For Employers

IDC Research Inc.

Vice President, Cybersecurity, Risk & Compliance (Deputy CISO)

Posted 2 hours ago
$165K - $290K per year
10+ years experience
Apply Now

Please mention DailyRemote when applying

?
Resume Match Score

See how much of this job your resume covers, and what’s missing.

Want a recruiter to go through it line by line?

Get professional review

Create a cover letter for this job

Upload your resume and we draft a letter for this exact role, tailored to what it asks for.

  • Tailored to this role
  • Based on your resume
  • Fully editable
AI Summary

The VP, Cybersecurity, Risk & Compliance serves as Deputy CISO, leading enterprise security strategy, architecture, and operations while enabling rapid technology delivery. They are responsible for building security guardrails, managing AI governance, and overseeing risk management and compliance programs across the global organization.

Overview

About the Role & Team

IDC's CIO organization is shifting from project-by-project security review to a pre-cleared, guardrail-based model so that new technology — including AI pilots — can ship in days instead of months. This role owns that shift: building the security architecture, controls, and governance that let the business move fast without moving recklessly.

 

Position summary

The VP, Cybersecurity, Risk & Compliance serves as Deputy CISO, leading enterprise security strategy, architecture, and operations for IDC day to day and standing in for the CISO on internal leadership, vendor, and operational matters. The role carries direct accountability for keeping pace with an accelerating delivery model across infrastructure, applications, and AI/automation initiatives. This is a hands-on leadership role: the VP sets the security roadmap, runs the team, and personally removes the friction that slows delivery — replacing per-project security gatekeeping with pre-approved patterns, standing guardrails, and fast, decisive risk calls.

 

What You’ll Do

 

Strategy, architecture, and governance

  • Own the enterprise cybersecurity strategy and multi-year architecture roadmap, aligned tobusiness and AI/automation priorities.
  • Design and maintain a library of pre-approved security patterns and guardrails so new projects and pilots can launch without a bespoke review cycle.
  • Sit on and support the AI Governance Council as the security authority, pre-clearing model, data, and vendor patterns rather than gating individual pilotsAI and platform security.
  • Lead security for IDC's AI platforms and pilots — prompt-injection defense, runtime AI protection, agentic SOC coverage, PII detection, and red-team/canary testing.
  • Partner with the AI & Automation team to build security into the 5-day intake-to-ship pilot lifecycle from day one, not as a late-stage checkpoint.
  • Own identity and access management, zero-trust architecture, and SSO/SAML standards across the enterprise application portfolio
  • Security engineeringOwn the security engineering function, including Quanta Cyber Guidance — the secure-by-design reference architecture and build standards for IDC's Quanta platform — keeping it current as Quanta expands into new markets.
  • Own the enterprise penetration testing program (internal, external, and third-party engagements) across Quanta and the broader application portfolio, tracking every finding through to verified remediation.
  • Build and maintain secure coding standards and embedded security tooling (SAST/DAST,dependency and vulnerability scanning) so engineering teams get fast, actionable findings inside their own pipelines

Enterprise risk management

  • Own the enterprise technology risk register, driving risk identification, quantification, andmitigation tracking across infrastructure, applications, and AI initiatives.
  • Set risk appetite and tolerance thresholds with the CIO and executive leadership, and make the fast, decisive accept/mitigate/escalate calls that keep pre-cleared pilots moving.
  • Author and maintain enterprise security and risk policies, standards, and control frameworks, ensuring consistent enforcement across a global organizationCompliance and audit.
  • Drive certification and regulatory compliance programs (SOC 2 Type II, ISO 27001, GDPR, and market-specific frameworks such as MLPS/ICP for China operations) on defined timelines.
  • Own the enterprise audit calendar, serving as the primary liaison to internal and external auditors and ensuring evidence and control documentation are always audit-ready.
  • Manage vendor security and compliance risk assessments against committed SLAs so third-party review never becomes the delivery bottleneck Security operations.
  • Own incident response, threat detection, and security logging/monitoring (SIEM, cloud-native logging) across the global estate

Leadership and reporting

  • Serve as Deputy CISO, acting with full authority on the CISO's behalf across day-to-day security, risk, and compliance decisions, and standing in for the CISO in their absence.
  • Build, lead, and develop a global cybersecurity, risk, and compliance team, including succession planning for key roles.
  • Partner with the CISO to prepare risk posture, compliance status, and audit program health for the CIO, executive leadership, and Audit Committee, and represent the program directly when the CISO is unavailable.
  • Partner with Infrastructure, Applications, and Data leadership to embed security and compliance checkpoints directly into CI/CD and rapid deployment pipelines.

 

What You Bring

 

  • 12+ years in cybersecurity, including 5+ years in a senior leadership role, owning strategy,architecture, risk, and a team.
  • Experience operating as a deputy or right hand to a CISO or equivalent security executive,including acting with delegated authority in their absence.
  • Demonstrated experience securing SaaS, cloud, and AI/LLM platforms at enterprise scale.
  • Direct ownership of an enterprise technology risk management program, including risk registers, risk quantification, and executive/board-level risk reporting.
  • Working knowledge of major compliance frameworks (SOC 2, ISO 27001, GDPR); experience with China-specific frameworks (MLPS/ICP) a strong plus
  • Hands-on experience with modern threat defense tooling, zero-trust architecture, and identity management
  • Experience owning a security engineering practice, including secure architecture guidance for a core platform and a penetration testing program through remediation.
  • A track record of balancing security rigor with delivery speed in agile, DevOps, or CI/CD
  • Bachelor’s degree in computer science, Information Security, or related field; CISSP, CISM,  or equivalent certification preferred

Preferred qualifications

  • Direct experience securing generative AI or LLM-based products, including runtime defense and agentic system monitoring.
  • Experience in a multinational, research, or information-services business
  • Experience designing a governance model that pre-clears risk categories rather than reviewing every project individually.
  • Exposure to global regulatory environments, including operating in or adjacent to the Chinese market.
  • Experience with GRC platforms and leading external audit engagements through to clean opinions

Success looks like (first 12 months)

  • A published library of pre-approved security patterns is in active use, measurably reducingtime-to-ship for new pilots and applications.
  • SOC 2 Type II and ISO 27001 programs are on track against agreed timelines with no material findings.
  • AI pilots ship through the standard lifecycle with security built in from intake, not bolted on before launch.
  • Vendor risk reviews consistently meet SLA, and the team is recognized as an enabler of delivery rather than a checkpoint.
  • The enterprise risk register is current and actively used to drive prioritization, with clear owners and mitigation timelines for every open risk

Why This Role Stands Out

At IDC, your work helps shape how the world understands technology and where it goes next. You collaborate with curious, high-caliber colleagues who value rigor, integrity, and shared success. As the premier global provider of trusted technology intelligence, IDC equips business and technology leaders with the evidence they need to make confident decisions. Our insights inform strategy, investment, and innovation across industries and regions.

 

Recognized by IIAR as Analyst Firm of the Year for five consecutive years, IDC sets the standard for credibility and impact. With more than 1,000 analysts worldwide and a truly global perspective, we combine deep expertise with practical relevance. Here, your ideas matter, your voice is heard, and your contributions provide the insights leaders rely on every day. It is meaningful work, backed by a culture that supports growth, collaboration, and long-term career development with a globally respected brand.

 

What We Offer

  • 15 vacation days (prorated based on start date)
  • 12 company-paid holidays
  • 6 paid sick days (prorated based on start date; may vary by state)
  • Medical, dental, and vision coverage
  • 2 floating holidays (prorated based on start date)
  • 1 volunteer day
  • 401(k) company match (IDC matches 3% on the first 6% of employee contributions)
  • Company-paid short-term disability
  • Company-paid life insurance
  • Company-paid parental leave

Compensation Transparency

At IDC, we are committed to fair and equitable pay practices. Employees are compensated equitably for their work, aligned with their skills and experience. Salary and incentive structures are determined through a rigorous process that considers experience, education, certifications, role-specific requirements, internal equity, and verified U.S. market data from an independent third-party partner.The base salary range for this role is $165,800 USD – $290,220 USD annually, depending on location and experience. This role is also eligible for a variable incentive of up to 25% of base salary.

If this role relocates to a different country, the salary range will be updated to reflect that country's range, rather than a currency conversion of the original range.Equal Opportunity Employer

IDC is committed to providing equal employment opportunities for all qualified persons. Employment eligibility verification required. We participate in E-Verify.

 IDC is currently able to employ remote workers in the following states: Arizona (AZ), California (CA), Colorado (CO), Connecticut (CT), Washington D.C. (DC), Florida (FL), Georgia (GA), Illinois (IL), Indiana (IN), Kansas (KS), Massachusetts (MA), Maryland (MD), Maine (ME), Michigan (MI), Minnesota (MN), Missouri (MO), Mississippi (MS), North Carolina (NC), New Hampshire (NH), New Jersey (NJ), New York (NY), Ohio (OH), Oregon (OR), Pennsylvania (PA), Rhode Island (RI), South Carolina (SC), Tennessee (TN), Texas (TX), Utah (UT), Virginia (VA), Vermont (VT), Washington (WA), and Wisconsin (WI).

#LI-ED1

#LI-HR1#LI-JF1#LI-Remote#LI-Hybrid#LI-Onsite

Automatically Apply to the Best Remote Jobs

Stop the endless job search. Our AI finds and applies to the best jobs for you.

Try it Now
Keep looking

Similar Jobs

See all Remote Legal jobs →

Legal Operations Manager

Full Time Armenia Legal

Claims Adjudicator (Remote - WI only)

Full Time United States Legal

Associate General Counsel & Privacy Officer (Remote First)

Full Time Canada 175K - 225K per year Legal

Associate PIP Claims Rep (Remote)

Full Time United States Legal

Associate Director, Compliance

Full Time United States Legal

Legal Process Server - Oklahoma

Freelance United States Legal
Apply Now

Personalize your Remote Job Search in 3 Easy Steps!

Featuring 219,353+ Jobs in Legal

Answer easy questions

Answer easy questions

219,353+ jobs across 15+ categories

Get your best job matches

Get your best job matches

Only hand-screened, legit jobs

Find a remote job faster

Find a remote job faster

No ads, scams, or junk

“I was the first applicant for a remote marketing position that got listed on the company website the same day I applied. Had an interview within 48 hours!”

Sarah J. — Sarah J. · Marketing Manager ★★★★★ Verified