cybersecurity architect or lead or director of security only w2 with CISM,CISSP,CISA
Cybersecurity ArchitectFountain Valley CA Full TimePurpose: · Oversee the development, implementation, and monitoring of a strategic, comprehensive enterprise information security / cybersecurity program. Ensure information and data assets as well as technologies are adequately protected from both internal and external threats. Plan and implement security hardware and software, making sure IT and network infrastructure is designed around best security practices. Stay abreast of possible security threats, oversee real-time analysis of immediate threats, and actively work to prevent them from occurring. Implement threat modeling, formulate application security procedures, and resolution plans. Work across business units to identify and address security observations and findings. Responsible for integrating security plans and policies with the organization's business process, training others on security procedures, purchasing security products, and ensuring that security practices are being followed. Evaluate system vulnerability and recommend security improvements.Requirements:· Bachelor's Degree or equivalent (with major course work in information security or a related field).· Minimum of 10+years of experience in a combination of risk management, information security and IT management jobs· Establishment of IS strategy & policy for a multi-faceted organization supported by multi-platform environments.· Security assessment and incident-response within a dynamic IT environment· Knowledge of common information security management frameworks, such as ISO/IEC 27001, and NIST.· Excellent written and verbal communication skills and high level of personal integrity· Innovative thinking and leadership with an ability to lead and motivate cross-functional, interdisciplinary teams.· Experience with contract and vendor negotiations and management including managed services.· Specific experience in Agile (scaled) software development or other best in class development practices.· Auditing or evaluations of complex IT controls· Possession of, or ability to obtain, one of the following information security certifications or equivalent is desirable:· CISM (Certified Information Security Manager)· CISSP (Certified Information)· Systems Security Professional)· CISA (Certified Information Systems Auditor)