Vice President, Cybersecurity, Risk & Compliance (Deputy CISO)
IDC · Media · 1,001-5,000 employees
Boston, MA · Hybrid · full_time
CLI Career Level
Enterprise CISO
Moderate confidence
Opportunity Score
76/100
Above average
High confidence
Executive Fit
Sign in
Add your background to score this role against you
Career Level and Opportunity Score describe the role itself. Executive Fit is the only figure that depends on your profile.
First seen Sep 27, 2026 · Last verified yesterday · Sourced from LinkedIn — VP / Head of Security (US)
CLI Take
Scope matches the title
CLI reads this as an Enterprise CISO mandate, consistent with how the employer has titled it. Scope language covers global responsibility; multinational responsibility; board or committee interaction; executive committee exposure, and it reports to Chief Information Security Officer and carries SOC 2 and SOX accountability. The posting reads closer to an individual contributor mandate: hands-on delivery expected. Team size is not disclosed and remains the main open question before pursuing it.
Why this role scores the way it does
76/100 — above average opportunity quality. CLI reads this as an Enterprise CISO mandate. Strongest signal: Scope language covers global responsibility; multinational responsibility; board or committee interaction; executive committee exposure. Main drag on the score: The posting reads closer to an individual contributor mandate: hands-on delivery expected. 2 of 10 dimensions are not disclosed, which lowers confidence rather than the score.
Career level read
Enterprise CISO — The employer lists this as “Vice President, Cybersecurity, Risk & Compliance (Deputy CISO)”. CLI reads it as Enterprise CISO because the role shows global responsibility; multinational responsibility; board or committee interaction; executive committee exposure, reports to the CISO, board-level exposure expected.
Moderate confidence
What makes it attractive
- Scope language covers global responsibility; multinational responsibility; board or committee interaction; executive committee exposure.
- CLI's analysis of the posting describes a strategic build or transformation mandate.
- Board-level exposure is expected in the role.
- Employer profile: 1,001-5,000 employee organization, pe backed ownership, private equity.
What to probe before applying
- The posting reads closer to an individual contributor mandate: hands-on delivery expected.
Scoring components · Above average
The employer discloses a base range, but there is no comparable set to benchmark it against yet.
The role reports to the CISO.
Scope language covers global responsibility; multinational responsibility; board or committee interaction; executive committee exposure.
CLI's analysis of the posting describes a strategic build or transformation mandate.
Board-level exposure is expected in the role.
The posting reads closer to an individual contributor mandate: hands-on delivery expected.
Employer profile: 1,001-5,000 employee organization, pe backed ownership, private equity.
Team size: not disclosed.
Budget ownership: not disclosed.
No adverse signals identified in the posting.
Dimensions the employer does not disclose are excluded and the remaining weights are rebalanced, so missing information lowers confidence rather than the score.
Sign in to see how this role scores against your background, and add your career goal to evaluate career value.
Compensation
$165,800 – $290,220 base salary, disclosed by employer
The mandate
Lead the transition of security operations from manual project-based gating to a pre-approved, guardrail-driven architecture to support rapid AI and product deployment. Serve as the Deputy CISO, owning enterprise security strategy, engineering, risk management, and global compliance efforts.
Reporting to the CISO, this leader manages a global cybersecurity, risk, and compliance team. The remit covers enterprise security strategy, architecture, AI security, and compliance across global operations including the US and China.
Scope
- Reports to Chief Information Security Officer
- Board-level exposure expected
Domains and regulation
- Enterprise Security
- Product Security
- Application Security
- Cloud Security
- Infrastructure Security
- Cyber Defense
- Incident Response
- Identity
- GRC
- Third-Party Risk
- Compliance
- Privacy
- DevSecOps
- SOC 2
- SOX
- GLBA
- NYDFS Part 500
- HIPAA
- HITRUST
- NERC CIP
- FERC
- FedRAMP
- CMMC
- NIST 800-171
- DFARS
- FERPA
- CCPA
- TSA Security Directives
Requirements
Must have
- 12+ years in cybersecurity, including 5+ years in a senior leadership role.
- Experience operating as a deputy or right hand to a CISO or equivalent security executive.
- Demonstrated experience securing SaaS, cloud, and AI/LLM platforms at enterprise scale.
- Direct ownership of an enterprise technology risk management program.
- Experience owning a security engineering practice and penetration testing program.
- Bachelor’s degree in computer science, Information Security, or related field.
Preferred / bonus
- Nothing listed as optional.
Only must-have items are scored as hard constraints in Executive Fit.
Likely challenges
- Shifting from project-by-project security review to a pre-cleared, guardrail-based model.
- Securing AI platforms and pilots within a rapid 5-day intake-to-ship lifecycle.
- Managing compliance for global operations including market-specific frameworks like China's MLPS/ICP.
- Replacing per-project security gatekeeping with fast, decisive risk calls to prevent delivery bottlenecks.
Not stated in the posting: Team size not specified..
About IDC
International Data Corporation (IDC) is a global provider of market intelligence, advisory services, and events for the information technology, telecommunications, and consumer technology markets. It provides strategic insights to help IT professionals, business executives, and the investment community make fact-based decisions on technology purchases and business strategy. The company operates as a subsidiary of IDG, which was acquired by Blackstone in 2021.
- Industry
- Media
- Headcount
- 1,001-5,000 employees
- Headquarters
- Needham, MA
- Founded
- 1964
- Ownership
- Private equity backed
- Funding
- Private equity backed
- Investors
- Blackstone
Full company profile for IDC →
View original job description
Cyber Leadership Index is not the employer and does not represent candidates for these roles. Verify all details with the employer before acting.