{"schemaVersion":"jobsearcher.job.v1","id":"672bd3b5b0b6befdf1382607","url":"https://jobsearcher.com/jobs/672bd3b5b0b6befdf1382607","canonicalUrl":"https://jobsearcher.com/jobs/672bd3b5b0b6befdf1382607","title":"Chief Security Officer","description":"Job Summary\nT5 Solutions has contracted with one of our clients to provide Virtual Chief Information Security Officer services. This will be a contract position for a period of twelve (2) months.\nWork Description\nThe Client recently completed two (2) security audits wherein several remediation tasks were outlined to be completed. The Client has engaged the T5 Solutions to deliver the following capabilities:\nWork to ensure all items listed in theaudit report are addressed and moved to partial or full remediation, or declared as “no longer active”\nEstablish a defensible, written information security program aligned to recognized frameworks (NIST CSF 2.0 and the FTC Safeguards Rule, with mappings to ABA Standard 203 governance expectations).\nUtilize the newly implemented security monitoring toolset to assist with implantation of security IT policies and processes. Reduce institutional risk across all administrative systems.\nBuild internal awareness and security culture\nStrategic Security Leadership\nServe as the Client’s designated Qualified Individual under 16 CFR §314.4(a) of the FTC Safeguards Rule.\nDevelop and maintain a multi-year information security strategy and roadmap, reviewed at least annually.\nProvide quarterly written reports to the Dean, CIO/CFO/COO, and (when requested) the Board of Trustees or Audit Committee, including the annual written report required under §314.4(i).\nRepresent the Client’s security posture to auditors, accreditors, cyber-insurance carriers, and external counsel.\n3.2 Governance, Risk, and Compliance (GRC)\nDevelop, review, and maintain core security policies: Information Security Policy, Acceptable Use, Access Control, Data Classification & Handling, Incident Response, Vendor Risk Management, Written Information Security Program (WISP), and Records Retention.\nConduct an annual risk assessment covering all in scope systems, in alignment with NIST CSF 2.0 and §314.4(b) of the Safeguards Rule.\nMaintain a risk register with prioritized treatment plans, owners, and target dates.\nMap controls to applicable obligations: GLBA Safeguards Rule, FERPA, HIPAA (where the Health Law Clinic or counseling services apply), state breach-notification laws, PCI DSS (if cards are accepted), and contractual obligations.\n3.3 Security Operations Oversight\nDefine and oversee a control baseline for endpoints, identity (SSO/MFA), email security, network segmentation, and backup integrity.\nReview monthly operational metrics from the Client’s IT team or MSP: patch compliance, MFA coverage, phishing-simulation results, EDR alerts, backup-restore tests, and privileged access reviews.\nOversee vulnerability management and prioritize remediation based on exploitability and exposure.\nGovern cloud security posture for Microsoft 365 / Google Workspace, the LMS (e.g., Canvas, Blackboard), the SIS, and clinic case-management systems.\nProvide architectural review for new system acquisitions and configuration changes.\n3.4 Incident Response and Resilience\nMaintain an Incident Response Plan and supporting playbooks for the most likely scenarios: business email compromise, ransomware, account takeover, lost/stolen device, exposed clinic file, and exam-system disruption.\nLead an annual tabletop exercise with the CIO and other leadership team,\nServe as incident commander for declared security incidents, coordinating internal teams, external counsel, forensic providers, and the cyber-insurance carrier.\nAdvise on regulatory and contractual notification obligations, including the 30-day Safeguards Rule notification trigger (§314.5).\nConduct post-incident reviews and drive corrective actions to closure.\n3.5 Awareness, Training, and Third-Party Risk\nDesign and oversee a security awareness program for all required staff — including role-based training for those handling client files.\nRun quarterly phishing simulations with targeted follow-up coaching.\nEstablish and operate a vendor risk management process: intake, tiering, due-diligence questionnaires, contract security clauses, and periodic reassessment.\nPay: $70.00 - $85.00 per hour\nExpected hours: 20 per week\nWork Location: Hybrid remote in San Francisco, CA 94102","company":"T5solutionstechnologyconsultingservices","rawCompany":"t5solutionstechnologyconsultingservices","city":"Millbrae","state":"CA","isRemote":false,"isActive":false,"createdAt":"2026-07-18T17:07:14.122Z","occupations":[{"code":"15-1212.00","title":"Information Security Analysts","slug":"information-security-analysts"},{"code":"13-1199.07","title":"Security Management Specialists","slug":"security-management-specialists"},{"code":"15-1299.05","title":"Information Security Engineers","slug":"information-security-engineers"}],"industries":[{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"},{"code":"561621","title":"Security Systems Services (except Locksmiths)","slug":"security-systems-services-except-locksmiths"},{"code":"541690","title":"Other Scientific and Technical Consulting Services","slug":"other-scientific-and-technical-consulting-services"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"Chief Security Officer","description":"Job Summary\nT5 Solutions has contracted with one of our clients to provide Virtual Chief Information Security Officer services. This will be a contract position for a period of twelve (2) months.\nWork Description\nThe Client recently completed two (2) security audits wherein several remediation tasks were outlined to be completed. The Client has engaged the T5 Solutions to deliver the following capabilities:\nWork to ensure all items listed in theaudit report are addressed and moved to partial or full remediation, or declared as “no longer active”\nEstablish a defensible, written information security program aligned to recognized frameworks (NIST CSF 2.0 and the FTC Safeguards Rule, with mappings to ABA Standard 203 governance expectations).\nUtilize the newly implemented security monitoring toolset to assist with implantation of security IT policies and processes. Reduce institutional risk across all administrative systems.\nBuild internal awareness and security culture\nStrategic Security Leadership\nServe as the Client’s designated Qualified Individual under 16 CFR §314.4(a) of the FTC Safeguards Rule.\nDevelop and maintain a multi-year information security strategy and roadmap, reviewed at least annually.\nProvide quarterly written reports to the Dean, CIO/CFO/COO, and (when requested) the Board of Trustees or Audit Committee, including the annual written report required under §314.4(i).\nRepresent the Client’s security posture to auditors, accreditors, cyber-insurance carriers, and external counsel.\n3.2 Governance, Risk, and Compliance (GRC)\nDevelop, review, and maintain core security policies: Information Security Policy, Acceptable Use, Access Control, Data Classification & Handling, Incident Response, Vendor Risk Management, Written Information Security Program (WISP), and Records Retention.\nConduct an annual risk assessment covering all in scope systems, in alignment with NIST CSF 2.0 and §314.4(b) of the Safeguards Rule.\nMaintain a risk register with prioritized treatment plans, owners, and target dates.\nMap controls to applicable obligations: GLBA Safeguards Rule, FERPA, HIPAA (where the Health Law Clinic or counseling services apply), state breach-notification laws, PCI DSS (if cards are accepted), and contractual obligations.\n3.3 Security Operations Oversight\nDefine and oversee a control baseline for endpoints, identity (SSO/MFA), email security, network segmentation, and backup integrity.\nReview monthly operational metrics from the Client’s IT team or MSP: patch compliance, MFA coverage, phishing-simulation results, EDR alerts, backup-restore tests, and privileged access reviews.\nOversee vulnerability management and prioritize remediation based on exploitability and exposure.\nGovern cloud security posture for Microsoft 365 / Google Workspace, the LMS (e.g., Canvas, Blackboard), the SIS, and clinic case-management systems.\nProvide architectural review for new system acquisitions and configuration changes.\n3.4 Incident Response and Resilience\nMaintain an Incident Response Plan and supporting playbooks for the most likely scenarios: business email compromise, ransomware, account takeover, lost/stolen device, exposed clinic file, and exam-system disruption.\nLead an annual tabletop exercise with the CIO and other leadership team,\nServe as incident commander for declared security incidents, coordinating internal teams, external counsel, forensic providers, and the cyber-insurance carrier.\nAdvise on regulatory and contractual notification obligations, including the 30-day Safeguards Rule notification trigger (§314.5).\nConduct post-incident reviews and drive corrective actions to closure.\n3.5 Awareness, Training, and Third-Party Risk\nDesign and oversee a security awareness program for all required staff — including role-based training for those handling client files.\nRun quarterly phishing simulations with targeted follow-up coaching.\nEstablish and operate a vendor risk management process: intake, tiering, due-diligence questionnaires, contract security clauses, and periodic reassessment.\nPay: $70.00 - $85.00 per hour\nExpected hours: 20 per week\nWork Location: Hybrid remote in San Francisco, CA 94102","datePosted":"2026-07-18T17:07:14.122Z","dateModified":"2026-07-18T17:07:14.122Z","hiringOrganization":{"@type":"Organization","name":"T5solutionstechnologyconsultingservices","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Millbrae","addressRegion":"CA","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"672bd3b5b0b6befdf1382607"},"url":"https://jobsearcher.com/jobs/672bd3b5b0b6befdf1382607"}}