Deputy CISO
Listed on 2026-09-01
-
IT/Tech
Cybersecurity, Information Security & Data Protection, IT Project Manager, IT Consultant
RK&K's Baltimore office is seeking a Deputy Chief Information Security Officer to lead the development and execution of a dedicated cybersecurity program. Reporting directly to the Chief Information Officer, the Deputy CISO will be responsible for all cybersecurity operations, cyber risk management, security architecture, incident response, governance, compliance, and the long-term strategy required to protect RK&K’s people, data, systems, clients, and business operations.
This is a foundational leadership role. This position will be responsible for building a standalone cybersecurity function from the ground up. The Deputy CISO will separate cybersecurity responsibilities from traditional IT operations, establish clear ownership of security controls and risk decisions, and create a scalable security operating model that supports RK&K’s continued growth.
The Deputy CISO will partner closely with the CIO to define cybersecurity strategy, prioritize investments, strengthen cyber resilience, and align security initiatives with business objectives. This role requires a hands‑on leader who can operate strategically while also building practical capabilities, policies, processes, tools, and teams.
Essential Functions- Serve as RK&K’s senior cybersecurity leader responsible for day-to-day cyber operations and execution of the firm’s cybersecurity roadmap.
- Partner with the CIO to develop, maintain, and execute a multi-year cybersecurity strategy aligned with RK&K’s business goals, client expectations, regulatory obligations, and risk appetite.
- Provide regular reporting to the CIO and executive leadership on security posture, risk trends, major initiatives, incidents, metrics, and investment needs.
- Advise the CIO on cybersecurity budget priorities, technology investments, staffing plans, vendor selection, and risk tradeoffs.
- Create annual and multi-year security plans with measurable goals, timelines, milestones, and success criteria.
- Represent cybersecurity in strategic technology planning, enterprise architecture decisions, digital transformation initiatives, acquisitions, client requirements, and major business initiatives.
- Develop and lead RK&K’s cyber operations program, including security monitoring, detection, response, vulnerability management, endpoint security, identity security, email security, cloud security, and threat management. Governance, Risk, and Compliance
- Develop and lead RK&K’s cybersecurity governance, risk, and compliance program.
- Lead a formal cyber risk acceptance and exception process.
- Align cybersecurity compliance with contractual, regulatory, client-driven, and industry-specific cybersecurity requirements.
- Establish security architecture principles, standards, and review processes for infrastructure, applications, cloud services, networks, endpoints, and identity platforms.
- Partner with IT operations and enterprise architecture teams to ensure security is embedded into technology design and implementation.
- Establish data protection strategies for sensitive business information, client data, employee data, financial data, intellectual property, and regulated information.
- Establish security requirements for document management, collaboration platforms, file shares, project data, client deliverables, and mobile access.
- Develop incident response policies, plans, playbooks, communication templates, escalation matrices, and decision trees.
- Conduct tabletop exercises with executive leadership, IT, legal, HR, finance, communications, and business stakeholders.
- Establish ransomware readiness plans, including containment strategies, backup validation, recovery priorities, communication plans, and decision‑making processes.
- Ensure backup environments are protected from compromise, unauthorized deletion, encryption by ransomware, and credential abuse.
- Define and maintain metrics for mean time to detect, mean time to respond, incident volume, root causes, recurring issues, and control failures.
- Bachelor’s degree in computer science,…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).