Group Chief Information Security Officer
Listed on 2026-09-01
-
IT/Tech
Cybersecurity, Information Security & Data Protection, IT Consultant, IT Project Manager
Group Chief Information Security Officer Organization:
Location:
New York, NY
Description:Job Summary
The Chief Information Security Officer (CISO) will lead and oversee the Information Security program across the entire organization. The role will be responsible for developing, implementing, and maintaining a unified enterprise security strategy that ensures the confidentiality, integrity, and availability of the company’s information assets, platforms, infrastructure, and customer data across all business operations.
As the organization continues to modernize its retail, digital, cloud, and enterprise technology platforms, we require a transformational security leader capable of driving the next phase of cybersecurity maturity across the group. This role is significantly broader than traditional cybersecurity operations and compliance management. The CISO will play a critical leadership role in helping the organization securely navigate large-scale technology transformation, AI adoption, cloud modernization, evolving regulatory requirements, and an increasingly sophisticated global threat landscape.
The CISO will be responsible for establishing and leading a group-wide cybersecurity strategy across both US and UK operations, driving consistency in governance, policy, standards, risk management, incident response, and operational security practices. This includes developing enterprise security standards, modernizing security architecture, implementing Zero Trust principles, strengthening cloud and identity security, improving business resilience, and reducing legacy technology and operational risk across the environment.
Cybersecurity has evolved far beyond traditional perimeter defense and audit-driven compliance programs. We now face a rapidly changing threat environment driven by AI-enabled attacks, ransomware, cloud complexity, third-party supply chain risk, increasing regulatory scrutiny, and growing operational dependence on digital platforms. As a result, the CISO must operate not only as a security leader, but also as a strategic business partner and an agent for transformation.
This role will require close collaboration with executive leadership, technology teams, legal, compliance, operations, and external partners to ensure security is embedded into the organization’s strategy and business operations. Given the strategic importance of cybersecurity and enterprise risk management to the organization, the CISO role will maintain a regular reporting cadence with the Board Risk Committee and will be responsible for providing ongoing updates related to cybersecurity posture, operational risk, regulatory compliance, major initiatives, emerging threats, and overall enterprise resilience.
WhatYou DoGlobal Security Strategy
- Define and execute a unified cybersecurity strategy that supports the business objectives of both B&N and Waterstones.
- Lead the development and implementation of security policies, standards, and procedures that align with local regulations and best practices.
- Serve as a trusted advisor to executive leadership and Board of Directors for both organizations.
- Lead the enterprise cybersecurity incident response and crisis management program, coordinating cross-functional response activities during major cyber incidents, ransomware events, operational disruptions, and data breaches.
- Act as the primary technical contact with external crisis response agencies, cyber insurance providers, legal counsel, forensic investigators, regulators, and law enforcement agencies during significant cybersecurity incidents.
- Drive the continuous maturation of the organization’s cyber resilience capabilities, including incident response planning, ransomware preparedness, disaster recovery, business continuity, tabletop exercises, and enterprise recovery strategies.
- Establish and maintain enterprise-wide cyber incident response standards, escalation procedures, communication protocols, and post-incident review processes to improve organizational readiness and operational resilience.
- Direct 24/7 global security operations, including monitoring, detection, and…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).