Similar Jobs
See allFractional Chief Information Security Officer (CISO) Contract
ApprovalMax
ISO 27001
SOC 2
GDPR
CISO
ButterflyMX
US
Security
AWS
GCP
Principal Consultant, SOC Advisory, Proactive Services (Unit 42)
Palo Alto Networks
Canada
SIEM
EDR
XDR
Product Security Architect
Jobgether
Europe
Security
NIST
SOC
Director of Cloud & Infrastructure
Serco
US
AWS
Azure
CMMC
Summary:
- Black Duck seeks an experienced, transformation‑oriented VP of Cybersecurity to lead a global security program and maturity roadmap.
- This executive will partner with a third‑party security firm to build and implement a two‑year roadmap to meet and exceed NIST, GDPR, and ISO 27001 standards.
- The role combines enterprise security leadership, hands‑on program delivery, and client engagement.
Key Responsibilities:
- Deliver and maintain certifications and frameworks: lead efforts to achieve ISO 27001 certification, align to the NIST Cybersecurity Framework, and ensure GDPR compliance.
- Modernize security tooling and architecture: define global architecture for IAM, cloud security, vulnerability management, SIEM/XDR, DLP, and secure SDLC integrations; manage vendor selection and lifecycle.
- Manage external partners and audits: coordinate with the third‑party consulting firm, external auditors, penetration testing vendors, and technology providers.
Required qualifications:
- Experience: 10+ years in cybersecurity leadership, including enterprise‑scale, multi‑region transformation and certification programs.
- Certifications and frameworks: Proven track record delivering ISO 27001 certification, NIST Cybersecurity Framework implementations, and GDPR compliance.
- Technical breadth: Cloud security (AWS/Azure/GCP), IAM, secure SDLC/DevSecOps, vulnerability management, logging/SIEM/XDR, data protection.
Black Duck Software, Inc.
Black Duck Software, Inc. helps organizations build secure, high-quality software, minimizing risks while maximizing speed and productivity. With a combination of industry-leading tools, services, and expertise, Black Duck helps organizations maximize security and quality in DevSecOps and throughout the software development life cycle.