Please mention DailyRemote when applying
Match your resume skills with our AI powered skill match!
The Regional Information Security Officer acts as a second line-of-defense, overseeing security governance, policy implementation, and risk management across the region. They serve as the primary liaison between corporate security and regional business units to ensure compliance and effective incident response.
About Us:
ZEISS is a global technology and innovation leader in optics and optoelectronics. Founded in Germany in 1846, ZEISS operates in 50+ countries and offers career opportunities across engineering, manufacturing, research, sales, and technology.
As a foundation-owned company, ZEISS is committed to responsibility, quality, and continuous innovation. Employees help shape the future through cutting-edge technology and impactful work. With a strong North American presence since 1925 and 20+ locations, ZEISS partners with industries including semiconductor, automotive, biomedical research, and medical technology, and is a leading manufacturer of eyeglass lenses, camera and cinema lenses, and precision optical systems.
What’s the role?
The Regional Information Security Officer (RISO) is a key member of the ZEISS regional IT and Information Security team (CIT-R) and the liaison with Corporate Information Security (CIT-I) reporting to and representing its head in the respective ZEISS region by mirroring CIT-I organization, acting as a 2nd line-of-defense function for all information security domains.
The RISO contributes to the overall Corporate Information Security strategy and oversees the effectiveness of the 1st line-of-defense, meeting the requirements of key stakeholders such as other ZEISS Business Support functions and Business Segments - or SBUs – in the respective ZEISS region.
The RISO is an experienced information security professional, with expertise in cyber-defense and IT infrastructure and application security, as well as physical and information security, incident response, with the technical and business acumen to translate that vision into a tangible risk-based security roadmap in the respective ZEISS region.
The RISO as the CIT-I representative within the region must build strong relationships with the business and technical leadership in the region to assess the implementation of corporate information security standards by identifying gaps in security controls and advising on the appropriate execution of ZEISS information security strategy.
Sound Interesting?
Here’s what you’ll do:
Serve as an independent 2nd Line-of-defense having a clear security governance and advisory role representing Corporate Information Security (CIT-I) in the respective region.
Contribute to the designing and driving of information security policies, standards, and processes to maintain and improve the company's overall security posture from a regional perspective.
Review and interpret CSOPs, SSOPs and other InfoSec-relevant Documents/Directives for language and applicability to various scenarios within assigned region.
Direct the regional information security team to enable 1st Line-of-defense organizations (e.g., regional or local IT team, Digital Units, HR) to implement and improve the operationalization of security standards and processes.
Communicate and coordinate ZEISS information security strategy, programs, and services with a diverse group of business stakeholders.
Continuously monitor and improve security posture and maturity in the region based on new challenges or changes in the overall threat landscape, tracking and actively advising on the prioritization of the mitigating actions.
Proactively consult the 1st Line-of-defense organizations and business with respect to security-relevant topics like e.g. need-to-know-, least privilege-, security-by-design-, security-by-default principles and their application and implementation in respective endeavors, business and solution designs, developments and the like.
Ensure that M&A projects and post-merger integrations (PMIs) comply with ZEISS security standards and policies, to avoid introducing unnecessary risk to the global organization.
Review security concepts for central Business Supporting Functions (e.g., CIT, ZDP and all other BSF within CZAG) within the region and regional demands outside of the BISO responsibility.
Address incident tickets & service requests related to regional topics and not covered by other CIT-I or 1st line-of-defense teams.
Participate in the security risk management of the 2nd line-of-defense, as well as in the aggregation of security risks of the 1st line-of-defense in the respective ZEISS region.
Support the regional information security incident response in the respective ZEISS region, looking beyond the individual results to find overarching insights (both successes and shortcomings) and identifying the critical efforts, driving the sustainable and timely closure of potential gaps and vulnerabilities.
Serves as a supporting role for the security incident response process, collaborating with 1st line-of-defense teams (including CIRT/SOC, CIT, regional IT, local IT, and Business IT) to assist in preparing for, mitigating, or resolving security incidents affecting the region during the investigation and response phases.
Be the primary escalation contact for information security topics in the region.
Participate in the CIDA (Cyber Incident Decision Authority) for security incidents occurring in the respective ZEISS region.
Conduct regional investigations (e.g., eDiscovery) and digital evidence gathering and analysis, supporting the HR and Legal departments and Law Enforcement within the region.
Cooperate with the region's HR and Legal departments to set and release litigation holds on user data to support data preservation orders as needed.
Advise on, proactively consult (also in cases of unavailable central standards or workarounds) and assess information security in various scenarios to ensure security maturity, following a risk-based approach in alignment with central InfoSec functions. Provide information security thought leadership with an understanding of the overall business organization, culture, audience, and climate.
Definition, assessment, and approval authority (including veto rights in alignment with Corporate Information Security team in the case of critical risks for the entire ZEISS Group) of information security regional requirements in 1st line-of-defense processes (e.g. Corporate IT), architecture, key projects, procurement or demand process, change process, incident process, procedures, services, systems or network security mechanisms, etc.
Evaluate risks associated to key projects and proactive consulting on their mitigation, including post M&A (Mergers and Acquisitions) integrations, and defining the security requirements that must be met to maintain a consistent level of security.
Guide local information security assessment (e.g., WISA) with local and regional IT personnel, and conduct on-site visits to evaluate and ensure compliance with security standards in a governance and consulting capacity, reporting and sharing the findings and recommendations with legal entity management, BISO and 1st line-of-defense teams (e.g., regional, and local) as a corrective action plan.
Support the achievement, maintenance, and periodic assessment of regulatory certifications and compliance (e.g., CMMC, ISO27001, TISAX, HIPAA, CyberEssentials, NIS2, etc.).
Assess, provide consultancy and support for the applicability of local information security regulatory requirements in the country or region, engaging internal Legal, Compliance, and Regulatory personnel as needed.
Inform and provide oversight about legal and regulatory cybersecurity changes in the region to the head of Corporate Information Security, as well as to the required InfoSec teams.
Monitor global/regional information security status (e.g., InfoSec KPIs) to provide guidance and consulting or advice to drive the implementation and maintenance of security measures by 1st line-of-defense teams.
Support and collaborate on developing business-relevant metrics and key performance or risk indicators (KPI and KRI) supporting the measurement of information security program maturity.
Understand the business workflows and engage with business leadership and teams to identify risks and business-aware mitigation strategies.
Coordinate activities and share information with Corporate Health & Safety on physical and facility security topics and internal investigations as needed.
Provide input to Business Information Security Officers (BISO) to assist in reviewing, approving, or responding to, information security contract amendments regarding products, services, purchase orders, and security questionnaires submitted by customers and government agencies.
Identify and recommend security awareness initiatives (i.e., baseline evaluation, training, testing) in the respective ZEISS region based on KPI or job function (e.g., Finance personnel, Executives, IT administrators, etc.), helping the organization to meet the security challenges arising from the latest security threats and trends.
Support and consult on key Corporate InfoSec (CIT-I) promoted programs in the respective region.
Do you qualify?
University degree in information security, information technology, engineering, cyber security, natural sciences, technology or similar.
Minimum of 10 years of experience in information security, IT security, or a related field with proven track record in a leadership role within information security, preferably in a regional or global capacity.
Experience in a technology-driven industry, with a preference for roles in manufacturing, healthcare, or other regulated sectors.
Knowledge of the applicable international and regional regulatory requirements and standards in the areas of Cybersecurity and Data Protection.
Hands-on experience with cybersecurity frameworks (e.g., NIST, ISO 27001) and risk management methodologies.
Sound experience managing security projects from inception to completion, including the ability to prioritize tasks and manage multiple projects simultaneously.
Experience working with cross-functional teams and engaging with senior leadership to drive security initiatives and foster a culture of security awareness.
CISSP certification would be beneficial.
The annual pay range for this position is $136,000 – $170,000.
The pay offered for this role may be influenced by factors such as job location, scope of role, qualifications, education, experience, & complexity/specialization/scarcity of talent.
This position is also eligible for a performance bonus or sales commissions. ZEISS also offers robust benefits, including medical plans, retirement savings plan and paid time off.
We have amazing benefits to support you as an employee at ZEISS!
Medical
Vision
Dental
401k Matching
Employee Assistance Programs
Vacation and sick pay
The list goes on!
The above is intended to describe the general content of and requirements for this job. It is not to be construed as an exhaustive statement of requirements, duties, or responsibilities. The Company reserves the right to interpret, amend, or otherwise modify, in whole or in part, any job description at any time, at its sole discretion.
Your ZEISS Recruiting Team:
Jo Anne MittelmanZeiss provides Equal Employment Opportunity without unlawful regard to an Applicants race, color, religion, creed, sex, gender, marital status, age, national origin or ancestry, physical or mental disability, medical condition, military or veteran status, citizen status, sexual orientation, pregnancy (includes childbirth, breastfeeding or related medical condition), genetic predisposition, carrier status, gender expression or identity, including transgender identity, or any other class or characteristic protected by federal, state, or local law of the employee (or the people with whom the employee associates, including relatives and friends).
Stop the endless job search. Our AI finds and applies to the best jobs for you.
Discover remote opportunities in Software Development
Answer easy questions
200,000+ jobs across 15+ categories
Get your best job matches
Only hand-screened, legit jobs
Find a remote job faster
No ads, scams, or junk
“I was the first applicant for a remote marketing position that got listed on the company website the same day I applied. Had an interview within 48 hours!”