← All roles
VP

Vice President, Cybersecurity, Risk & Compliance (Deputy CISO)

IDC · Media · 1,001-5,000 employees

Boston, MA · Hybrid · full_time

CLI Career Level

Enterprise CISO

Moderate confidence

Opportunity Score

76/100

Above average

High confidence

Executive Fit

Sign in

Add your background to score this role against you

Career Level and Opportunity Score describe the role itself. Executive Fit is the only figure that depends on your profile.

First seen Sep 27, 2026 · Last verified yesterday · Sourced from LinkedIn — VP / Head of Security (US)

CLI Take

Scope matches the title

CLI reads this as an Enterprise CISO mandate, consistent with how the employer has titled it. Scope language covers global responsibility; multinational responsibility; board or committee interaction; executive committee exposure, and it reports to Chief Information Security Officer and carries SOC 2 and SOX accountability. The posting reads closer to an individual contributor mandate: hands-on delivery expected. Team size is not disclosed and remains the main open question before pursuing it.

Why this role scores the way it does

76/100 — above average opportunity quality. CLI reads this as an Enterprise CISO mandate. Strongest signal: Scope language covers global responsibility; multinational responsibility; board or committee interaction; executive committee exposure. Main drag on the score: The posting reads closer to an individual contributor mandate: hands-on delivery expected. 2 of 10 dimensions are not disclosed, which lowers confidence rather than the score.

Career level read

Enterprise CISO — The employer lists this as “Vice President, Cybersecurity, Risk & Compliance (Deputy CISO)”. CLI reads it as Enterprise CISO because the role shows global responsibility; multinational responsibility; board or committee interaction; executive committee exposure, reports to the CISO, board-level exposure expected.

Moderate confidence

What makes it attractive

  • Scope language covers global responsibility; multinational responsibility; board or committee interaction; executive committee exposure.
  • CLI's analysis of the posting describes a strategic build or transformation mandate.
  • Board-level exposure is expected in the role.
  • Employer profile: 1,001-5,000 employee organization, pe backed ownership, private equity.

What to probe before applying

  • The posting reads closer to an individual contributor mandate: hands-on delivery expected.

Scoring components · Above average

Compensation versus comparable roles55 · weight 15%

The employer discloses a base range, but there is no comparable set to benchmark it against yet.

Reporting level57 · weight 12%

The role reports to the CISO.

Functional and geographic scope100 · weight 12%

Scope language covers global responsibility; multinational responsibility; board or committee interaction; executive committee exposure.

Quality of the mandate100 · weight 12%

CLI's analysis of the posting describes a strategic build or transformation mandate.

Executive and board exposure100 · weight 10%

Board-level exposure is expected in the role.

Role authority versus title25 · weight 10%

The posting reads closer to an individual contributor mandate: hands-on delivery expected.

Company scale and trajectory83 · weight 10%

Employer profile: 1,001-5,000 employee organization, pe backed ownership, private equity.

Team ownershipNot disclosed · excluded from the score

Team size: not disclosed.

Budget ownershipNot disclosed · excluded from the score

Budget ownership: not disclosed.

Risk signals100 · weight 5%

No adverse signals identified in the posting.

Dimensions the employer does not disclose are excluded and the remaining weights are rebalanced, so missing information lowers confidence rather than the score.

Sign in to see how this role scores against your background, and add your career goal to evaluate career value.

Compensation

$165,800 – $290,220 base salary, disclosed by employer

Sample size not yet sufficient for a market comparison

See the full benchmark bands by level and region

The mandate

Lead the transition of security operations from manual project-based gating to a pre-approved, guardrail-driven architecture to support rapid AI and product deployment. Serve as the Deputy CISO, owning enterprise security strategy, engineering, risk management, and global compliance efforts.

Reporting to the CISO, this leader manages a global cybersecurity, risk, and compliance team. The remit covers enterprise security strategy, architecture, AI security, and compliance across global operations including the US and China.

Scope

  • Reports to Chief Information Security Officer
  • Board-level exposure expected

Domains and regulation

  • Enterprise Security
  • Product Security
  • Application Security
  • Cloud Security
  • Infrastructure Security
  • Cyber Defense
  • Incident Response
  • Identity
  • GRC
  • Third-Party Risk
  • Compliance
  • Privacy
  • DevSecOps
  • SOC 2
  • SOX
  • GLBA
  • NYDFS Part 500
  • HIPAA
  • HITRUST
  • NERC CIP
  • FERC
  • FedRAMP
  • CMMC
  • NIST 800-171
  • DFARS
  • FERPA
  • CCPA
  • TSA Security Directives

Requirements

Must have

  • 12+ years in cybersecurity, including 5+ years in a senior leadership role.
  • Experience operating as a deputy or right hand to a CISO or equivalent security executive.
  • Demonstrated experience securing SaaS, cloud, and AI/LLM platforms at enterprise scale.
  • Direct ownership of an enterprise technology risk management program.
  • Experience owning a security engineering practice and penetration testing program.
  • Bachelor’s degree in computer science, Information Security, or related field.

Preferred / bonus

  • Nothing listed as optional.

Only must-have items are scored as hard constraints in Executive Fit.

Likely challenges

Not stated in the posting: Team size not specified..

About IDC

International Data Corporation (IDC) is a global provider of market intelligence, advisory services, and events for the information technology, telecommunications, and consumer technology markets. It provides strategic insights to help IT professionals, business executives, and the investment community make fact-based decisions on technology purchases and business strategy. The company operates as a subsidiary of IDG, which was acquired by Blackstone in 2021.

Industry
Media
Headcount
1,001-5,000 employees
Headquarters
Needham, MA
Founded
1964
Ownership
Private equity backed
Funding
Private equity backed
Investors
Blackstone

Full company profile for IDC →

View original job description
About The Role & TeamIDC's CIO organization is shifting from project-by-project security review to a pre-cleared, guardrail-based model so that new technology — including AI pilots — can ship in days instead of months. This role owns that shift: building the security architecture, controls, and governance that let the business move fast without moving recklessly.Position SummaryThe VP, Cybersecurity, Risk & Compliance serves as Deputy CISO, leading enterprise security strategy, architecture, and operations for IDC day to day and standing in for the CISO on internal leadership, vendor, and operational matters. The role carries direct accountability for keeping pace with an accelerating delivery model across infrastructure, applications, and AI/automation initiatives. This is a hands-on leadership role: the VP sets the security roadmap, runs the team, and personally removes the friction that slows delivery — replacing per-project security gatekeeping with pre-approved patterns, standing guardrails, and fast, decisive risk calls.What You’ll DoStrategy, architecture, and governance Own the enterprise cybersecurity strategy and multi-year architecture roadmap, aligned to business and AI/automation priorities. Design and maintain a library of pre-approved security patterns and guardrails so new projects and pilots can launch without a bespoke review cycle. Sit on and support the AI Governance Council as the security authority, pre-clearing model, data, and vendor patterns rather than gating individual pilots AI and platform security. Lead security for IDC's AI platforms and pilots — prompt-injection defense, runtime AI protection, agentic SOC coverage, PII detection, and red-team/canary testing. Partner with the AI & Automation team to build security into the 5-day intake-to-ship pilot lifecycle from day one, not as a late-stage checkpoint. Own identity and access management, zero-trust architecture, and SSO/SAML standards across the enterprise application portfolio Security engineering Own the security engineering function, including Quanta Cyber Guidance — the secure-by-design reference architecture and build standards for IDC's Quanta platform — keeping it current as Quanta expands into new markets. Own the enterprise penetration testing program (internal, external, and third-party engagements) across Quanta and the broader application portfolio, tracking every finding through to verified remediation. Build and maintain secure coding standards and embedded security tooling (SAST/DAST, dependency and vulnerability scanning) so engineering teams get fast, actionable findings inside their own pipelinesEnterprise risk management Own the enterprise technology risk register, driving risk identification, quantification, and mitigation tracking across infrastructure, applications, and AI initiatives. Set risk appetite and tolerance thresholds with the CIO and executive leadership, and make the fast, decisive accept/mitigate/escalate calls that keep pre-cleared pilots moving. Author and maintain enterprise security and risk policies, standards, and control frameworks, ensuring consistent enforcement across a global organization Compliance and audit. Drive certification and regulatory compliance programs (SOC 2 Type II, ISO 27001, GDPR, and market-specific frameworks such as MLPS/ICP for China operations) on defined timelines. Own the enterprise audit calendar, serving as the primary liaison to internal and external auditors and ensuring evidence and control documentation are always audit-ready. Manage vendor security and compliance risk assessments against committed SLAs so third-party review never becomes the delivery bottleneck Security operations. Own incident response, threat detection, and security logging/monitoring (SIEM, cloud-native logging) across the global estateLeadership and reporting Serve as Deputy CISO, acting with full authority on the CISO's behalf across day-to-day security, risk, and compliance decisions, and standing in for the CISO in their absence. Build, lead, and develop a global cybersecurity, risk, and compliance team, including succession planning for key roles. Partner with the CISO to prepare risk posture, compliance status, and audit program health for the CIO, executive leadership, and Audit Committee, and represent the program directly when the CISO is unavailable. Partner with Infrastructure, Applications, and Data leadership to embed security and compliance checkpoints directly into CI/CD and rapid deployment pipelines. What You Bring 12+ years in cybersecurity, including 5+ years in a senior leadership role, owning strategy, architecture, risk, and a team. Experience operating as a deputy or right hand to a CISO or equivalent security executive, including acting with delegated authority in their absence. Demonstrated experience securing SaaS, cloud, and AI/LLM platforms at enterprise scale. Direct ownership of an enterprise technology risk management program, including risk registers, risk quantification, and executive/board-level risk reporting. Working knowledge of major compliance frameworks (SOC 2, ISO 27001, GDPR); experience with China-specific frameworks (MLPS/ICP) a strong plus Hands-on experience with modern threat defense tooling, zero-trust architecture, and identity management Experience owning a security engineering practice, including secure architecture guidance for a core platform and a penetration testing program through remediation. A track record of balancing security rigor with delivery speed in agile, DevOps, or CI/CD Bachelor’s degree in computer science, Information Security, or related field; CISSP, CISM, or equivalent certification preferredPreferred Qualifications Direct experience securing generative AI or LLM-based products, including runtime defense and agentic system monitoring. Experience in a multinational, research, or information-services business Experience designing a governance model that pre-clears risk categories rather than reviewing every project individually. Exposure to global regulatory environments, including operating in or adjacent to the Chinese market. Experience with GRC platforms and leading external audit engagements through to clean opinions Success looks like (first 12 months) A published library of pre-approved security patterns is in active use, measurably reducing time-to-ship for new pilots and applications. SOC 2 Type II and ISO 27001 programs are on track against agreed timelines with no material findings. AI pilots ship through the standard lifecycle with security built in from intake, not bolted on before launch. Vendor risk reviews consistently meet SLA, and the team is recognized as an enabler of delivery rather than a checkpoint. The enterprise risk register is current and actively used to drive prioritization, with clear owners and mitigation timelines for every open risk Why This Role Stands Out At IDC, your work helps shape how the world understands technology and where it goes next. You collaborate with curious, high-caliber colleagues who value rigor, integrity, and shared success. As the premier global provider of trusted technology intelligence, IDC equips business and technology leaders with the evidence they need to make confident decisions. Our insights inform strategy, investment, and innovation across industries and regions.Recognized by IIAR as Analyst Firm of the Year for five consecutive years, IDC sets the standard for credibility and impact. With more than 1,000 analysts worldwide and a truly global perspective, we combine deep expertise with practical relevance. Here, your ideas matter, your voice is heard, and your contributions provide the insights leaders rely on every day. It is meaningful work, backed by a culture that supports growth, collaboration, and long-term career development with a globally respected brand.What We Offer 15 vacation days (prorated based on start date) 12 company-paid holidays 6 paid sick days (prorated based on start date; may vary by state) Medical, dental, and vision coverage 2 floating holidays (prorated based on start date) 1 volunteer day 401(k) company match (IDC matches 3% on the first 6% of employee contributions) Company-paid short-term disability Company-paid life insurance Company-paid parental leave Compensation TransparencyAt IDC, we are committed to fair and equitable pay practices. Employees are compensated equitably for their work, aligned with their skills and experience. Salary and incentive structures are determined through a rigorous process that considers experience, education, certifications, role-specific requirements, internal equity, and verified U.S. market data from an independent third-party partner.The base salary range for this role is $165,800 USD – $290,220 USD annually, depending on location and experience. This role is also eligible for a variable incentive of up to 25% of base salary.If this role relocates to a different country, the salary range will be updated to reflect that country's range, rather than a currency conversion of the original range.Equal Opportunity EmployerIDC is committed to providing equal employment opportunities for all qualified persons. Employment eligibility verification required. We participate in E-Verify.IDC is currently able to employ remote workers in the following states: Arizona (AZ), California (CA), Colorado (CO), Connecticut (CT), Washington D.C. (DC), Florida (FL), Georgia (GA), Illinois (IL), Indiana (IN), Kansas (KS), Massachusetts (MA), Maryland (MD), Maine (ME), Michigan (MI), Minnesota (MN), Missouri (MO), Mississippi (MS), North Carolina (NC), New Hampshire (NH), New Jersey (NJ), New York (NY), Ohio (OH), Oregon (OR), Pennsylvania (PA), Rhode Island (RI), South Carolina (SC), Tennessee (TN), Texas (TX), Utah (UT), Virginia (VA), Vermont (VT), Washington (WA), and Wisconsin (WI).

Cyber Leadership Index is not the employer and does not represent candidates for these roles. Verify all details with the employer before acting.