIEC, FDIC and FRB examiner inquiries; ownership of the examiner-ready narrative; coordination of the evidence.
  • FFIEC control remediation. Lead remediation of identified FFIEC IT control deficiencies to charter readiness ahead of the OCC pre-opening examination
  • Policy architecture. Carry the bank-scoped policy stack (Policy / Standard / Procedure), including ratification cycles, MRCC memos, and board approvals.
  • BC/DR. Partner with the Chief Risk Officer on bank continuity, resilience, and recovery, including tabletop exercises and full-scale drills.
  • Audit and assurance. Manage relationships with internal audit (3LOD) and external assessors (SOC 2, FFIEC CAT, regulator-led IT examinations).
  • Third-party risk. Ensure TPRM evidence holds up to bank-grade scrutiny for critical service providers and material outsourcing arrangements.
  • Team development. Coach and grow the GRC sub-team; run a recurring training cadence; build the bench depth a national bank requires.

What we need:
  • 8+ years in Information Security, with 3+ years inside a regulated bank, trust bank, or de novo bank charter effort. Mercury is a startup chartering a national bank - this experience is non-negotiable.
  • Deep FFIEC and OCC fluency. You have deep working knowledge of the FFIEC CAT, the FFIEC IT Examination Handbook, BSA/AML IT supervisory expectations, and the OCC Heightened Standards.
  • Direct examiner-facing experience. You have defended a control to an OCC, FDIC, or Federal Reserve examiner. You know what good evidence looks like before it gets challenged.
  • Policy and standards craft. You can draft a board-ratifiable policy and the supporting standards stack that operationalizes intent, not just satisfies a checklist.
  • Operating discipline. You run cadences, write status that survives executive review, and maintain currency of controls, evidence, and risk registers.
  • 2LOD instinct. You understand the three-lines-of-defense model and have served in the oversight role.

What we'd love:
  • Prior Deputy CISO or equivalent senior 2LOD role at a national bank, trust bank, or large credit union.
  • Charter or de novo bank experience - if you've stood one up before, that is a meaningful advantage here.
  • Strong technical baseline, you don't need to be an engineer, but you should be able to challenge an architecture review and read an incident timeline credibly.
  • CISSP, CISM, or CRISC

What success looks like:
  • At 30 days - You have developed working knowledge of Mercury's FFIEC IT control inventory and roadmap, every in-flight policy draft, and met one-on-one with the GRC team. You can speak to the top ten risks in the bank-entity program by name.
  • At 90 days - You are running the weekly bank charter status cadence, leading examiner-readiness reviews, and personally accountable for at least three priority program tracks. The CISO is briefing the board and the MRCC with material you authored.
  • At one year - The charter timeline is on track. The bank-entity Information Security program sustains supervisory-grade standards as a standing posture. You are the executive other functions consult to determine whether a security risk is material.

Why this role:
We are building a security program designed to protect Mercury and enable the business. Chartering a national bank does not change that philosophy. It does mean we need a Deputy who can hold the bar to OCC standards without losing the operating tempo that has defined Mercury since inception.
If you've been waiting for a chance to build the bank-side security program you wish you'd inherited, this is it.
Mercury values diversity & belonging and is proud to be an Equal Employment Opportunity employer. All individuals seeking employment at Mercury are considered without regard to race, color, religion, national origin, age, sex, marital status, ancestry, physical or mental disability, veteran status, gender identity, sexual orientation, or any other legally protected characteristic. We are committed to providing reasonable accommodations throughout the recruitment process for applicants with disabilities or special needs. If you need assistance, or an accommodation, please let your recruiter know once you are contacted about a role.
#LI-DNI
Total Rewards
The total rewards package at Mercury includes base salary, equity (stock options/RSUs), and benefits.
Our salary and equity ranges are highly competitive within the SaaS and fintech industry and are updated regularly using the most reliable compensation survey data for our industry. New hire offers are made based on a candidate's experience, expertise, geographic location, and internal pay equity relative to peers.
Our target new hire base salary ranges for this role are the following:
US employees in New York City, Los Angeles, Seattle, or the San Francisco Bay Area:
$269,700-$353,950 USD
US employees outside of New York City, Los Angeles, Seattle, or the San Francisco Bay Area:
$242,700-$318,550 USD