5,365 Chief Information Security Officer jobs in the United States
Chief Information Security Officer
Posted 12 days ago
Job Viewed
Job Description
The Regional Chief Information Security Officer (Regional CISO) is responsible for the security (availability, integrity and confidentiality) of all systems and data in use on his/her reporting scope at Saint-Gobain (Region and/or Businesses), and accountable for the one managed by another team (e.g. GDI, web agency, etc.). The Regional CISO works with appropriate levels of management, both regionally and at Group level, to ensure the implementation of Saint-Gobain cybersecurity standards and the monitoring of cybersecurity risks.
**Essential Functions:**
+ Act as the security of Infrastructure for IT solutions used by all Businesses of the Group in the Region (both Regional and global Businesses)
+ The Regional CISO is liable for evaluating risks, defining strategy and setting up an appropriate governance model on his/her Regional and Business perimeter, with the support of Central Cybersecurity team.
+ Design and implement a cybersecurity roadmap, based on the Group cybersecurity roadmap, Regional and Business specific cybersecurity risks and legal/regulatory local requirements, validation with Region / Business the roadmap, and appropriate reporting.
+ Manage security governance on the Regional and Business perimeter, by defining and setting up the necessary follow-up meetings and communication channels with all Business and IT stakeholders.
+ The Regional CISO oversees the application of security rules and standards on his/her regional and Business perimeter:
+ Ensure that projects are secured-by-design on his/her regional and Business perimeter, according to the Saint-Gobain processes (PSAT, Third parties management security, SIP, risk analysis.)
+ Ensure that all third parties contributing to a project or activity implement the appropriate set of security measures, of security tools, and provide the associated controls
+ The Regional CISO ensures that all operational security actions are carried out on his/her regional and Business perimeter.
+ Coordinate and supervise the management of security incidents and contribute to the resolution of major incidents on the perimeter in conjunction with the relevant teams, in collaboration with CyberSOC teams.
+ Contribute to the development of the Business Continuity Plan (BCP) by providing assistance to the Business in the identification of the business impacts of application unavailability and ensuring that the cyberattack scenario is included in the BCP.
+ Design and implement an awareness strategy (messages, phishing campaigns, etc.) toward all stakeholders of the perimeter, with the support of Central team
+ Follow up on acquisitions and divestitures projects on the perimeter and provide associated KPIs to the central M&A team operating for the Group CISO.
+ Bachelor's Degree in information systems, Business Analytics, or related field, required.
+ Chief Information Security Officer should possess a blend of technical acumen, strategic focus, and strong leadership.
+ 10+ years of experience IT leadership experience with significant responsibilities in IT security
+ 5+ years of experience in a senior level leadership role
+ Experience implementing controls and mitigating risks related to GDPR, PCI, and other information security and data privacy standards
+ Demonstrated experience representing an organization's information security program in presentations and discussions with customers, partners and other external parties
+ Well-versed in the rapidly evolving threat landscape with a strategic mindset to mitigate threats
+ Outstanding communication skills with an ability to build strong narratives to highlight the importance of security to employees internally and customers/shareholders externally, including both technical and non-technical audiences
+ Experience at a leadership level building and scaling a high-functioning security organization
Through the responsible development of innovative and sustainable building products, CertainTeed, headquartered in Malvern, Pennsylvania, has helped shape the building products industry for more than 110 years. Founded in 1904 as General Roofing Manufacturing Company, the firm's slogan "Quality Made Certain, Satisfaction Guaranteed," inspired the name CertainTeed. Today, CertainTeed is a leading North American brand of exterior and interior building products, including roofing, siding, trim, insulation, drywall and ceilings.
-
A subsidiary of Saint-Gobain, one of the world's largest and oldest building products companies, CertainTeed has more than 6,300 employees and more than 60 manufacturing facilities throughout the United States and Canada. provides equal employment opportunities (EEO) to all employees and applicants for employment without regard to race, color, religion, sex, gender, sexual orientation, gender identity or expression, national origin, age, disability, genetic information, marital status, amnesty, or status as a covered veteran in accordance with applicable federal, state and local laws. Saint-Gobain is an equal opportunity employer of individuals with disabilities and supports the hiring of veterans.
Applicants for roles based in Washington state or remote roles that would be worked from Washington state are encouraged to direct any concerns regarding the state's Pay Transparency laws to the SGNA HR Compliance team at .
Saint-Gobain is committed to helping you and your family be well in all aspects of your life. Be Well. Be You brings together inclusive programs and meaningful resources to support all aspects of your physical, emotional, financial, and social well-being. Employees have the flexibility to choose the benefits that best fit their individual needs.
+ Health and Well-being - Supporting your wellbeing, to thrive in life and work.
+ Medical, Prescription Drug, Vision, and Dental Insurance
+ Healthcare Saving Account and Flexible Spending Account options
+ LiveWell Wellness Program
+ Employee Assistance Program (EAP)
+ Paid Time Off and Paid Parental Leave
+ Retirement and Protection - Helping to make the future life you want a reality.
+ 401(k) with Company Match, Retirement Accumulation Plan (RAP) Cash Balance Pension Plan
+ Company-provided Life Insurance, AD&D, Short-Term Disability
+ Voluntary employee and dependent life insurance, Long-Term Disability, Critical Illness and
+ Accident Insurance
+ Additional Benefits - Helping shape the experience and impact you want
+ Commuter Benefits
+ Group Legal
+ Identity Theft Protection
+ Auto and Home Insurance
+ Pet Insurance and Discounts
+ Back-up Child and Elder Care
+ PerkSpot Employee Discount Program
+ Volunteer Day
Chief Information Security Officer
Posted today
Job Viewed
Job Description
Job Description
Amalgamated Bank seeks a dedicated Chief Information Security Officer to be responsible for designing and implementing the Bank’s Information Security program while protecting the business from cyber security threats. This is a hybrid role reporting to our NYC headquarters.
By joining our team, you’ll be joining a Bank that believes that maintaining a diverse and inclusive workplace where everyone feels valued and respected is essential for us to grow as a company. We are dedicated to building a more equitable world in our everyday practices by embracing the values of our employees and customers.
Essential Job Functions:
- Develop and maintain an Enterprise Information Security Program
- Design a critical response process for Cyber Security incidents
- Identify, report and control Cyber Security incidents
- Manage and train Information Security staff and develop and deliver Information Security training to the Bank’s employees
- Continuously monitor threats to the Bank’s operating environment
- Approve and administer identity access policies
- Maintain a current understanding of the IT and Cyber Security threat landscape for the industry
- Ensure Bank compliance with relevant Information Security laws and applicable regulations
- Lead, and assess the results of periodic security tests, including internal and external penetration testing and phishing
- Schedule table-top exercises for Crisis Team and senior management and report findings to management, including implementation of recommendations
- Review and approve Information Security policies, procedures and controls
- Ensure that they are kept current and are communicated to staff/consultants
- Ensure staff/vendor compliance with the Bank’s security policies and procedures
- Manage a team of employees, contractors and vendors involved in Information Security
- Brief the Executive Team on status and risks, overall strategy and necessary budget
- Communicate best practices and risks to the Bank
- Perform a risk assessment of the Bank’s vulnerabilities in the Cybersecurity landscape and develop the Bank’s risk appetite for Information Security
- Develop Key Risk Indicators (KRIs) and dashboard metrics reporting to both the Management Team and the Board of Directors
- Establish strong working relationships with the Heads of IT and business lines
- Develop and present quarterly reports to the Board of Directors.
Knowledge, Skills and Experience Requirements:
- Master’s degree or equivalent experience
- Minimum of ten (10) years of experience, at least five (5) years focused on managing information security in a complex, matrixed environment
- Extensive experience in regulated industries, especially financial services; banking experience is preferred
- Proven ability to create and maintain enterprise-level information security programs
- Motivated individual with strong analytical, problem solving and root cause analysis skills
- Ability to work on multiple, time-critical projects simultaneously
- Knowledge of Data Privacy Laws
- Working knowledge of information security engineering concepts and principles
- Familiarity with DFS 500 and similar regulations
- Experience working with external regulators, including NY DFS and FDIC
- Excellent verbal and written communications, including presentation of complex data in easily, understood ways
- Ability to confidently interact at multiple levels in the organization and lead cross-departmental team projects
- Experience presenting to senior levels, including Board of Directors
- CISSP, CISA or CISM designations preferred
Our job titles may span more than one career level. The starting base salary for this role is between $240,000.00 – $260,000.00. The actual base pay is dependent upon many factors, such as: training, transferrable skills, work experience, business needs and market demands. The base pay range is subject to change and may be modified in the future.
Amalgamated Bank is an Equal Opportunity and Affirmative Action Employer, Minorities / Females / Individuals with Disability / Veterans. AmeriCorps, Peace Corps and other national service alumni are encouraged to apply. View our Pay Transparency Statement. Submission of a resume or any information regarding your qualifications does not constitute a promise or offer of employment. At Amalgamated Bank, we consider an applicant to be someone who has interviewed at least once, in person, with the hiring manager. Amalgamated Bank does not sponsor applicants for work visas.
Hybrid Work Model
Effective February 18, 2025, employees in office-based positions will be working a Hybrid work schedule consisting of three days or more, on-site per week, Monday - Thursday, although the specific days may vary by site or organization, with Friday designated as a remote-working day, unless business critical tasks require an on-site presence. This Hybrid work model does not apply to, and daily in-person attendance is required for, the contact center, branch service roles, and general services where the work to be performed is located at a Company site; positions covered by a collective-bargaining agreement (unless the agreement provides for hybrid work); or any other position for which the Company has determined the job requirements cannot be reasonably met working remotely. Please note, this Hybrid work model guidance does not apply to roles that have been designated as “remote”.
Search Firm Representatives- Please Read Carefully
Amalgamated Bank does not accept unsolicited assistance from search firms for employment opportunities. All CVs / resumes submitted by search firms to any employee at our company without a valid written search agreement in place for the position will be deemed the sole property of our company. No fee will be paid in the event a candidate is hired by our company as a result of an agency referral where no pre-existing agreement is in place. Where agency agreements are in place, introductions are position specific. Please, no phone calls or emails.
Chief Information Security Officer (Remote)
Posted 4 days ago
Job Viewed
Job Description
At Cengage Group, our employees have a direct impact in helping students around the world discover the power and joy of learning. We are bonded by our shared purpose - driving innovation that helps millions of learners improve their lives and achieve their dreams through education.
**Our culture values inclusion, engagement, and discovery**
Our business is driven by our strong culture, and we know that creating an inclusive workplace is absolutely essential to the success of our company and our learners, as well as our individual well-being. We recognize the value of diverse perspectives in everything we do, and strive to ensure employees of all levels and backgrounds feel empowered to voice their ideas and bring their authentic selves to work. We achieve these priorities through programs, benefits, and initiatives that are integrated into the fabric of how we work every day. To learn more, please see .
The Chief Information Security Officer (CISO) is a senior technology executive accountable for protecting Cengage Group's digital assets, data confidentiality, and technology infrastructure from cyber threats while ensuring compliance with regulatory requirements. This leader defines and delivers the enterprise information security strategy, building a robust and resilient security posture that enables business innovation while mitigating risk.
The CISO combines deep technical expertise with executive leadership, shaping the company's security vision while driving excellence in security operations, risk management, and governance. This role balances strategic vision, business partnership, and organizational influence to ensure security becomes an enabler of digital transformation rather than a barrier to progress. As a critical member of the IT leadership team, reporting to the CIO, this role serves as the primary authority on cybersecurity matters and partners closely with business leaders, legal, compliance, and the board to align security investments with enterprise priorities and risk appetite.
**Key Responsibilities**
**Enterprise Security Strategy & Risk Leadership**
+ Define and deliver the enterprise information security strategy, aligned with business priorities, digital transformation initiatives, and the company's risk tolerance in a PE-backed environment preparing for liquidity events.
+ Lead the development and implementation of comprehensive security programs encompassing cyber defense, data protection, identity and access management, security operations, and threat intelligence.
+ Conduct enterprise-wide risk assessments, identify vulnerabilities across the technology estate, and prioritize remediation efforts to reduce risk exposure while enabling business agility.
+ Serve as the primary cybersecurity advisor to the CIO, executive leadership team, and board of directors, translating technical risks into business impact and providing strategic recommendations on security investments.
+ Drive security architecture decisions that balance protection with performance, cost efficiency, and user experience across cloud, on-premises, and hybrid environments.
**Cyber Defense & Security Operations**
+ Oversee security incident detection, response, and recovery programs, ensuring swift identification and mitigation of potential breaches with minimal business disruption.
+ Manage the security architecture, tools, and technologies deployed across the organization's IT infrastructure, including firewalls, intrusion detection/prevention systems, SIEMs, endpoint protection, and encryption protocols.
+ Lead security operations center (SOC), threat hunting capabilities, and vulnerability management programs that proactively identify and remediate security weaknesses.
+ Develop and maintain incident response playbooks, disaster recovery plans, and business continuity protocols that ensure organizational resilience against emerging threats.
+ Monitor security metrics, threat landscape trends, and attack patterns to continuously evolve defensive capabilities and inform executive decision-making on security posture.
**Governance, Compliance & Data Protection**
+ Ensure compliance with industry standards, regulatory requirements, and data protection laws including GDPR, CCPA, FERPA, SOC 2, ISO 27001, and other relevant frameworks for the education technology sector.
+ Coordinate with legal, compliance, privacy, and regulatory teams to maintain certifications, manage audits, and respond to regulatory inquiries with appropriate documentation and evidence.
+ Develop and enforce security policies, procedures, standards, and protocols that align with business goals, regulatory obligations, and industry guidelines.
+ Be responsible for data classification, data loss prevention (DLP), and privacy programs that protect sensitive student, employee, and company information across all systems and geographies.
+ Manage security audits, compliance assessments, and third-party risk evaluations, ensuring vendors and partners meet security requirements and contractual obligations.
**Business Partnership & Security Enablement**
+ Serve as a trusted partner to business executives, ensuring security investments and controls enable business innovation while appropriately managing risk.
+ Collaborate with product, engineering, and DevOps teams to integrate security measures into software development lifecycles through DevSecOps practices and secure-by-design principles.
+ Partner with IT leadership on technology modernization initiatives including cloud migration, digital transformation, and AI/ML adoption, ensuring security is embedded from inception.
+ Communicate security value and risk posture at the executive and board levels, linking security investments to business outcomes including revenue protection, regulatory compliance, and competitive differentiation.
+ Champion security awareness and cultural transformation across the enterprise, promoting shared responsibility for security rather than viewing it as solely an IT function.
**Leadership & Talent Development**
+ Lead and inspire a global security team including security architects, security engineers, SOC analysts, governance/risk/compliance specialists, and security operations professionals.
+ Establish career pathways, competencies, and training programs that elevate security capability and develop next-generation cybersecurity leaders.
+ Champion a culture of accountability, collaboration, continuous learning, and innovation within the security organization.
+ Act as an executive sponsor for security awareness training programs for employees at all levels, promoting a culture of cybersecurity across the organization.
+ Build strategic relationships with peer CISOs, industry groups, law enforcement, and threat intelligence communities to stay ahead of emerging threats and share best practices.
**Qualifications**
+ 15+ years of progressive leadership in information security, cybersecurity, or risk management, with 5+ years in senior director, VP, or CISO roles.
+ Proven track record developing and implementing enterprise security programs in global, complex organizations, preferably in education technology, SaaS, or regulated industries.
+ Extensive knowledge of information security principles, cybersecurity frameworks (NIST, ISO 27001, CIS Controls), and risk management practices with demonstrable success reducing organizational risk.
+ Deep expertise in security technologies including firewalls, intrusion detection/prevention systems, SIEMs, identity and access management (IAM), cloud security platforms, and encryption protocols.
+ Solid understanding of data privacy regulations (GDPR, CCPA, FERPA) and compliance requirements with experience managing audits and regulatory relationships.
+ Experience securing cloud infrastructure (AWS, Azure, GCP) and implementing cloud-native security architectures in multi-cloud and hybrid environments.
+ Demonstrated ability to lead incident response programs, manage security breaches, and coordinate with legal, communications, and executive teams during crisis situations.
+ Exceptional leadership skills with a history of developing high-performing, distributed security teams across multiple disciplines and geographies.
+ Strong business sense and communication skills, with the ability to influence C-suite leaders and board members by translating technical security concepts into business risk and value propositions.
+ Experience working in PE-backed technology companies preferred, with understanding of security requirements for M&A due diligence, integration, and preparing for liquidity events.
+ Relevant certifications such as Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified Information Systems Auditor (CISA), or equivalent strongly preferred.
+ Familiarity with DevSecOps practices, secure software development, ethical hacking, and penetration testing techniques valued.
+ Understanding of artificial intelligence and machine learning applications in security, including emerging threats and defensive capabilities in AI-powered systems.
Cengage Group is committed to working with broad talent pools to attract and hire strong and most qualified individuals. Our job applicants are considered regardless of race, national origin, religion, sex, sexual orientation, genetic information, disability, age, veteran status, and any other classification protected by applicable federal, state, provincial or local laws.
Cengage is also committed to providing reasonable accommodations for qualified individuals with disabilities including during our job application process. If you are an applicant with a disability and require reasonable accommodation in our job application process, please contact us at or at .
**About Cengage** **Group**
Cengage Group, a global education technology company serving millions of learners, provides affordable, quality digital products and services that equip students with the skills and competencies needed to be job ready. For more than 100 years, we have enabled the power and joy of learning with trusted, engaging content, and now, integrated digital platforms. We serve the higher education, workforce skills, secondary education, English language teaching and research markets worldwide. Through our scalable technology, including MindTap and Cengage Unlimited, we support all learners who seek to improve their lives and achieve their dreams through education.
**Compensation**
At Cengage Group, we take great pride in our commitment to providing a comprehensive and rewarding Total Rewards package designed to support and empower our employees. Click here ( to learn more about our _Total Rewards Philosophy_ .
The full base pay range has been provided for this position. Individual base pay will vary based on work schedule, qualifications, experience, internal equity, and geographic location. Sales roles often incorporate a significant incentive compensation program beyond this base pay range.
$250,200.00 - $308,000.00 USD
**Cengage Group** , a global education technology company serving millions of learners, provides affordable, quality digital products and services that equip students with the skills and competencies needed to be job ready. For more than 100 years, we have enabled the power and joy of learning with trusted, engaging content, and now, integrated digital platforms.
We serve the higher education, workforce skills, secondary education, English language teaching and research markets worldwide. Through our scalable technology, including MindTap and Cengage Unlimited, we support all learners who seek to improve their lives and achieve their dreams through education.
**_Warning: Be aware, there has been an increase of targeted recruitment_** **_scams perpetrated by bad actors falsely providing job offers on behalf Cengage Group to candidates as a means of obtaining personal information. Note that Cengage will always interview candidates via live in-person meetings, phone calls and video calls before an offer would be extended. Also, be sure to check that communication is coming from an @cengage.com email address._**
Chief Information Security Officer (Remote)
Posted today
Job Viewed
Job Description
At Cengage Group, our employees have a direct impact in helping students around the world discover the power and joy of learning. We are bonded by our shared purpose - driving innovation that helps millions of learners improve their lives and achieve their dreams through education.
**Our culture values inclusion, engagement, and discovery**
Our business is driven by our strong culture, and we know that creating an inclusive workplace is absolutely essential to the success of our company and our learners, as well as our individual well-being. We recognize the value of diverse perspectives in everything we do, and strive to ensure employees of all levels and backgrounds feel empowered to voice their ideas and bring their authentic selves to work. We achieve these priorities through programs, benefits, and initiatives that are integrated into the fabric of how we work every day. To learn more, please see .
The Chief Information Security Officer (CISO) is a senior technology executive accountable for protecting Cengage Group's digital assets, data confidentiality, and technology infrastructure from cyber threats while ensuring compliance with regulatory requirements. This leader defines and delivers the enterprise information security strategy, building a robust and resilient security posture that enables business innovation while mitigating risk.
The CISO combines deep technical expertise with executive leadership, shaping the company's security vision while driving excellence in security operations, risk management, and governance. This role balances strategic vision, business partnership, and organizational influence to ensure security becomes an enabler of digital transformation rather than a barrier to progress. As a critical member of the IT leadership team, reporting to the CIO, this role serves as the primary authority on cybersecurity matters and partners closely with business leaders, legal, compliance, and the board to align security investments with enterprise priorities and risk appetite.
**Key Responsibilities**
**Enterprise Security Strategy & Risk Leadership**
+ Define and deliver the enterprise information security strategy, aligned with business priorities, digital transformation initiatives, and the company's risk tolerance in a PE-backed environment preparing for liquidity events.
+ Lead the development and implementation of comprehensive security programs encompassing cyber defense, data protection, identity and access management, security operations, and threat intelligence.
+ Conduct enterprise-wide risk assessments, identify vulnerabilities across the technology estate, and prioritize remediation efforts to reduce risk exposure while enabling business agility.
+ Serve as the primary cybersecurity advisor to the CIO, executive leadership team, and board of directors, translating technical risks into business impact and providing strategic recommendations on security investments.
+ Drive security architecture decisions that balance protection with performance, cost efficiency, and user experience across cloud, on-premises, and hybrid environments.
**Cyber Defense & Security Operations**
+ Oversee security incident detection, response, and recovery programs, ensuring swift identification and mitigation of potential breaches with minimal business disruption.
+ Manage the security architecture, tools, and technologies deployed across the organization's IT infrastructure, including firewalls, intrusion detection/prevention systems, SIEMs, endpoint protection, and encryption protocols.
+ Lead security operations center (SOC), threat hunting capabilities, and vulnerability management programs that proactively identify and remediate security weaknesses.
+ Develop and maintain incident response playbooks, disaster recovery plans, and business continuity protocols that ensure organizational resilience against emerging threats.
+ Monitor security metrics, threat landscape trends, and attack patterns to continuously evolve defensive capabilities and inform executive decision-making on security posture.
**Governance, Compliance & Data Protection**
+ Ensure compliance with industry standards, regulatory requirements, and data protection laws including GDPR, CCPA, FERPA, SOC 2, ISO 27001, and other relevant frameworks for the education technology sector.
+ Coordinate with legal, compliance, privacy, and regulatory teams to maintain certifications, manage audits, and respond to regulatory inquiries with appropriate documentation and evidence.
+ Develop and enforce security policies, procedures, standards, and protocols that align with business goals, regulatory obligations, and industry guidelines.
+ Be responsible for data classification, data loss prevention (DLP), and privacy programs that protect sensitive student, employee, and company information across all systems and geographies.
+ Manage security audits, compliance assessments, and third-party risk evaluations, ensuring vendors and partners meet security requirements and contractual obligations.
**Business Partnership & Security Enablement**
+ Serve as a trusted partner to business executives, ensuring security investments and controls enable business innovation while appropriately managing risk.
+ Collaborate with product, engineering, and DevOps teams to integrate security measures into software development lifecycles through DevSecOps practices and secure-by-design principles.
+ Partner with IT leadership on technology modernization initiatives including cloud migration, digital transformation, and AI/ML adoption, ensuring security is embedded from inception.
+ Communicate security value and risk posture at the executive and board levels, linking security investments to business outcomes including revenue protection, regulatory compliance, and competitive differentiation.
+ Champion security awareness and cultural transformation across the enterprise, promoting shared responsibility for security rather than viewing it as solely an IT function.
**Leadership & Talent Development**
+ Lead and inspire a global security team including security architects, security engineers, SOC analysts, governance/risk/compliance specialists, and security operations professionals.
+ Establish career pathways, competencies, and training programs that elevate security capability and develop next-generation cybersecurity leaders.
+ Champion a culture of accountability, collaboration, continuous learning, and innovation within the security organization.
+ Act as an executive sponsor for security awareness training programs for employees at all levels, promoting a culture of cybersecurity across the organization.
+ Build strategic relationships with peer CISOs, industry groups, law enforcement, and threat intelligence communities to stay ahead of emerging threats and share best practices.
**Qualifications**
+ 15+ years of progressive leadership in information security, cybersecurity, or risk management, with 5+ years in senior director, VP, or CISO roles.
+ Proven track record developing and implementing enterprise security programs in global, complex organizations, preferably in education technology, SaaS, or regulated industries.
+ Extensive knowledge of information security principles, cybersecurity frameworks (NIST, ISO 27001, CIS Controls), and risk management practices with demonstrable success reducing organizational risk.
+ Deep expertise in security technologies including firewalls, intrusion detection/prevention systems, SIEMs, identity and access management (IAM), cloud security platforms, and encryption protocols.
+ Solid understanding of data privacy regulations (GDPR, CCPA, FERPA) and compliance requirements with experience managing audits and regulatory relationships.
+ Experience securing cloud infrastructure (AWS, Azure, GCP) and implementing cloud-native security architectures in multi-cloud and hybrid environments.
+ Demonstrated ability to lead incident response programs, manage security breaches, and coordinate with legal, communications, and executive teams during crisis situations.
+ Exceptional leadership skills with a history of developing high-performing, distributed security teams across multiple disciplines and geographies.
+ Strong business sense and communication skills, with the ability to influence C-suite leaders and board members by translating technical security concepts into business risk and value propositions.
+ Experience working in PE-backed technology companies preferred, with understanding of security requirements for M&A due diligence, integration, and preparing for liquidity events.
+ Relevant certifications such as Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified Information Systems Auditor (CISA), or equivalent strongly preferred.
+ Familiarity with DevSecOps practices, secure software development, ethical hacking, and penetration testing techniques valued.
+ Understanding of artificial intelligence and machine learning applications in security, including emerging threats and defensive capabilities in AI-powered systems.
Cengage Group is committed to working with broad talent pools to attract and hire strong and most qualified individuals. Our job applicants are considered regardless of race, national origin, religion, sex, sexual orientation, genetic information, disability, age, veteran status, and any other classification protected by applicable federal, state, provincial or local laws.
Cengage is also committed to providing reasonable accommodations for qualified individuals with disabilities including during our job application process. If you are an applicant with a disability and require reasonable accommodation in our job application process, please contact us at or at .
**About Cengage** **Group**
Cengage Group, a global education technology company serving millions of learners, provides affordable, quality digital products and services that equip students with the skills and competencies needed to be job ready. For more than 100 years, we have enabled the power and joy of learning with trusted, engaging content, and now, integrated digital platforms. We serve the higher education, workforce skills, secondary education, English language teaching and research markets worldwide. Through our scalable technology, including MindTap and Cengage Unlimited, we support all learners who seek to improve their lives and achieve their dreams through education.
**Compensation**
At Cengage Group, we take great pride in our commitment to providing a comprehensive and rewarding Total Rewards package designed to support and empower our employees. Click here ( to learn more about our _Total Rewards Philosophy_ .
The full base pay range has been provided for this position. Individual base pay will vary based on work schedule, qualifications, experience, internal equity, and geographic location. Sales roles often incorporate a significant incentive compensation program beyond this base pay range.
$250,200.00 - $308,000.00 USD
**Cengage Group** , a global education technology company serving millions of learners, provides affordable, quality digital products and services that equip students with the skills and competencies needed to be job ready. For more than 100 years, we have enabled the power and joy of learning with trusted, engaging content, and now, integrated digital platforms.
We serve the higher education, workforce skills, secondary education, English language teaching and research markets worldwide. Through our scalable technology, including MindTap and Cengage Unlimited, we support all learners who seek to improve their lives and achieve their dreams through education.
**_Warning: Be aware, there has been an increase of targeted recruitment_** **_scams perpetrated by bad actors falsely providing job offers on behalf Cengage Group to candidates as a means of obtaining personal information. Note that Cengage will always interview candidates via live in-person meetings, phone calls and video calls before an offer would be extended. Also, be sure to check that communication is coming from an @cengage.com email address._**
Chief Information Security Officer (Remote)
Posted today
Job Viewed
Job Description
At Cengage Group, our employees have a direct impact in helping students around the world discover the power and joy of learning. We are bonded by our shared purpose - driving innovation that helps millions of learners improve their lives and achieve their dreams through education.
**Our culture values inclusion, engagement, and discovery**
Our business is driven by our strong culture, and we know that creating an inclusive workplace is absolutely essential to the success of our company and our learners, as well as our individual well-being. We recognize the value of diverse perspectives in everything we do, and strive to ensure employees of all levels and backgrounds feel empowered to voice their ideas and bring their authentic selves to work. We achieve these priorities through programs, benefits, and initiatives that are integrated into the fabric of how we work every day. To learn more, please see .
The Chief Information Security Officer (CISO) is a senior technology executive accountable for protecting Cengage Group's digital assets, data confidentiality, and technology infrastructure from cyber threats while ensuring compliance with regulatory requirements. This leader defines and delivers the enterprise information security strategy, building a robust and resilient security posture that enables business innovation while mitigating risk.
The CISO combines deep technical expertise with executive leadership, shaping the company's security vision while driving excellence in security operations, risk management, and governance. This role balances strategic vision, business partnership, and organizational influence to ensure security becomes an enabler of digital transformation rather than a barrier to progress. As a critical member of the IT leadership team, reporting to the CIO, this role serves as the primary authority on cybersecurity matters and partners closely with business leaders, legal, compliance, and the board to align security investments with enterprise priorities and risk appetite.
**Key Responsibilities**
**Enterprise Security Strategy & Risk Leadership**
+ Define and deliver the enterprise information security strategy, aligned with business priorities, digital transformation initiatives, and the company's risk tolerance in a PE-backed environment preparing for liquidity events.
+ Lead the development and implementation of comprehensive security programs encompassing cyber defense, data protection, identity and access management, security operations, and threat intelligence.
+ Conduct enterprise-wide risk assessments, identify vulnerabilities across the technology estate, and prioritize remediation efforts to reduce risk exposure while enabling business agility.
+ Serve as the primary cybersecurity advisor to the CIO, executive leadership team, and board of directors, translating technical risks into business impact and providing strategic recommendations on security investments.
+ Drive security architecture decisions that balance protection with performance, cost efficiency, and user experience across cloud, on-premises, and hybrid environments.
**Cyber Defense & Security Operations**
+ Oversee security incident detection, response, and recovery programs, ensuring swift identification and mitigation of potential breaches with minimal business disruption.
+ Manage the security architecture, tools, and technologies deployed across the organization's IT infrastructure, including firewalls, intrusion detection/prevention systems, SIEMs, endpoint protection, and encryption protocols.
+ Lead security operations center (SOC), threat hunting capabilities, and vulnerability management programs that proactively identify and remediate security weaknesses.
+ Develop and maintain incident response playbooks, disaster recovery plans, and business continuity protocols that ensure organizational resilience against emerging threats.
+ Monitor security metrics, threat landscape trends, and attack patterns to continuously evolve defensive capabilities and inform executive decision-making on security posture.
**Governance, Compliance & Data Protection**
+ Ensure compliance with industry standards, regulatory requirements, and data protection laws including GDPR, CCPA, FERPA, SOC 2, ISO 27001, and other relevant frameworks for the education technology sector.
+ Coordinate with legal, compliance, privacy, and regulatory teams to maintain certifications, manage audits, and respond to regulatory inquiries with appropriate documentation and evidence.
+ Develop and enforce security policies, procedures, standards, and protocols that align with business goals, regulatory obligations, and industry guidelines.
+ Be responsible for data classification, data loss prevention (DLP), and privacy programs that protect sensitive student, employee, and company information across all systems and geographies.
+ Manage security audits, compliance assessments, and third-party risk evaluations, ensuring vendors and partners meet security requirements and contractual obligations.
**Business Partnership & Security Enablement**
+ Serve as a trusted partner to business executives, ensuring security investments and controls enable business innovation while appropriately managing risk.
+ Collaborate with product, engineering, and DevOps teams to integrate security measures into software development lifecycles through DevSecOps practices and secure-by-design principles.
+ Partner with IT leadership on technology modernization initiatives including cloud migration, digital transformation, and AI/ML adoption, ensuring security is embedded from inception.
+ Communicate security value and risk posture at the executive and board levels, linking security investments to business outcomes including revenue protection, regulatory compliance, and competitive differentiation.
+ Champion security awareness and cultural transformation across the enterprise, promoting shared responsibility for security rather than viewing it as solely an IT function.
**Leadership & Talent Development**
+ Lead and inspire a global security team including security architects, security engineers, SOC analysts, governance/risk/compliance specialists, and security operations professionals.
+ Establish career pathways, competencies, and training programs that elevate security capability and develop next-generation cybersecurity leaders.
+ Champion a culture of accountability, collaboration, continuous learning, and innovation within the security organization.
+ Act as an executive sponsor for security awareness training programs for employees at all levels, promoting a culture of cybersecurity across the organization.
+ Build strategic relationships with peer CISOs, industry groups, law enforcement, and threat intelligence communities to stay ahead of emerging threats and share best practices.
**Qualifications**
+ 15+ years of progressive leadership in information security, cybersecurity, or risk management, with 5+ years in senior director, VP, or CISO roles.
+ Proven track record developing and implementing enterprise security programs in global, complex organizations, preferably in education technology, SaaS, or regulated industries.
+ Extensive knowledge of information security principles, cybersecurity frameworks (NIST, ISO 27001, CIS Controls), and risk management practices with demonstrable success reducing organizational risk.
+ Deep expertise in security technologies including firewalls, intrusion detection/prevention systems, SIEMs, identity and access management (IAM), cloud security platforms, and encryption protocols.
+ Solid understanding of data privacy regulations (GDPR, CCPA, FERPA) and compliance requirements with experience managing audits and regulatory relationships.
+ Experience securing cloud infrastructure (AWS, Azure, GCP) and implementing cloud-native security architectures in multi-cloud and hybrid environments.
+ Demonstrated ability to lead incident response programs, manage security breaches, and coordinate with legal, communications, and executive teams during crisis situations.
+ Exceptional leadership skills with a history of developing high-performing, distributed security teams across multiple disciplines and geographies.
+ Strong business sense and communication skills, with the ability to influence C-suite leaders and board members by translating technical security concepts into business risk and value propositions.
+ Experience working in PE-backed technology companies preferred, with understanding of security requirements for M&A due diligence, integration, and preparing for liquidity events.
+ Relevant certifications such as Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified Information Systems Auditor (CISA), or equivalent strongly preferred.
+ Familiarity with DevSecOps practices, secure software development, ethical hacking, and penetration testing techniques valued.
+ Understanding of artificial intelligence and machine learning applications in security, including emerging threats and defensive capabilities in AI-powered systems.
Cengage Group is committed to working with broad talent pools to attract and hire strong and most qualified individuals. Our job applicants are considered regardless of race, national origin, religion, sex, sexual orientation, genetic information, disability, age, veteran status, and any other classification protected by applicable federal, state, provincial or local laws.
Cengage is also committed to providing reasonable accommodations for qualified individuals with disabilities including during our job application process. If you are an applicant with a disability and require reasonable accommodation in our job application process, please contact us at or at .
**About Cengage** **Group**
Cengage Group, a global education technology company serving millions of learners, provides affordable, quality digital products and services that equip students with the skills and competencies needed to be job ready. For more than 100 years, we have enabled the power and joy of learning with trusted, engaging content, and now, integrated digital platforms. We serve the higher education, workforce skills, secondary education, English language teaching and research markets worldwide. Through our scalable technology, including MindTap and Cengage Unlimited, we support all learners who seek to improve their lives and achieve their dreams through education.
**Compensation**
At Cengage Group, we take great pride in our commitment to providing a comprehensive and rewarding Total Rewards package designed to support and empower our employees. Click here ( to learn more about our _Total Rewards Philosophy_ .
The full base pay range has been provided for this position. Individual base pay will vary based on work schedule, qualifications, experience, internal equity, and geographic location. Sales roles often incorporate a significant incentive compensation program beyond this base pay range.
$250,200.00 - $308,000.00 USD
**Cengage Group** , a global education technology company serving millions of learners, provides affordable, quality digital products and services that equip students with the skills and competencies needed to be job ready. For more than 100 years, we have enabled the power and joy of learning with trusted, engaging content, and now, integrated digital platforms.
We serve the higher education, workforce skills, secondary education, English language teaching and research markets worldwide. Through our scalable technology, including MindTap and Cengage Unlimited, we support all learners who seek to improve their lives and achieve their dreams through education.
**_Warning: Be aware, there has been an increase of targeted recruitment_** **_scams perpetrated by bad actors falsely providing job offers on behalf Cengage Group to candidates as a means of obtaining personal information. Note that Cengage will always interview candidates via live in-person meetings, phone calls and video calls before an offer would be extended. Also, be sure to check that communication is coming from an @cengage.com email address._**
Chief Information Security Officer (Remote)
Posted today
Job Viewed
Job Description
At Cengage Group, our employees have a direct impact in helping students around the world discover the power and joy of learning. We are bonded by our shared purpose - driving innovation that helps millions of learners improve their lives and achieve their dreams through education.
**Our culture values inclusion, engagement, and discovery**
Our business is driven by our strong culture, and we know that creating an inclusive workplace is absolutely essential to the success of our company and our learners, as well as our individual well-being. We recognize the value of diverse perspectives in everything we do, and strive to ensure employees of all levels and backgrounds feel empowered to voice their ideas and bring their authentic selves to work. We achieve these priorities through programs, benefits, and initiatives that are integrated into the fabric of how we work every day. To learn more, please see .
The Chief Information Security Officer (CISO) is a senior technology executive accountable for protecting Cengage Group's digital assets, data confidentiality, and technology infrastructure from cyber threats while ensuring compliance with regulatory requirements. This leader defines and delivers the enterprise information security strategy, building a robust and resilient security posture that enables business innovation while mitigating risk.
The CISO combines deep technical expertise with executive leadership, shaping the company's security vision while driving excellence in security operations, risk management, and governance. This role balances strategic vision, business partnership, and organizational influence to ensure security becomes an enabler of digital transformation rather than a barrier to progress. As a critical member of the IT leadership team, reporting to the CIO, this role serves as the primary authority on cybersecurity matters and partners closely with business leaders, legal, compliance, and the board to align security investments with enterprise priorities and risk appetite.
**Key Responsibilities**
**Enterprise Security Strategy & Risk Leadership**
+ Define and deliver the enterprise information security strategy, aligned with business priorities, digital transformation initiatives, and the company's risk tolerance in a PE-backed environment preparing for liquidity events.
+ Lead the development and implementation of comprehensive security programs encompassing cyber defense, data protection, identity and access management, security operations, and threat intelligence.
+ Conduct enterprise-wide risk assessments, identify vulnerabilities across the technology estate, and prioritize remediation efforts to reduce risk exposure while enabling business agility.
+ Serve as the primary cybersecurity advisor to the CIO, executive leadership team, and board of directors, translating technical risks into business impact and providing strategic recommendations on security investments.
+ Drive security architecture decisions that balance protection with performance, cost efficiency, and user experience across cloud, on-premises, and hybrid environments.
**Cyber Defense & Security Operations**
+ Oversee security incident detection, response, and recovery programs, ensuring swift identification and mitigation of potential breaches with minimal business disruption.
+ Manage the security architecture, tools, and technologies deployed across the organization's IT infrastructure, including firewalls, intrusion detection/prevention systems, SIEMs, endpoint protection, and encryption protocols.
+ Lead security operations center (SOC), threat hunting capabilities, and vulnerability management programs that proactively identify and remediate security weaknesses.
+ Develop and maintain incident response playbooks, disaster recovery plans, and business continuity protocols that ensure organizational resilience against emerging threats.
+ Monitor security metrics, threat landscape trends, and attack patterns to continuously evolve defensive capabilities and inform executive decision-making on security posture.
**Governance, Compliance & Data Protection**
+ Ensure compliance with industry standards, regulatory requirements, and data protection laws including GDPR, CCPA, FERPA, SOC 2, ISO 27001, and other relevant frameworks for the education technology sector.
+ Coordinate with legal, compliance, privacy, and regulatory teams to maintain certifications, manage audits, and respond to regulatory inquiries with appropriate documentation and evidence.
+ Develop and enforce security policies, procedures, standards, and protocols that align with business goals, regulatory obligations, and industry guidelines.
+ Be responsible for data classification, data loss prevention (DLP), and privacy programs that protect sensitive student, employee, and company information across all systems and geographies.
+ Manage security audits, compliance assessments, and third-party risk evaluations, ensuring vendors and partners meet security requirements and contractual obligations.
**Business Partnership & Security Enablement**
+ Serve as a trusted partner to business executives, ensuring security investments and controls enable business innovation while appropriately managing risk.
+ Collaborate with product, engineering, and DevOps teams to integrate security measures into software development lifecycles through DevSecOps practices and secure-by-design principles.
+ Partner with IT leadership on technology modernization initiatives including cloud migration, digital transformation, and AI/ML adoption, ensuring security is embedded from inception.
+ Communicate security value and risk posture at the executive and board levels, linking security investments to business outcomes including revenue protection, regulatory compliance, and competitive differentiation.
+ Champion security awareness and cultural transformation across the enterprise, promoting shared responsibility for security rather than viewing it as solely an IT function.
**Leadership & Talent Development**
+ Lead and inspire a global security team including security architects, security engineers, SOC analysts, governance/risk/compliance specialists, and security operations professionals.
+ Establish career pathways, competencies, and training programs that elevate security capability and develop next-generation cybersecurity leaders.
+ Champion a culture of accountability, collaboration, continuous learning, and innovation within the security organization.
+ Act as an executive sponsor for security awareness training programs for employees at all levels, promoting a culture of cybersecurity across the organization.
+ Build strategic relationships with peer CISOs, industry groups, law enforcement, and threat intelligence communities to stay ahead of emerging threats and share best practices.
**Qualifications**
+ 15+ years of progressive leadership in information security, cybersecurity, or risk management, with 5+ years in senior director, VP, or CISO roles.
+ Proven track record developing and implementing enterprise security programs in global, complex organizations, preferably in education technology, SaaS, or regulated industries.
+ Extensive knowledge of information security principles, cybersecurity frameworks (NIST, ISO 27001, CIS Controls), and risk management practices with demonstrable success reducing organizational risk.
+ Deep expertise in security technologies including firewalls, intrusion detection/prevention systems, SIEMs, identity and access management (IAM), cloud security platforms, and encryption protocols.
+ Solid understanding of data privacy regulations (GDPR, CCPA, FERPA) and compliance requirements with experience managing audits and regulatory relationships.
+ Experience securing cloud infrastructure (AWS, Azure, GCP) and implementing cloud-native security architectures in multi-cloud and hybrid environments.
+ Demonstrated ability to lead incident response programs, manage security breaches, and coordinate with legal, communications, and executive teams during crisis situations.
+ Exceptional leadership skills with a history of developing high-performing, distributed security teams across multiple disciplines and geographies.
+ Strong business sense and communication skills, with the ability to influence C-suite leaders and board members by translating technical security concepts into business risk and value propositions.
+ Experience working in PE-backed technology companies preferred, with understanding of security requirements for M&A due diligence, integration, and preparing for liquidity events.
+ Relevant certifications such as Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified Information Systems Auditor (CISA), or equivalent strongly preferred.
+ Familiarity with DevSecOps practices, secure software development, ethical hacking, and penetration testing techniques valued.
+ Understanding of artificial intelligence and machine learning applications in security, including emerging threats and defensive capabilities in AI-powered systems.
Cengage Group is committed to working with broad talent pools to attract and hire strong and most qualified individuals. Our job applicants are considered regardless of race, national origin, religion, sex, sexual orientation, genetic information, disability, age, veteran status, and any other classification protected by applicable federal, state, provincial or local laws.
Cengage is also committed to providing reasonable accommodations for qualified individuals with disabilities including during our job application process. If you are an applicant with a disability and require reasonable accommodation in our job application process, please contact us at or at .
**About Cengage** **Group**
Cengage Group, a global education technology company serving millions of learners, provides affordable, quality digital products and services that equip students with the skills and competencies needed to be job ready. For more than 100 years, we have enabled the power and joy of learning with trusted, engaging content, and now, integrated digital platforms. We serve the higher education, workforce skills, secondary education, English language teaching and research markets worldwide. Through our scalable technology, including MindTap and Cengage Unlimited, we support all learners who seek to improve their lives and achieve their dreams through education.
**Compensation**
At Cengage Group, we take great pride in our commitment to providing a comprehensive and rewarding Total Rewards package designed to support and empower our employees. Click here ( to learn more about our _Total Rewards Philosophy_ .
The full base pay range has been provided for this position. Individual base pay will vary based on work schedule, qualifications, experience, internal equity, and geographic location. Sales roles often incorporate a significant incentive compensation program beyond this base pay range.
$250,200.00 - $308,000.00 USD
**Cengage Group** , a global education technology company serving millions of learners, provides affordable, quality digital products and services that equip students with the skills and competencies needed to be job ready. For more than 100 years, we have enabled the power and joy of learning with trusted, engaging content, and now, integrated digital platforms.
We serve the higher education, workforce skills, secondary education, English language teaching and research markets worldwide. Through our scalable technology, including MindTap and Cengage Unlimited, we support all learners who seek to improve their lives and achieve their dreams through education.
**_Warning: Be aware, there has been an increase of targeted recruitment_** **_scams perpetrated by bad actors falsely providing job offers on behalf Cengage Group to candidates as a means of obtaining personal information. Note that Cengage will always interview candidates via live in-person meetings, phone calls and video calls before an offer would be extended. Also, be sure to check that communication is coming from an @cengage.com email address._**
Chief Information Security Officer (Remote)
Posted today
Job Viewed
Job Description
At Cengage Group, our employees have a direct impact in helping students around the world discover the power and joy of learning. We are bonded by our shared purpose - driving innovation that helps millions of learners improve their lives and achieve their dreams through education.
**Our culture values inclusion, engagement, and discovery**
Our business is driven by our strong culture, and we know that creating an inclusive workplace is absolutely essential to the success of our company and our learners, as well as our individual well-being. We recognize the value of diverse perspectives in everything we do, and strive to ensure employees of all levels and backgrounds feel empowered to voice their ideas and bring their authentic selves to work. We achieve these priorities through programs, benefits, and initiatives that are integrated into the fabric of how we work every day. To learn more, please see .
The Chief Information Security Officer (CISO) is a senior technology executive accountable for protecting Cengage Group's digital assets, data confidentiality, and technology infrastructure from cyber threats while ensuring compliance with regulatory requirements. This leader defines and delivers the enterprise information security strategy, building a robust and resilient security posture that enables business innovation while mitigating risk.
The CISO combines deep technical expertise with executive leadership, shaping the company's security vision while driving excellence in security operations, risk management, and governance. This role balances strategic vision, business partnership, and organizational influence to ensure security becomes an enabler of digital transformation rather than a barrier to progress. As a critical member of the IT leadership team, reporting to the CIO, this role serves as the primary authority on cybersecurity matters and partners closely with business leaders, legal, compliance, and the board to align security investments with enterprise priorities and risk appetite.
**Key Responsibilities**
**Enterprise Security Strategy & Risk Leadership**
+ Define and deliver the enterprise information security strategy, aligned with business priorities, digital transformation initiatives, and the company's risk tolerance in a PE-backed environment preparing for liquidity events.
+ Lead the development and implementation of comprehensive security programs encompassing cyber defense, data protection, identity and access management, security operations, and threat intelligence.
+ Conduct enterprise-wide risk assessments, identify vulnerabilities across the technology estate, and prioritize remediation efforts to reduce risk exposure while enabling business agility.
+ Serve as the primary cybersecurity advisor to the CIO, executive leadership team, and board of directors, translating technical risks into business impact and providing strategic recommendations on security investments.
+ Drive security architecture decisions that balance protection with performance, cost efficiency, and user experience across cloud, on-premises, and hybrid environments.
**Cyber Defense & Security Operations**
+ Oversee security incident detection, response, and recovery programs, ensuring swift identification and mitigation of potential breaches with minimal business disruption.
+ Manage the security architecture, tools, and technologies deployed across the organization's IT infrastructure, including firewalls, intrusion detection/prevention systems, SIEMs, endpoint protection, and encryption protocols.
+ Lead security operations center (SOC), threat hunting capabilities, and vulnerability management programs that proactively identify and remediate security weaknesses.
+ Develop and maintain incident response playbooks, disaster recovery plans, and business continuity protocols that ensure organizational resilience against emerging threats.
+ Monitor security metrics, threat landscape trends, and attack patterns to continuously evolve defensive capabilities and inform executive decision-making on security posture.
**Governance, Compliance & Data Protection**
+ Ensure compliance with industry standards, regulatory requirements, and data protection laws including GDPR, CCPA, FERPA, SOC 2, ISO 27001, and other relevant frameworks for the education technology sector.
+ Coordinate with legal, compliance, privacy, and regulatory teams to maintain certifications, manage audits, and respond to regulatory inquiries with appropriate documentation and evidence.
+ Develop and enforce security policies, procedures, standards, and protocols that align with business goals, regulatory obligations, and industry guidelines.
+ Be responsible for data classification, data loss prevention (DLP), and privacy programs that protect sensitive student, employee, and company information across all systems and geographies.
+ Manage security audits, compliance assessments, and third-party risk evaluations, ensuring vendors and partners meet security requirements and contractual obligations.
**Business Partnership & Security Enablement**
+ Serve as a trusted partner to business executives, ensuring security investments and controls enable business innovation while appropriately managing risk.
+ Collaborate with product, engineering, and DevOps teams to integrate security measures into software development lifecycles through DevSecOps practices and secure-by-design principles.
+ Partner with IT leadership on technology modernization initiatives including cloud migration, digital transformation, and AI/ML adoption, ensuring security is embedded from inception.
+ Communicate security value and risk posture at the executive and board levels, linking security investments to business outcomes including revenue protection, regulatory compliance, and competitive differentiation.
+ Champion security awareness and cultural transformation across the enterprise, promoting shared responsibility for security rather than viewing it as solely an IT function.
**Leadership & Talent Development**
+ Lead and inspire a global security team including security architects, security engineers, SOC analysts, governance/risk/compliance specialists, and security operations professionals.
+ Establish career pathways, competencies, and training programs that elevate security capability and develop next-generation cybersecurity leaders.
+ Champion a culture of accountability, collaboration, continuous learning, and innovation within the security organization.
+ Act as an executive sponsor for security awareness training programs for employees at all levels, promoting a culture of cybersecurity across the organization.
+ Build strategic relationships with peer CISOs, industry groups, law enforcement, and threat intelligence communities to stay ahead of emerging threats and share best practices.
**Qualifications**
+ 15+ years of progressive leadership in information security, cybersecurity, or risk management, with 5+ years in senior director, VP, or CISO roles.
+ Proven track record developing and implementing enterprise security programs in global, complex organizations, preferably in education technology, SaaS, or regulated industries.
+ Extensive knowledge of information security principles, cybersecurity frameworks (NIST, ISO 27001, CIS Controls), and risk management practices with demonstrable success reducing organizational risk.
+ Deep expertise in security technologies including firewalls, intrusion detection/prevention systems, SIEMs, identity and access management (IAM), cloud security platforms, and encryption protocols.
+ Solid understanding of data privacy regulations (GDPR, CCPA, FERPA) and compliance requirements with experience managing audits and regulatory relationships.
+ Experience securing cloud infrastructure (AWS, Azure, GCP) and implementing cloud-native security architectures in multi-cloud and hybrid environments.
+ Demonstrated ability to lead incident response programs, manage security breaches, and coordinate with legal, communications, and executive teams during crisis situations.
+ Exceptional leadership skills with a history of developing high-performing, distributed security teams across multiple disciplines and geographies.
+ Strong business sense and communication skills, with the ability to influence C-suite leaders and board members by translating technical security concepts into business risk and value propositions.
+ Experience working in PE-backed technology companies preferred, with understanding of security requirements for M&A due diligence, integration, and preparing for liquidity events.
+ Relevant certifications such as Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified Information Systems Auditor (CISA), or equivalent strongly preferred.
+ Familiarity with DevSecOps practices, secure software development, ethical hacking, and penetration testing techniques valued.
+ Understanding of artificial intelligence and machine learning applications in security, including emerging threats and defensive capabilities in AI-powered systems.
Cengage Group is committed to working with broad talent pools to attract and hire strong and most qualified individuals. Our job applicants are considered regardless of race, national origin, religion, sex, sexual orientation, genetic information, disability, age, veteran status, and any other classification protected by applicable federal, state, provincial or local laws.
Cengage is also committed to providing reasonable accommodations for qualified individuals with disabilities including during our job application process. If you are an applicant with a disability and require reasonable accommodation in our job application process, please contact us at or at .
**About Cengage** **Group**
Cengage Group, a global education technology company serving millions of learners, provides affordable, quality digital products and services that equip students with the skills and competencies needed to be job ready. For more than 100 years, we have enabled the power and joy of learning with trusted, engaging content, and now, integrated digital platforms. We serve the higher education, workforce skills, secondary education, English language teaching and research markets worldwide. Through our scalable technology, including MindTap and Cengage Unlimited, we support all learners who seek to improve their lives and achieve their dreams through education.
**Compensation**
At Cengage Group, we take great pride in our commitment to providing a comprehensive and rewarding Total Rewards package designed to support and empower our employees. Click here ( to learn more about our _Total Rewards Philosophy_ .
The full base pay range has been provided for this position. Individual base pay will vary based on work schedule, qualifications, experience, internal equity, and geographic location. Sales roles often incorporate a significant incentive compensation program beyond this base pay range.
$250,200.00 - $308,000.00 USD
**Cengage Group** , a global education technology company serving millions of learners, provides affordable, quality digital products and services that equip students with the skills and competencies needed to be job ready. For more than 100 years, we have enabled the power and joy of learning with trusted, engaging content, and now, integrated digital platforms.
We serve the higher education, workforce skills, secondary education, English language teaching and research markets worldwide. Through our scalable technology, including MindTap and Cengage Unlimited, we support all learners who seek to improve their lives and achieve their dreams through education.
**_Warning: Be aware, there has been an increase of targeted recruitment_** **_scams perpetrated by bad actors falsely providing job offers on behalf Cengage Group to candidates as a means of obtaining personal information. Note that Cengage will always interview candidates via live in-person meetings, phone calls and video calls before an offer would be extended. Also, be sure to check that communication is coming from an @cengage.com email address._**
Be The First To Know
About the latest Chief information security officer Jobs in United States !
Chief Information Security Officer (Remote)
Posted today
Job Viewed
Job Description
At Cengage Group, our employees have a direct impact in helping students around the world discover the power and joy of learning. We are bonded by our shared purpose - driving innovation that helps millions of learners improve their lives and achieve their dreams through education.
**Our culture values inclusion, engagement, and discovery**
Our business is driven by our strong culture, and we know that creating an inclusive workplace is absolutely essential to the success of our company and our learners, as well as our individual well-being. We recognize the value of diverse perspectives in everything we do, and strive to ensure employees of all levels and backgrounds feel empowered to voice their ideas and bring their authentic selves to work. We achieve these priorities through programs, benefits, and initiatives that are integrated into the fabric of how we work every day. To learn more, please see .
The Chief Information Security Officer (CISO) is a senior technology executive accountable for protecting Cengage Group's digital assets, data confidentiality, and technology infrastructure from cyber threats while ensuring compliance with regulatory requirements. This leader defines and delivers the enterprise information security strategy, building a robust and resilient security posture that enables business innovation while mitigating risk.
The CISO combines deep technical expertise with executive leadership, shaping the company's security vision while driving excellence in security operations, risk management, and governance. This role balances strategic vision, business partnership, and organizational influence to ensure security becomes an enabler of digital transformation rather than a barrier to progress. As a critical member of the IT leadership team, reporting to the CIO, this role serves as the primary authority on cybersecurity matters and partners closely with business leaders, legal, compliance, and the board to align security investments with enterprise priorities and risk appetite.
**Key Responsibilities**
**Enterprise Security Strategy & Risk Leadership**
+ Define and deliver the enterprise information security strategy, aligned with business priorities, digital transformation initiatives, and the company's risk tolerance in a PE-backed environment preparing for liquidity events.
+ Lead the development and implementation of comprehensive security programs encompassing cyber defense, data protection, identity and access management, security operations, and threat intelligence.
+ Conduct enterprise-wide risk assessments, identify vulnerabilities across the technology estate, and prioritize remediation efforts to reduce risk exposure while enabling business agility.
+ Serve as the primary cybersecurity advisor to the CIO, executive leadership team, and board of directors, translating technical risks into business impact and providing strategic recommendations on security investments.
+ Drive security architecture decisions that balance protection with performance, cost efficiency, and user experience across cloud, on-premises, and hybrid environments.
**Cyber Defense & Security Operations**
+ Oversee security incident detection, response, and recovery programs, ensuring swift identification and mitigation of potential breaches with minimal business disruption.
+ Manage the security architecture, tools, and technologies deployed across the organization's IT infrastructure, including firewalls, intrusion detection/prevention systems, SIEMs, endpoint protection, and encryption protocols.
+ Lead security operations center (SOC), threat hunting capabilities, and vulnerability management programs that proactively identify and remediate security weaknesses.
+ Develop and maintain incident response playbooks, disaster recovery plans, and business continuity protocols that ensure organizational resilience against emerging threats.
+ Monitor security metrics, threat landscape trends, and attack patterns to continuously evolve defensive capabilities and inform executive decision-making on security posture.
**Governance, Compliance & Data Protection**
+ Ensure compliance with industry standards, regulatory requirements, and data protection laws including GDPR, CCPA, FERPA, SOC 2, ISO 27001, and other relevant frameworks for the education technology sector.
+ Coordinate with legal, compliance, privacy, and regulatory teams to maintain certifications, manage audits, and respond to regulatory inquiries with appropriate documentation and evidence.
+ Develop and enforce security policies, procedures, standards, and protocols that align with business goals, regulatory obligations, and industry guidelines.
+ Be responsible for data classification, data loss prevention (DLP), and privacy programs that protect sensitive student, employee, and company information across all systems and geographies.
+ Manage security audits, compliance assessments, and third-party risk evaluations, ensuring vendors and partners meet security requirements and contractual obligations.
**Business Partnership & Security Enablement**
+ Serve as a trusted partner to business executives, ensuring security investments and controls enable business innovation while appropriately managing risk.
+ Collaborate with product, engineering, and DevOps teams to integrate security measures into software development lifecycles through DevSecOps practices and secure-by-design principles.
+ Partner with IT leadership on technology modernization initiatives including cloud migration, digital transformation, and AI/ML adoption, ensuring security is embedded from inception.
+ Communicate security value and risk posture at the executive and board levels, linking security investments to business outcomes including revenue protection, regulatory compliance, and competitive differentiation.
+ Champion security awareness and cultural transformation across the enterprise, promoting shared responsibility for security rather than viewing it as solely an IT function.
**Leadership & Talent Development**
+ Lead and inspire a global security team including security architects, security engineers, SOC analysts, governance/risk/compliance specialists, and security operations professionals.
+ Establish career pathways, competencies, and training programs that elevate security capability and develop next-generation cybersecurity leaders.
+ Champion a culture of accountability, collaboration, continuous learning, and innovation within the security organization.
+ Act as an executive sponsor for security awareness training programs for employees at all levels, promoting a culture of cybersecurity across the organization.
+ Build strategic relationships with peer CISOs, industry groups, law enforcement, and threat intelligence communities to stay ahead of emerging threats and share best practices.
**Qualifications**
+ 15+ years of progressive leadership in information security, cybersecurity, or risk management, with 5+ years in senior director, VP, or CISO roles.
+ Proven track record developing and implementing enterprise security programs in global, complex organizations, preferably in education technology, SaaS, or regulated industries.
+ Extensive knowledge of information security principles, cybersecurity frameworks (NIST, ISO 27001, CIS Controls), and risk management practices with demonstrable success reducing organizational risk.
+ Deep expertise in security technologies including firewalls, intrusion detection/prevention systems, SIEMs, identity and access management (IAM), cloud security platforms, and encryption protocols.
+ Solid understanding of data privacy regulations (GDPR, CCPA, FERPA) and compliance requirements with experience managing audits and regulatory relationships.
+ Experience securing cloud infrastructure (AWS, Azure, GCP) and implementing cloud-native security architectures in multi-cloud and hybrid environments.
+ Demonstrated ability to lead incident response programs, manage security breaches, and coordinate with legal, communications, and executive teams during crisis situations.
+ Exceptional leadership skills with a history of developing high-performing, distributed security teams across multiple disciplines and geographies.
+ Strong business sense and communication skills, with the ability to influence C-suite leaders and board members by translating technical security concepts into business risk and value propositions.
+ Experience working in PE-backed technology companies preferred, with understanding of security requirements for M&A due diligence, integration, and preparing for liquidity events.
+ Relevant certifications such as Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified Information Systems Auditor (CISA), or equivalent strongly preferred.
+ Familiarity with DevSecOps practices, secure software development, ethical hacking, and penetration testing techniques valued.
+ Understanding of artificial intelligence and machine learning applications in security, including emerging threats and defensive capabilities in AI-powered systems.
Cengage Group is committed to working with broad talent pools to attract and hire strong and most qualified individuals. Our job applicants are considered regardless of race, national origin, religion, sex, sexual orientation, genetic information, disability, age, veteran status, and any other classification protected by applicable federal, state, provincial or local laws.
Cengage is also committed to providing reasonable accommodations for qualified individuals with disabilities including during our job application process. If you are an applicant with a disability and require reasonable accommodation in our job application process, please contact us at or at .
**About Cengage** **Group**
Cengage Group, a global education technology company serving millions of learners, provides affordable, quality digital products and services that equip students with the skills and competencies needed to be job ready. For more than 100 years, we have enabled the power and joy of learning with trusted, engaging content, and now, integrated digital platforms. We serve the higher education, workforce skills, secondary education, English language teaching and research markets worldwide. Through our scalable technology, including MindTap and Cengage Unlimited, we support all learners who seek to improve their lives and achieve their dreams through education.
**Compensation**
At Cengage Group, we take great pride in our commitment to providing a comprehensive and rewarding Total Rewards package designed to support and empower our employees. Click here ( to learn more about our _Total Rewards Philosophy_ .
The full base pay range has been provided for this position. Individual base pay will vary based on work schedule, qualifications, experience, internal equity, and geographic location. Sales roles often incorporate a significant incentive compensation program beyond this base pay range.
$250,200.00 - $308,000.00 USD
**Cengage Group** , a global education technology company serving millions of learners, provides affordable, quality digital products and services that equip students with the skills and competencies needed to be job ready. For more than 100 years, we have enabled the power and joy of learning with trusted, engaging content, and now, integrated digital platforms.
We serve the higher education, workforce skills, secondary education, English language teaching and research markets worldwide. Through our scalable technology, including MindTap and Cengage Unlimited, we support all learners who seek to improve their lives and achieve their dreams through education.
**_Warning: Be aware, there has been an increase of targeted recruitment_** **_scams perpetrated by bad actors falsely providing job offers on behalf Cengage Group to candidates as a means of obtaining personal information. Note that Cengage will always interview candidates via live in-person meetings, phone calls and video calls before an offer would be extended. Also, be sure to check that communication is coming from an @cengage.com email address._**
Chief Information Security Officer (Remote)
Posted today
Job Viewed
Job Description
At Cengage Group, our employees have a direct impact in helping students around the world discover the power and joy of learning. We are bonded by our shared purpose - driving innovation that helps millions of learners improve their lives and achieve their dreams through education.
**Our culture values inclusion, engagement, and discovery**
Our business is driven by our strong culture, and we know that creating an inclusive workplace is absolutely essential to the success of our company and our learners, as well as our individual well-being. We recognize the value of diverse perspectives in everything we do, and strive to ensure employees of all levels and backgrounds feel empowered to voice their ideas and bring their authentic selves to work. We achieve these priorities through programs, benefits, and initiatives that are integrated into the fabric of how we work every day. To learn more, please see .
The Chief Information Security Officer (CISO) is a senior technology executive accountable for protecting Cengage Group's digital assets, data confidentiality, and technology infrastructure from cyber threats while ensuring compliance with regulatory requirements. This leader defines and delivers the enterprise information security strategy, building a robust and resilient security posture that enables business innovation while mitigating risk.
The CISO combines deep technical expertise with executive leadership, shaping the company's security vision while driving excellence in security operations, risk management, and governance. This role balances strategic vision, business partnership, and organizational influence to ensure security becomes an enabler of digital transformation rather than a barrier to progress. As a critical member of the IT leadership team, reporting to the CIO, this role serves as the primary authority on cybersecurity matters and partners closely with business leaders, legal, compliance, and the board to align security investments with enterprise priorities and risk appetite.
**Key Responsibilities**
**Enterprise Security Strategy & Risk Leadership**
+ Define and deliver the enterprise information security strategy, aligned with business priorities, digital transformation initiatives, and the company's risk tolerance in a PE-backed environment preparing for liquidity events.
+ Lead the development and implementation of comprehensive security programs encompassing cyber defense, data protection, identity and access management, security operations, and threat intelligence.
+ Conduct enterprise-wide risk assessments, identify vulnerabilities across the technology estate, and prioritize remediation efforts to reduce risk exposure while enabling business agility.
+ Serve as the primary cybersecurity advisor to the CIO, executive leadership team, and board of directors, translating technical risks into business impact and providing strategic recommendations on security investments.
+ Drive security architecture decisions that balance protection with performance, cost efficiency, and user experience across cloud, on-premises, and hybrid environments.
**Cyber Defense & Security Operations**
+ Oversee security incident detection, response, and recovery programs, ensuring swift identification and mitigation of potential breaches with minimal business disruption.
+ Manage the security architecture, tools, and technologies deployed across the organization's IT infrastructure, including firewalls, intrusion detection/prevention systems, SIEMs, endpoint protection, and encryption protocols.
+ Lead security operations center (SOC), threat hunting capabilities, and vulnerability management programs that proactively identify and remediate security weaknesses.
+ Develop and maintain incident response playbooks, disaster recovery plans, and business continuity protocols that ensure organizational resilience against emerging threats.
+ Monitor security metrics, threat landscape trends, and attack patterns to continuously evolve defensive capabilities and inform executive decision-making on security posture.
**Governance, Compliance & Data Protection**
+ Ensure compliance with industry standards, regulatory requirements, and data protection laws including GDPR, CCPA, FERPA, SOC 2, ISO 27001, and other relevant frameworks for the education technology sector.
+ Coordinate with legal, compliance, privacy, and regulatory teams to maintain certifications, manage audits, and respond to regulatory inquiries with appropriate documentation and evidence.
+ Develop and enforce security policies, procedures, standards, and protocols that align with business goals, regulatory obligations, and industry guidelines.
+ Be responsible for data classification, data loss prevention (DLP), and privacy programs that protect sensitive student, employee, and company information across all systems and geographies.
+ Manage security audits, compliance assessments, and third-party risk evaluations, ensuring vendors and partners meet security requirements and contractual obligations.
**Business Partnership & Security Enablement**
+ Serve as a trusted partner to business executives, ensuring security investments and controls enable business innovation while appropriately managing risk.
+ Collaborate with product, engineering, and DevOps teams to integrate security measures into software development lifecycles through DevSecOps practices and secure-by-design principles.
+ Partner with IT leadership on technology modernization initiatives including cloud migration, digital transformation, and AI/ML adoption, ensuring security is embedded from inception.
+ Communicate security value and risk posture at the executive and board levels, linking security investments to business outcomes including revenue protection, regulatory compliance, and competitive differentiation.
+ Champion security awareness and cultural transformation across the enterprise, promoting shared responsibility for security rather than viewing it as solely an IT function.
**Leadership & Talent Development**
+ Lead and inspire a global security team including security architects, security engineers, SOC analysts, governance/risk/compliance specialists, and security operations professionals.
+ Establish career pathways, competencies, and training programs that elevate security capability and develop next-generation cybersecurity leaders.
+ Champion a culture of accountability, collaboration, continuous learning, and innovation within the security organization.
+ Act as an executive sponsor for security awareness training programs for employees at all levels, promoting a culture of cybersecurity across the organization.
+ Build strategic relationships with peer CISOs, industry groups, law enforcement, and threat intelligence communities to stay ahead of emerging threats and share best practices.
**Qualifications**
+ 15+ years of progressive leadership in information security, cybersecurity, or risk management, with 5+ years in senior director, VP, or CISO roles.
+ Proven track record developing and implementing enterprise security programs in global, complex organizations, preferably in education technology, SaaS, or regulated industries.
+ Extensive knowledge of information security principles, cybersecurity frameworks (NIST, ISO 27001, CIS Controls), and risk management practices with demonstrable success reducing organizational risk.
+ Deep expertise in security technologies including firewalls, intrusion detection/prevention systems, SIEMs, identity and access management (IAM), cloud security platforms, and encryption protocols.
+ Solid understanding of data privacy regulations (GDPR, CCPA, FERPA) and compliance requirements with experience managing audits and regulatory relationships.
+ Experience securing cloud infrastructure (AWS, Azure, GCP) and implementing cloud-native security architectures in multi-cloud and hybrid environments.
+ Demonstrated ability to lead incident response programs, manage security breaches, and coordinate with legal, communications, and executive teams during crisis situations.
+ Exceptional leadership skills with a history of developing high-performing, distributed security teams across multiple disciplines and geographies.
+ Strong business sense and communication skills, with the ability to influence C-suite leaders and board members by translating technical security concepts into business risk and value propositions.
+ Experience working in PE-backed technology companies preferred, with understanding of security requirements for M&A due diligence, integration, and preparing for liquidity events.
+ Relevant certifications such as Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified Information Systems Auditor (CISA), or equivalent strongly preferred.
+ Familiarity with DevSecOps practices, secure software development, ethical hacking, and penetration testing techniques valued.
+ Understanding of artificial intelligence and machine learning applications in security, including emerging threats and defensive capabilities in AI-powered systems.
Cengage Group is committed to working with broad talent pools to attract and hire strong and most qualified individuals. Our job applicants are considered regardless of race, national origin, religion, sex, sexual orientation, genetic information, disability, age, veteran status, and any other classification protected by applicable federal, state, provincial or local laws.
Cengage is also committed to providing reasonable accommodations for qualified individuals with disabilities including during our job application process. If you are an applicant with a disability and require reasonable accommodation in our job application process, please contact us at or at .
**About Cengage** **Group**
Cengage Group, a global education technology company serving millions of learners, provides affordable, quality digital products and services that equip students with the skills and competencies needed to be job ready. For more than 100 years, we have enabled the power and joy of learning with trusted, engaging content, and now, integrated digital platforms. We serve the higher education, workforce skills, secondary education, English language teaching and research markets worldwide. Through our scalable technology, including MindTap and Cengage Unlimited, we support all learners who seek to improve their lives and achieve their dreams through education.
**Compensation**
At Cengage Group, we take great pride in our commitment to providing a comprehensive and rewarding Total Rewards package designed to support and empower our employees. Click here ( to learn more about our _Total Rewards Philosophy_ .
The full base pay range has been provided for this position. Individual base pay will vary based on work schedule, qualifications, experience, internal equity, and geographic location. Sales roles often incorporate a significant incentive compensation program beyond this base pay range.
$250,200.00 - $308,000.00 USD
**Cengage Group** , a global education technology company serving millions of learners, provides affordable, quality digital products and services that equip students with the skills and competencies needed to be job ready. For more than 100 years, we have enabled the power and joy of learning with trusted, engaging content, and now, integrated digital platforms.
We serve the higher education, workforce skills, secondary education, English language teaching and research markets worldwide. Through our scalable technology, including MindTap and Cengage Unlimited, we support all learners who seek to improve their lives and achieve their dreams through education.
**_Warning: Be aware, there has been an increase of targeted recruitment_** **_scams perpetrated by bad actors falsely providing job offers on behalf Cengage Group to candidates as a means of obtaining personal information. Note that Cengage will always interview candidates via live in-person meetings, phone calls and video calls before an offer would be extended. Also, be sure to check that communication is coming from an @cengage.com email address._**
Chief Information Security Officer (Remote)
Posted today
Job Viewed
Job Description
At Cengage Group, our employees have a direct impact in helping students around the world discover the power and joy of learning. We are bonded by our shared purpose - driving innovation that helps millions of learners improve their lives and achieve their dreams through education.
**Our culture values inclusion, engagement, and discovery**
Our business is driven by our strong culture, and we know that creating an inclusive workplace is absolutely essential to the success of our company and our learners, as well as our individual well-being. We recognize the value of diverse perspectives in everything we do, and strive to ensure employees of all levels and backgrounds feel empowered to voice their ideas and bring their authentic selves to work. We achieve these priorities through programs, benefits, and initiatives that are integrated into the fabric of how we work every day. To learn more, please see .
The Chief Information Security Officer (CISO) is a senior technology executive accountable for protecting Cengage Group's digital assets, data confidentiality, and technology infrastructure from cyber threats while ensuring compliance with regulatory requirements. This leader defines and delivers the enterprise information security strategy, building a robust and resilient security posture that enables business innovation while mitigating risk.
The CISO combines deep technical expertise with executive leadership, shaping the company's security vision while driving excellence in security operations, risk management, and governance. This role balances strategic vision, business partnership, and organizational influence to ensure security becomes an enabler of digital transformation rather than a barrier to progress. As a critical member of the IT leadership team, reporting to the CIO, this role serves as the primary authority on cybersecurity matters and partners closely with business leaders, legal, compliance, and the board to align security investments with enterprise priorities and risk appetite.
**Key Responsibilities**
**Enterprise Security Strategy & Risk Leadership**
+ Define and deliver the enterprise information security strategy, aligned with business priorities, digital transformation initiatives, and the company's risk tolerance in a PE-backed environment preparing for liquidity events.
+ Lead the development and implementation of comprehensive security programs encompassing cyber defense, data protection, identity and access management, security operations, and threat intelligence.
+ Conduct enterprise-wide risk assessments, identify vulnerabilities across the technology estate, and prioritize remediation efforts to reduce risk exposure while enabling business agility.
+ Serve as the primary cybersecurity advisor to the CIO, executive leadership team, and board of directors, translating technical risks into business impact and providing strategic recommendations on security investments.
+ Drive security architecture decisions that balance protection with performance, cost efficiency, and user experience across cloud, on-premises, and hybrid environments.
**Cyber Defense & Security Operations**
+ Oversee security incident detection, response, and recovery programs, ensuring swift identification and mitigation of potential breaches with minimal business disruption.
+ Manage the security architecture, tools, and technologies deployed across the organization's IT infrastructure, including firewalls, intrusion detection/prevention systems, SIEMs, endpoint protection, and encryption protocols.
+ Lead security operations center (SOC), threat hunting capabilities, and vulnerability management programs that proactively identify and remediate security weaknesses.
+ Develop and maintain incident response playbooks, disaster recovery plans, and business continuity protocols that ensure organizational resilience against emerging threats.
+ Monitor security metrics, threat landscape trends, and attack patterns to continuously evolve defensive capabilities and inform executive decision-making on security posture.
**Governance, Compliance & Data Protection**
+ Ensure compliance with industry standards, regulatory requirements, and data protection laws including GDPR, CCPA, FERPA, SOC 2, ISO 27001, and other relevant frameworks for the education technology sector.
+ Coordinate with legal, compliance, privacy, and regulatory teams to maintain certifications, manage audits, and respond to regulatory inquiries with appropriate documentation and evidence.
+ Develop and enforce security policies, procedures, standards, and protocols that align with business goals, regulatory obligations, and industry guidelines.
+ Be responsible for data classification, data loss prevention (DLP), and privacy programs that protect sensitive student, employee, and company information across all systems and geographies.
+ Manage security audits, compliance assessments, and third-party risk evaluations, ensuring vendors and partners meet security requirements and contractual obligations.
**Business Partnership & Security Enablement**
+ Serve as a trusted partner to business executives, ensuring security investments and controls enable business innovation while appropriately managing risk.
+ Collaborate with product, engineering, and DevOps teams to integrate security measures into software development lifecycles through DevSecOps practices and secure-by-design principles.
+ Partner with IT leadership on technology modernization initiatives including cloud migration, digital transformation, and AI/ML adoption, ensuring security is embedded from inception.
+ Communicate security value and risk posture at the executive and board levels, linking security investments to business outcomes including revenue protection, regulatory compliance, and competitive differentiation.
+ Champion security awareness and cultural transformation across the enterprise, promoting shared responsibility for security rather than viewing it as solely an IT function.
**Leadership & Talent Development**
+ Lead and inspire a global security team including security architects, security engineers, SOC analysts, governance/risk/compliance specialists, and security operations professionals.
+ Establish career pathways, competencies, and training programs that elevate security capability and develop next-generation cybersecurity leaders.
+ Champion a culture of accountability, collaboration, continuous learning, and innovation within the security organization.
+ Act as an executive sponsor for security awareness training programs for employees at all levels, promoting a culture of cybersecurity across the organization.
+ Build strategic relationships with peer CISOs, industry groups, law enforcement, and threat intelligence communities to stay ahead of emerging threats and share best practices.
**Qualifications**
+ 15+ years of progressive leadership in information security, cybersecurity, or risk management, with 5+ years in senior director, VP, or CISO roles.
+ Proven track record developing and implementing enterprise security programs in global, complex organizations, preferably in education technology, SaaS, or regulated industries.
+ Extensive knowledge of information security principles, cybersecurity frameworks (NIST, ISO 27001, CIS Controls), and risk management practices with demonstrable success reducing organizational risk.
+ Deep expertise in security technologies including firewalls, intrusion detection/prevention systems, SIEMs, identity and access management (IAM), cloud security platforms, and encryption protocols.
+ Solid understanding of data privacy regulations (GDPR, CCPA, FERPA) and compliance requirements with experience managing audits and regulatory relationships.
+ Experience securing cloud infrastructure (AWS, Azure, GCP) and implementing cloud-native security architectures in multi-cloud and hybrid environments.
+ Demonstrated ability to lead incident response programs, manage security breaches, and coordinate with legal, communications, and executive teams during crisis situations.
+ Exceptional leadership skills with a history of developing high-performing, distributed security teams across multiple disciplines and geographies.
+ Strong business sense and communication skills, with the ability to influence C-suite leaders and board members by translating technical security concepts into business risk and value propositions.
+ Experience working in PE-backed technology companies preferred, with understanding of security requirements for M&A due diligence, integration, and preparing for liquidity events.
+ Relevant certifications such as Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified Information Systems Auditor (CISA), or equivalent strongly preferred.
+ Familiarity with DevSecOps practices, secure software development, ethical hacking, and penetration testing techniques valued.
+ Understanding of artificial intelligence and machine learning applications in security, including emerging threats and defensive capabilities in AI-powered systems.
Cengage Group is committed to working with broad talent pools to attract and hire strong and most qualified individuals. Our job applicants are considered regardless of race, national origin, religion, sex, sexual orientation, genetic information, disability, age, veteran status, and any other classification protected by applicable federal, state, provincial or local laws.
Cengage is also committed to providing reasonable accommodations for qualified individuals with disabilities including during our job application process. If you are an applicant with a disability and require reasonable accommodation in our job application process, please contact us at or at .
**About Cengage** **Group**
Cengage Group, a global education technology company serving millions of learners, provides affordable, quality digital products and services that equip students with the skills and competencies needed to be job ready. For more than 100 years, we have enabled the power and joy of learning with trusted, engaging content, and now, integrated digital platforms. We serve the higher education, workforce skills, secondary education, English language teaching and research markets worldwide. Through our scalable technology, including MindTap and Cengage Unlimited, we support all learners who seek to improve their lives and achieve their dreams through education.
**Compensation**
At Cengage Group, we take great pride in our commitment to providing a comprehensive and rewarding Total Rewards package designed to support and empower our employees. Click here ( to learn more about our _Total Rewards Philosophy_ .
The full base pay range has been provided for this position. Individual base pay will vary based on work schedule, qualifications, experience, internal equity, and geographic location. Sales roles often incorporate a significant incentive compensation program beyond this base pay range.
$250,200.00 - $308,000.00 USD
**Cengage Group** , a global education technology company serving millions of learners, provides affordable, quality digital products and services that equip students with the skills and competencies needed to be job ready. For more than 100 years, we have enabled the power and joy of learning with trusted, engaging content, and now, integrated digital platforms.
We serve the higher education, workforce skills, secondary education, English language teaching and research markets worldwide. Through our scalable technology, including MindTap and Cengage Unlimited, we support all learners who seek to improve their lives and achieve their dreams through education.
**_Warning: Be aware, there has been an increase of targeted recruitment_** **_scams perpetrated by bad actors falsely providing job offers on behalf Cengage Group to candidates as a means of obtaining personal information. Note that Cengage will always interview candidates via live in-person meetings, phone calls and video calls before an offer would be extended. Also, be sure to check that communication is coming from an @cengage.com email address._**