Chief information security officer
Lensa is a career site that helps job seekers find great jobs in the US. We are not a staffing firm or agency. Lensa does not hire directly for these jobs, but promotes jobs on LinkedIn on behalf of its direct clients, recruitment ad agencies, and marketing partners. Lensa partners with DirectEmployers to promote this job for Cengage Group. Clicking "Apply Now" or "Read more" on Lensa redirects you to the job board/employer site. Any information collected there is subject to their terms and privacy notice.
We believe in the power and joy of learning At Cengage Group, our employees have a direct impact in helping students around the world discover the power and joy of learning. We are bonded by our shared purpose - driving innovation that helps millions of learners improve their lives and achieve their dreams through education. Our culture values inclusion, engagement, and discovery Our business is driven by our strong culture, and we know that creating an inclusive workplace is absolutely essential to the success of our company and our learners, as well as our individual well-being. We recognize the value of diverse perspectives in everything we do, and strive to ensure employees of all levels and backgrounds feel empowered to voice their ideas and bring their authentic selves to work. We achieve these priorities through programs, benefits, and initiatives that are integrated into the fabric of how we work every day. To learn more, please see . The Chief Information Security Officer (CISO) is a senior technology executive accountable for protecting Cengage Group's digital assets, data confidentiality, and technology infrastructure from cyber threats while ensuring compliance with regulatory requirements. This leader defines and delivers the enterprise information security strategy, building a robust and resilient security posture that enables business innovation while mitigating risk. The CISO combines deep technical expertise with executive leadership, shaping the company's security vision while driving excellence in security operations, risk management, and governance. This role balances strategic vision, business partnership, and organizational influence to ensure security becomes an enabler of digital transformation rather than a barrier to progress. As a critical member of the IT leadership team, reporting to the CIO, this role serves as the primary authority on cybersecurity matters and partners closely with business leaders, legal, compliance, and the board to align security investments with enterprise priorities and risk appetite. Key Responsibilities Enterprise Security Strategy & Risk Leadership- Define and deliver the enterprise information security strategy, aligned with business priorities, digital transformation initiatives, and the company's risk tolerance in a PE-backed environment preparing for liquidity events.
- Lead the development and implementation of comprehensive security programs encompassing cyber defense, data protection, identity and access management, security operations, and threat intelligence.
- Conduct enterprise-wide risk assessments, identify vulnerabilities across the technology estate, and prioritize remediation efforts to reduce risk exposure while enabling business agility.
- Serve as the primary cybersecurity advisor to the CIO, executive leadership team, and board of directors, translating technical risks into business impact and providing strategic recommendations on security investments.
- Drive security architecture decisions that balance protection with performance, cost efficiency, and user experience across cloud, on-premises, and hybrid environments.
- Oversee security incident detection, response, and recovery programs, ensuring swift identification and mitigation of potential breaches with minimal business disruption.
- Manage the security architecture, tools, and technologies deployed across the organization's IT infrastructure, including firewalls, intrusion detection/prevention systems, SIEMs, endpoint protection, and encryption protocols.
- Lead security operations center (SOC), threat hunting capabilities, and vulnerability management programs that proactively identify and remediate security weaknesses.
- Develop and maintain incident response playbooks, disaster recovery plans, and business continuity protocols that ensure organizational resilience against emerging threats.
- Monitor security metrics, threat landscape trends, and attack patterns to continuously evolve defensive capabilities and inform executive decision-making on security posture.
- Ensure compliance with industry standards, regulatory requirements, and data protection laws including GDPR, CCPA, FERPA, SOC 2, ISO 27001, and other relevant frameworks for the education technology sector.
- Coordinate with legal, compliance, privacy, and regulatory teams to maintain certifications, manage audits, and respond to regulatory inquiries with appropriate documentation and evidence.
- Develop and enforce security policies, procedures, standards, and protocols that align with business goals, regulatory obligations, and industry guidelines.
- Be responsible for data classification, data loss prevention (DLP), and privacy programs that protect sensitive student, employee, and company information across all systems and geographies.
- Manage security audits, compliance assessments, and third-party risk evaluations, ensuring vendors and partners meet security requirements and contractual obligations.
- Serve as a trusted partner to business executives, ensuring security investments and controls enable business innovation while appropriately managing risk.
- Collaborate with product, engineering, and DevOps teams to integrate security measures into software development lifecycles through DevSecOps practices and secure-by-design principles.
- Partner with IT leadership on technology modernization initiatives including cloud migration, digital transformation, and AI/ML adoption, ensuring security is embedded from inception.
- Communicate security value and risk posture at the executive and board levels, linking security investments to business outcomes including revenue protection, regulatory compliance, and competitive differentiation.
- Champion security awareness and cultural transformation across the enterprise, promoting shared responsibility for security rather than viewing it as solely an IT function.
- Lead and inspire a global security team including security architects, security engineers, SOC analysts, governance/risk/compliance specialists, and security operations professionals.
- Establish career pathways, competencies, and training programs that elevate security capability and develop next-generation cybersecurity leaders.
- Champion a culture of accountability, collaboration, continuous learning, and innovation within the security organization.
- Act as an executive sponsor for security awareness training programs for employees at all levels, promoting a culture of cybersecurity across the organization.
- Build strategic relationships with peer CISOs, industry groups, law enforcement, and threat intelligence communities to stay ahead of emerging threats and share best practices.
- 15+ years of progressive leadership in information security, cybersecurity, or risk management, with 5+ years in senior director, VP, or CISO roles.
- Proven track record developing and implementing enterprise security programs in global, complex organizations, preferably in education technology, SaaS, or regulated industries.
- Extensive knowledge of information security principles, cybersecurity frameworks (NIST, ISO 27001, CIS Controls), and risk management practices with demonstrable success reducing organizational risk.
- Deep expertise in security technologies including firewalls, intrusion detection/prevention systems, SIEMs, identity and access management (IAM), cloud security platforms, and encryption protocols.
- Solid understanding of data privacy regulations (GDPR, CCPA, FERPA) and compliance requirements with experience managing audits and regulatory relationships.
- Experience securing cloud infrastructure (AWS, Azure, GCP) and implementing cloud-native security architectures in multi-cloud and hybrid environments.
- Demonstrated ability to lead incident response programs, manage security breaches, and coordinate with legal, communications, and executive teams during crisis situations.
- Exceptional leadership skills with a history of developing high-performing, distributed security teams across multiple disciplines and geographies.
- Strong business sense and communication skills, with the ability to influence C-suite leaders and board members by translating technical security concepts into business risk and value propositions.
- Experience working in PE-backed technology companies preferred, with understanding of security requirements for M&A due diligence, integration, and preparing for liquidity events.
- Relevant certifications such as Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified Information Systems Auditor (CISA), or equivalent strongly preferred.
- Familiarity with DevSecOps practices, secure software development, ethical hacking, and penetration testing techniques valued.
- Understanding of artificial intelligence and machine learning applications in security, including emerging threats and defensive capabilities in AI-powered systems.
Recommended Jobs
Senior product development engineer
Amogy, Brooklyn, NY. Senior Product Development Engineer. Develop electromechanical products in compliance with applicable electrical, mechanical, and safety standards, as well as incorporating cert…
Floor Manager
About Grand Brasserie Grand Brasserie is where timeless charm meets modern hospitality. Our bustling dining room comes alive each morning with the vibrant energy of our breakfast and lunch service, …
FID, Quantitative Developer Strat, Munis
C o m p an y P r o file: Morgan Stanley is a leading global financial services firm providing a wide range of investment banking, securities, investment management and wealth management serv…
Utility operator
Armstrong has an opening for a first shift Utility Operator. Armstrong Rapid Manufacturing has been in business for over 50 years in the East Syracuse NY area. Armstrong specializes in both pro…
Corporate Associate (3rd-5th year)
Leading New York mid-size firm. New hybrid role - highly regarded practice founded over 30 years ago. About Our Client Known for a high collaborative environment that fosters Attorney develo…
Restaurant Manager
Genesis House, a luxury fine dining and cultural destination in New York’s Meatpacking District, blends world-class cuisine, immersive design, and outstanding hospitality to build unforgettable exper…
PMHNP in New York, NY
Join our team and make a difference in the lives of individuals struggling with mental health challenges. We are seeking a dedicated psychiatric physician assistant or mental health nurse practiti…
Software Engineer
Jahnel Group’s mission is to provide the absolute best environment for software creators to pursue their passion by connecting them with great clients doing meaningful work. This is a full time po…
Full Stack PHP Web Developer
About the ANA The mission is to drive growth for marketing professionals, brands and businesses, the industry, and humanity. Founded in 1910, the ANA provides leadership that advances marketing…
Marketing Intern
Moët Hennessy is offering a 10-week summer internship program for aspiring marketing professionals. Based in New York, this role provides hands-on experience within the luxury wines and spirits indust…