×
Register Here to Apply for Jobs or Post Jobs. X

Vice President, Cybersecurity, Risk & Compliance; Deputy CISO

Job in Boston, Suffolk County, Massachusetts, 02298, USA
Listing for: IDC Corporate
Full Time position
Listed on 2026-09-28
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection
Salary/Wage Range or Industry Benchmark: 165800 - 290220 USD Yearly USD 165800.00 290220.00 YEAR
Job Description & How to Apply Below

Overview About the Role & Team

IDC's CIO organization is shifting from project-by-project security review to a pre-cleared, guardrail-based model so that new technology — including AI pilots — can ship in days instead of months. This role owns that shift: building the security architecture, controls, and governance that let the business move fast without moving recklessly.

Position summary

The VP, Cybersecurity, Risk & Compliance serves as Deputy CISO, leading enterprise security strategy, architecture, and operations for IDC day to day and standing in for the CISO on internal leadership, vendor, and operational matters. The role carries direct accountability for keeping pace with an accelerating delivery model across infrastructure, applications, and AI/automation initiatives.

This is a hands-on leadership role: the VP sets the security roadmap, runs the team, and personally removes the friction that slows delivery — replacing per-project security gatekeeping with pre-approved patterns, standing guardrails, and fast, decisive risk calls.

What You’ll Do Strategy, architecture, and governance
  • Own the enterprise cybersecurity strategy and multi-year architecture roadmap, alignedtobusiness and AI/automation priorities.
  • Design and maintain a library of pre-approved security patterns and guardrails so new projects and pilots can launch without a bespoke review cycle.
  • Sit on and support the AI Governance Council as the security authority, pre-clearing model, data, and vendor patterns rather than gating individual pilotsAI and platform security.
  • Lead security for IDC's AI platforms and pilots — prompt-injection defense, runtime AI protection, agentic SOC coverage, PII detection, and red-team/canary testing.
  • Partner with the AI & Automation team to build security into the 5-day intake-to-ship pilot lifecycle from day one, not as a late-stage checkpoint.
  • Own identity and access management, zero-trust architecture, and SSO/SAML standards across the enterprise application portfolio
  • Security engineering

    Own the security engineering function, including Quanta Cyber Guidance — the secure-by-design reference architecture and build standards for IDC's Quanta platform — keeping it current as Quanta expands into new markets.
  • Own the enterprise penetration testing program (internal, external, and third-party engagements) across Quanta and the broader application portfolio, tracking every finding through to verified remediation.
  • Build and maintain secure coding standards and embedded security tooling (SAST/DAST,dependency and vulnerability scanning) so engineering teams get fast, actionable findings inside their own pipelines
Enterprise risk management
  • Own the enterprise technology risk register, driving risk identification, quantification, and mitigation tracking across infrastructure, applications, and AI initiatives.
  • Set risk appetite and tolerance thresholds with the CIO and executive leadership, and make the fast, decisive accept/mitigate/escalate calls that keep pre-cleared pilots moving.
  • Author and maintain enterprise security and risk policies, standards, and control frameworks, ensuring consistent enforcement across a global organization

    Compliance and audit.
  • Drive certification and regulatory compliance programs (SOC 2 Type II, ISO 27001, GDPR, and market-specific frameworks such as MLPS/ICP for China operations) on defined timelines.
  • Own the enterprise audit calendar, serving as the primary liaison to internal and external auditors and ensuring evidence and control documentation are always audit-ready.
  • Manage vendor security and compliance risk assessments against committed SLAs so third-party review never becomes the delivery bottleneck Security operations.
  • Own incident response, threat detection, and security…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary