| Detail | For this role |
|---|---|
| Department | Leadership and Senior Management |
| Level | Leadership |
| Reports to | Chief Executive Officer |
| Direct reports | Security Operations Lead, GRC Lead, Application Security Lead |
| Experience | 12+ years in IT security, with 4 years leading security teams |
Chief Information Security Officer job description template
Copy this job description, replace the text in square brackets and post it on your careers page or a job portal.
Job title: Chief Information Security Officer
Department: Leadership and Senior Management
Reports to: Chief Executive Officer
Location: [City], [office, branch or site]
About the role
A Chief Information Security Officer protects the company's data and systems from attack, misuse and loss. They set the security strategy, run the security operations and incident response teams, and keep the company aligned with security standards and data protection rules. The role balances protection against the speed the business needs to move. A good CISO reduces real risk, detects and contains incidents fast, passes security audits, and builds security awareness so employees stop being the weakest link.
Key responsibilities
- Set the information security strategy and policy, and get leadership and board backing for it.
- Run security operations, monitoring and incident response, and contain incidents quickly when they happen.
- Assess risks across systems, vendors and data, and prioritise fixes by real business impact.
- Keep the company aligned with security standards and applicable data protection rules.
- Lead security audits and certifications, and close gaps before they become findings.
- Set access controls, encryption and data-handling rules, and check they are followed.
- Run security awareness training and phishing tests so employees spot and report threats.
- Review the security of new applications and vendors before they go live.
- Manage the security budget and tools, and remove tools that do not reduce real risk.
- Report the security posture, incidents and risk trends to the CEO and board.
Requirements
- Degree in computer science, IT or engineering
- CISSP, CISM or equivalent is an advantage
- Strong record in security operations and risk
- 12+ years in IT security, with 4 years leading security teams
KRAs and KPIs for a Chief Information Security Officer
Key result areas for the appraisal form, each with a KPI you can measure every month or quarter.
| Key result area | How to measure it |
|---|---|
| Incident response | Security incidents detected and contained within the agreed response times |
| Risk reduction | High-risk findings closed within the committed timelines each quarter |
| Patching | Critical patches applied across systems within the agreed window |
| Compliance | Security audits and certifications passed with no major non-conformities |
| Awareness | Phishing test failure rate reduced to the target across the company |
| Access control | Access reviews completed on time with no unauthorised standing access |
Skills and tools
Tools used day to day: SIEM tools, Vulnerability scanners, Firewalls, Endpoint protection, Identity and access tools.
Reporting line and career path
Next roles: Chief Information Officer, Chief Risk Officer
Interview questions for a Chief Information Security Officer
- Walk me through the first hours of your response to a ransomware attack on our systems.
- How do you prioritise which security risks to fix first when everything looks urgent?
- How do you secure the company without becoming the team that says no to everything?
- How would you prepare us for a security certification we have never held before?
- How do you reduce the risk that an employee clicks a phishing link and gives away credentials?
- How do you assess the security of a new vendor before we share data with them?
Managing a Chief Information Security Officer in ZeniaHR
Hire and manage your leadership and senior management team in one place
Post the role, onboard the new hire, and track attendance, leave and KRAs in ZeniaHR. Free for your first 50 employees.
Book a free demoSee pricingFrequently asked questions
What does a Chief Information Security Officer do?
A Chief Information Security Officer protects the company's data and systems. They set security strategy and policy, run monitoring and incident response, assess and reduce risk, lead security audits, control access, and train employees to spot threats. They report the security posture to the board and balance protection against the speed the business needs.
What is the difference between a CISO and a CIO?
A Chief Information Officer builds and runs IT systems so the business can work. A Chief Information Security Officer secures those systems and the data in them. The CIO is measured on availability and delivery, the CISO on risk, incidents and compliance. They work closely, and their goals sometimes pull in different directions.
What qualifications does a CISO need?
Most CISOs hold a degree in computer science, IT or engineering and years of hands-on security experience across operations, risk and compliance. Certifications like CISSP or CISM are common and often expected. What matters most is a proven record of running incident response and passing security audits.