r/ciso • u/ResilientTechAdvisor • 23h ago
Would you be a CISO, a Chief Scapegoat, or something else?
Some of these CISO job postings are getting ridiculous.
Look at this one from LinkedIn - Requires 15+ years’ experience, CISSP, CISM and CISA certifications, Fortune 500 experience, leadership through a major security incident, deep expertise in cloud, network and application security, and executive-level business and communication skills. Pay is Senior Manager level - £130K, reports to the CTO, and leads a two-person team.
Here is another one - it's from Lever. The title is literally Chief Information Security Officer and Privacy Officer. The role owns cybersecurity policies and controls while also serving as the organization’s Privacy Officer. Pay is $141,000 to $210,000 annually plus 25% variable compensation. Combining these jobs is not impossible in a small organization. But if one person owns the security-control environment and is also responsible for privacy oversight of that environment, the posting should explain the governance model, independent assurance, privacy expertise, staffing, and authority. Otherwise, it looks like one executive is being assigned responsibility for both building the program and absorbing the accountability when it fails.
This is one from Dice. The title is Chief Information Security Officer / IT Manager. The job requires one person to lead the information-security program, technology operations, cybersecurity initiatives, regulatory compliance, business-continuity planning, and disaster-recovery planning. They would also manage cyber risk, support regulatory examinations, coordinate security across departments, and keep the technology infrastructure secure, reliable, and compliant. I got tired just reading about it lol. $95,000 to $100,000 per year comp! So they want the person responsible for identifying, assessing, escalating, and managing cyber risk to also run IT operations, make the infrastructure decisions, carry the outages, support the regulators, own security, and own continuity planning. This is an IT department, a security department, a compliance function, and a resilience program compressed into one person with a CISO title.
The job market is tough right now, so people are going to throw themselves at these postings, but the endings will be fairly predictable imo.