Job Information
FLIGHTSAFETY INTERNATIONAL, INC. VP, Chief Information Security Officer in Grove City, Ohio
About FlightSafety International FlightSafety International is the world's premier professional aviation training company and supplier of flight simulators, visual systems and displays to commercial, government and military organizations. The company provides training for pilots, technicians and other aviation professionals from 167 countries and independent territories. FlightSafety operates the world's largest fleet of advanced full-flight simulators and award-winning maintenance training at Learning Centers and training locations in the United States, Canada, France and the United Kingdom. Purpose of Position The VP, CISO is a key leadership role responsible for the enterprise Information Security & Risk program. This position leads all Information Security efforts in support of end-to-end security strategy, design, and operational support. The Information Security leader serves as the principal and accountable representative for the enterprise security roadmap and related matters, while building and delivering a highly collaborative working relationship with the end-user community as well as fellow technology and engineering teams. This role is both strategic and tactical, demonstrating strong technical capabilities in the risk/security arena while also exhibiting strong leadership skills within the team and across adjacent functions. This role partners closely with Information Technology while providing leadership and guidance on security implementations, purpose and priority. This position reports to the Chief Information Officer. Tasks and Responsibilities Oversee the development, implementation, and maintenance of the security strategy, risk and governance framework, based on National Institute of Standards and Technology (NIST),that can scale across multiple regulatory controls, geographies, and internal business units to enable a culture of security throughout the enterprise * Create a metrics-driven culture using the appropriate methodologies, tools and communications practices. * Translate technical risks into interpretable organizational risks for a wide range of business and leadership audiences, including the Board and Senior Leadership Team (SLT) * Partner closely with the business and IT leadership to continually communicate on prioritized industry trends, threat groups/actors as well as emerging risks * Collaborate with IT teams within both FSI & NetJets to ensure that security practices are integrated into all systems and processes, balancing security requirements with business agility * Develop and implement security policies, protocols, and procedures to safeguard the company's data, intellectual property, and systems from internal as well as external cyber threats * Monitor the external threat environment for emerging threats, advising relevant stakeholders, and coordinating with external agencies, such as law enforcement and other advisory bodies, to ensure that the organization maintains a strong security posture * Define and implement 1st and 3rd party risk assessment processes and controls for new technology platforms * Lead third-party security assessments for future and existing business partners * Work with cyber insurance carriers to implement long term strategic initiatives that comply with external industry/insurance requirements * Liaise with business control teams (i.e. Legal, Compliance, HR, Finance, etc.) and IT groups in the security analysis, design, and planning phases of IT and business-related projects to ensure practices are in line with organizational and regulatory policies * Partner on security tactics across DevOps, Architecture, and Engineering to ensure robust security engineering practices are in place * Establish a strong set of controls for SaaS solutions, enterprise cloud environments and cloud service provider platforms - such as Microsoft Azure, and others - and their embedded security as well as mul