Jobs · Information Technology · Illinois

Vice President, Information Security & Risk

Thresholds · Chicago, IL · 2 wk ago
Information Technology$155k–$175k/yrFull-time

About the role

The Vice President (VP), Information Security & Risk leads the execution and continuous improvement of Thresholds’ information security and risk management program. This role is accountable for protecting Thresholds’ information and technology assets, including digital data in the cloud, while enabling innovation, analytics, and digital transformation securely and compliantly. The VP serves as the agency’s designated security official and a trusted advisor to the Chief Information Officer and agency leaders.

Responsibilities

  • Security Operations and Execution: Manage day-to-day information security operations, including security posture and event monitoring, threat and vulnerability identification, policy violation and access control monitoring, and incident response. Oversee remediation of security issues, policy violations, and ineffective access controls, and maintain standard operating procedures for security operations. Develop and maintain security operations KPI dashboards for IT management review.
  • Application, Cloud, Digital, Infrastructure and Platform Security: Support secure implementation and operation of applications, cloud services, infrastructure, and platforms. Partner with ITS and digital teams to incorporate security controls into design, development, and deployment. Perform or coordinate risk reviews of application and digital systems and their configurations.
  • Data Security and Privacy: Manage the IT Risk Management Program using Thresholds’ risk management tool to record, assess, and track risks. Lead enterprise, regulatory, service provider, and project IT risk assessments. Support internal and external audits, regulatory reviews, and security inquiries.
  • Policy, Awareness & Documentation: Develop and enforce information security policies, standards, and procedures, including Acceptable Use Policies. Lead or oversee security awareness and training programs. Maintain and improve the Incident Response Playbook.
  • Collaboration and Continuous Improvement: Advise business units and project teams on AI security, application security, network security, IT risk, regulatory compliance, emerging threats, and data classification. Promote a practical security/risk culture that balances protection with usability and business needs. Clearly articulate risk, tradeoffs, and recommendations to influence decisions.
  • Program Leadership and Strategy Execution: Embed security-by-design principles into system implementations, vendor selection, and operational processes. Translate security strategy into actionable roadmaps and measurable outcomes. Stay current on evolving AI and cyber threats, data protection practices, and regulatory requirements.
  • Vulnerability and Threat Management: Manage the Vulnerability Management Program using Thresholds’ tools to identify, assess, and track vulnerabilities. Review threat intelligence and proactively perform remedial actions. Provide threat action summaries to ITS leadership.
  • Team Leadership and Development: Directly manage, mentor, and develop security staff, setting performance goals and supporting career growth. Provide technical guidance and decision support to the security team and cross-functional partners. Shape workforce planning, resource allocation, and budget inputs for security initiatives.

Requirements

  • Accredited bachelor’s degree in information security, Computer Science, Information Systems, or a related field (or equivalent experience).
  • Minimum of seven (7) years of progressive experience in information security, cybersecurity, data protection, or IT risk management.
  • Minimum of three (3) years of experience leading teams or major security/risk management programs.
  • Hands-on experience with security operations, incident response, risk assessments, or compliance activities.
  • Working knowledge of security and risk frameworks (e.g., NIST, ISO 27001, CIS Controls), AI security and risk management best practices, regulatory requirements (e.g., HIPAA, PCI DSS), Microsoft security tools, identity and access management, network access controls, data loss prevention, and SIEM systems.
  • Demonstrated ability to explain security risk and control matters to non-technical audiences.

Preferred Qualifications

  • Experience supporting cloud environments, SaaS platforms, or digital transformation initiatives.
  • Experience in a mid-sized, non-profit and/or regulated organization.
  • Familiarity with data analytics and reporting tools.
  • Familiarity with computer forensic techniques.
  • Demonstrated experience partnering with and influencing senior leaders.

Skills

  • Security certifications (e.g., CISSP, CISM, Security+, CCSP).
  • Microsoft certification.
  • Strong analytical and problem-solving skills.
  • Practical, risk-based approach to security.
  • Clear interpersonal and communication skills, both written and oral.
  • Policy writing and scripting (preferably PowerShell).
  • Collaboration and relationship management.
  • Attention to detail and follow-through.
  • High integrity and discretion.
  • Project management and people management skills.
  • Strategic execution and program ownership.
  • Effective cross-functional collaboration.

Benefits

  • Competitive pay – Salary Range: $155,000.00 - $175,000.00 annually.
  • Generous PTO (9 federal holidays, 8 days of sick leave, 15-22 days personal and vacation).
  • Dental insurance, vision insurance, and a choice of 3 medical insurance plans.
  • 403(b) retirement plan with 3% employer match.
  • Robust employee assistance program (EAP).

Thresholds is a mission-driven agency committed to fostering an inclusive environment where all employees feel valued and respected. Recognized as a Chicago Tribune Top Workplace and one of Chicago’s 101 Best & Brightest Companies to Work For.

Similar jobs