JOBSEARCHER

Chief Security Officer

Job Summary T5 Solutions has contracted with one of our clients to provide Virtual Chief Information Security Officer services. This will be a contract position for a period of twelve (2) months. Work Description The Client recently completed two (2) security audits wherein several remediation tasks were outlined to be completed. The Client has engaged the T5 Solutions to deliver the following capabilities: Work to ensure all items listed in theaudit report are addressed and moved to partial or full remediation, or declared as “no longer active” Establish a defensible, written information security program aligned to recognized frameworks (NIST CSF 2.0 and the FTC Safeguards Rule, with mappings to ABA Standard 203 governance expectations). Utilize the newly implemented security monitoring toolset to assist with implantation of security IT policies and processes. Reduce institutional risk across all administrative systems. Build internal awareness and security culture Strategic Security Leadership Serve as the Client’s designated Qualified Individual under 16 CFR §314.4(a) of the FTC Safeguards Rule. Develop and maintain a multi-year information security strategy and roadmap, reviewed at least annually. Provide quarterly written reports to the Dean, CIO/CFO/COO, and (when requested) the Board of Trustees or Audit Committee, including the annual written report required under §314.4(i). Represent the Client’s security posture to auditors, accreditors, cyber-insurance carriers, and external counsel. 3.2 Governance, Risk, and Compliance (GRC) Develop, review, and maintain core security policies: Information Security Policy, Acceptable Use, Access Control, Data Classification & Handling, Incident Response, Vendor Risk Management, Written Information Security Program (WISP), and Records Retention. Conduct an annual risk assessment covering all in scope systems, in alignment with NIST CSF 2.0 and §314.4(b) of the Safeguards Rule. Maintain a risk register with prioritized treatment plans, owners, and target dates. Map controls to applicable obligations: GLBA Safeguards Rule, FERPA, HIPAA (where the Health Law Clinic or counseling services apply), state breach-notification laws, PCI DSS (if cards are accepted), and contractual obligations. 3.3 Security Operations Oversight Define and oversee a control baseline for endpoints, identity (SSO/MFA), email security, network segmentation, and backup integrity. Review monthly operational metrics from the Client’s IT team or MSP: patch compliance, MFA coverage, phishing-simulation results, EDR alerts, backup-restore tests, and privileged access reviews. Oversee vulnerability management and prioritize remediation based on exploitability and exposure. Govern cloud security posture for Microsoft 365 / Google Workspace, the LMS (e.g., Canvas, Blackboard), the SIS, and clinic case-management systems. Provide architectural review for new system acquisitions and configuration changes. 3.4 Incident Response and Resilience Maintain an Incident Response Plan and supporting playbooks for the most likely scenarios: business email compromise, ransomware, account takeover, lost/stolen device, exposed clinic file, and exam-system disruption. Lead an annual tabletop exercise with the CIO and other leadership team, Serve as incident commander for declared security incidents, coordinating internal teams, external counsel, forensic providers, and the cyber-insurance carrier. Advise on regulatory and contractual notification obligations, including the 30-day Safeguards Rule notification trigger (§314.5). Conduct post-incident reviews and drive corrective actions to closure. 3.5 Awareness, Training, and Third-Party Risk Design and oversee a security awareness program for all required staff — including role-based training for those handling client files. Run quarterly phishing simulations with targeted follow-up coaching. Establish and operate a vendor risk management process: intake, tiering, due-diligence questionnaires, contract security clauses, and periodic reassessment. Pay: $70.00 - $85.00 per hour Expected hours: 20 per week Work Location: Hybrid remote in San Francisco, CA 94102