← All roles
Deputy CISO

Vice President, Deputy CISO

Arctic Wolf · Software · 1,001-5,000 employees

Pleasant Grove, UT · Onsite · full_time

CLI Career Level

Enterprise CISO

Moderate confidence

Opportunity Score

89/100

Strong

High confidence

Executive Fit

Sign in

Add your background to score this role against you

Career Level and Opportunity Score describe the role itself. Executive Fit is the only figure that depends on your profile.

First seen Aug 20, 2026 · Last verified 2 hours ago · Sourced from LinkedIn — VP / Head of Security (US)

CLI Take

Scope matches the title

CLI reads this as an Enterprise CISO mandate, consistent with how the employer has titled it. CLI's analysis of the posting describes a strategic build or transformation mandate, and it reports to Chief Information Security Officer and carries board-level exposure. Total compensation and team size are not disclosed and remain the main open questions before pursuing it.

Why this role scores the way it does

89/100 — strong opportunity quality. CLI reads this as an Enterprise CISO mandate. Strongest signal: CLI's analysis of the posting describes a strategic build or transformation mandate. 3 of 10 dimensions are not disclosed, which lowers confidence rather than the score.

Career level read

Enterprise CISO — The employer lists this as “Vice President, Deputy CISO”. CLI reads it as Enterprise CISO because the role shows global responsibility; multinational responsibility; executive committee exposure, reports to the CISO, board-level exposure expected.

Moderate confidence

What makes it attractive

  • CLI's analysis of the posting describes a strategic build or transformation mandate.
  • Scope language covers global responsibility; multinational responsibility; executive committee exposure.
  • Board-level exposure is expected in the role.
  • The role carries more scope than the employer's title suggests.
  • Employer profile: 1,001-5,000 employee organization, vc backed ownership, series d plus, revenue 250m 1b.

What to probe before applying

  • No material concerns identified in the posting.

Scoring components · Strong

Compensation versus comparable rolesNot disclosed · excluded from the score

Compensation is not disclosed and there is no comparable set to place it against.

Reporting level57 · weight 12%

The role reports to the CISO.

Functional and geographic scope93 · weight 12%

Scope language covers global responsibility; multinational responsibility; executive committee exposure.

Quality of the mandate100 · weight 12%

CLI's analysis of the posting describes a strategic build or transformation mandate.

Executive and board exposure100 · weight 10%

Board-level exposure is expected in the role.

Role authority versus title100 · weight 10%

The role carries more scope than the employer's title suggests.

Company scale and trajectory83 · weight 10%

Employer profile: 1,001-5,000 employee organization, vc backed ownership, series d plus, revenue 250m 1b.

Team ownershipNot disclosed · excluded from the score

Team size: not disclosed.

Budget ownershipNot disclosed · excluded from the score

Budget ownership: not disclosed.

Risk signals100 · weight 5%

No adverse signals identified in the posting.

Dimensions the employer does not disclose are excluded and the remaining weights are rebalanced, so missing information lowers confidence rather than the score.

Sign in to see how this role scores against your background, and add your career goal to evaluate career value.

Compensation

No compensation disclosed and insufficient comparable data to estimate.

Sample size not yet sufficient for a market comparison

Directly manages the combined budget for security engineering, SecOps, and GRC.

See the full benchmark bands by level and region

The mandate

The Deputy CISO will serve as the primary people manager for Security Engineering, SecOps, and GRC, with full accountability for strategy, staffing, and budget. This leader is tasked with protecting enterprise assets while bridging technical security functions with business risk management and regulatory compliance.

Reporting to the CISO, this VP manages the Security Engineering, SecOps, and GRC functions. The role carries full accountability for the strategy, staffing, performance, and budget of these combined security units.

Scope

  • Reports to Chief Information Security Officer
  • Board-level exposure expected

Domains and regulation

  • Enterprise Security
  • GRC
  • Cyber Defense
  • Incident Response
  • Infrastructure Security
  • Third-Party Risk
  • Privacy
  • DevSecOps
  • SOC 2
  • PCI DSS
  • CCPA
  • NIST 800-171

Requirements

Must have

  • 8+ years of leadership experience directly managing security engineering, security operations, or GRC teams.
  • 10+ years of progressive information security experience spanning both technical security engineering and GRC.
  • Demonstrated experience building and leading enterprise risk management programs, including risk assessment and reporting.
  • Experience managing SOC 2, ISO 27001, or similar certification and audit processes from initiation through completion.
  • A Bachelor’s Degree in Computer Science, Information Systems, Engineering, or a related technical field.
  • Deep knowledge of GRC frameworks including NIST CSF, NIST 800-53, ISO 27001/27701, and CIS Controls.

Preferred / bonus

  • Nothing listed as optional.

Only must-have items are scored as hard constraints in Executive Fit.

Likely challenges

Not stated in the posting: Compensation range not disclosed.; Specific team size (number of direct/indirect reports) not disclosed..

About Arctic Wolf

Arctic Wolf is a cybersecurity operations company that provides managed detection and response (MDR), cloud monitoring, and risk management services through its cloud-native platform. The company serves mid-market and enterprise customers globally using a security-as-a-service model. For a security leader, it represents a high-growth, late-stage private firm operating at a global scale with significant venture backing.

Industry
Software
Headcount
1,001-5,000 employees
Headquarters
Eden Prairie, MN
Founded
2012
Ownership
Venture backed
Funding
Series D or later · $899M raised
Revenue
$250M – $1B
Investors
Lightspeed Venture Partners, Viking Global Investors, Redpoint Ventures, Warburg Pincus, SoftBank Vision Fund

Full company profile for Arctic Wolf →

View original job description
At Arctic Wolf, you won’t just watch the cybersecurity industry evolve – you'll help lead the change. Our global Pack is made up of people who thrive on solving hard problems, moving fast, and building technology that protects organizations around the world. We’re proud to be recognized by Forbes, CNBC, Fortune, CRN, Gartner Peer Insights and IDC MarketScape – but what matters most is the work behind it: delivering real outcomes for customers through award winning innovation like our Aurora Platform.If you’re looking for meaningful work, smart teammates and the chance to make a real impact in a high-growth company that’s redefining security operations, Arctic Wolf is the right place for you!Our mission is simple: End Cyber Risk. We’re looking for a Vice President, Deputy CISO to be a part of making that happen.Position OverviewYou are an information security leader with deep experience across all domains of information security, with particular strength in governance, risk management, and compliance (GRC), and a proven record of directly managing technical security teams. You know how to build trust and influence outcomes across the organization, using your domain knowledge, prior experience, and executive presence to engage both technical and business leaders.Reporting to the Chief Information Security Officer (CISO), the Vice President, Deputy Chief Information Security Officer (Deputy CISO) is the direct people manager for Security Engineering, Security Operations (SecOps), and Governance, Risk, and Compliance (GRC), with full accountability for the strategy, staffing, performance, and budget of each function. The Deputy CISO ensures the enterprise’s personnel, data, and assets are protected against current and emerging threats, and provides leadership continuity for the security program in the CISO’s absence.Location: must work in the Pleasant Grove, Utah office, not taking remote applicants at this timeResponsibilitiesDirectly manages the Security Engineering, Security Operations (SecOps), and GRC functions, including hiring, performance management, and development of each team’s leadership.Sets strategy and priorities across security engineering, security operations, and GRC, ensuring the three functions operate as one coordinated program.Owns the organization’s security governance framework and compliance posture against industry frameworks and regulations (e.g., SOC 2, ISO 27001/27701, NIST CSF/800-53, PCI DSS, GDPR, CCPA), including third-party risk management and audit oversight.Oversees the security engineering roadmap and the operation of security monitoring, threat detection, and incident response, including post-incident governance and regulatory notification.Owns the enterprise security risk management program, including risk assessment, treatment, reporting, and the organization’s risk register.Manages the combined budget for security engineering, SecOps, and GRC, and contributes to enterprise security budget planning alongside the CISO.Provides leadership continuity in the CISO’s absence, including strategy execution, decision-making, and representation at the executive and board levels.Delivers security metrics, KPIs, and risk reporting to executive leadership, the board, and audit or risk committees.Partners with Legal and Privacy to align security requirements with contractual, regulatory, and privacy obligations, including customer due diligence and RFP responses.Acts as a representative for Arctic Wolf’s security and compliance posture with customers, auditors, regulators, and senior executives.Skills And Requirements8+ years of leadership experience directly managing security engineering, security operations, or GRC teams.10+ years of progressive information security experience spanning both technical security engineering functions and GRC.Demonstrated experience building and leading enterprise risk management programs, including risk assessment, risk registers, and reporting to executive leadership.Demonstrated experience managing SOC 2, ISO 27001, or similar certification and audit processes from initiation through completion.Experience with international industry security standards (NIST, ISO, SOC 2) and data privacy regulations (GDPR, CCPA, and other regional standards).Experience managing third-party and vendor risk management programs.Ability to establish executive-level relationships across business and technology leadership and manage competing priorities under pressure.A Bachelor’s Degree in Computer Science, Information Systems, Engineering, or a related technical field.Deep knowledge of information security governance, risk management, and compliance (GRC) frameworks, including NIST CSF, NIST 800-53, ISO 27001/27701, SOC 2, and CIS Controls.Demonstrated ability to lead security engineering and security operations teams, including secure architecture, SOC operations, and incident response.Experience designing and operating enterprise risk assessment, risk register, and audit or certification processes (e.g., SOC 2 Type II, ISO 27001).Strong understanding of data privacy regulations, including GDPR and CCPA/CPRA, and third-party risk management practices.Familiarity with Secure SDLC, DevSecOps, and security automation practices.Strong executive communication, board reporting, and stakeholder management skills.Ability to translate technical and regulatory risk into business risk language for non-technical audiences.Preferred Skills And RequirementsExperience serving as a CISO, Deputy CISO, or acting CISO.Relevant industry certification(s) such as CISSP, CISM, CRISC, or CISA.Master’s degree in a related field, or MBA.Experience in a regulated industry, such as financial services, healthcare, or SaaS/cybersecurity.Familiarity with GRC platforms, tools, and automation (e.g., Archer, OneTrust, Vanta, or Drata).On-Camera PolicyTo support a fair, transparent, and engaging interview experience, candidates interviewing remotely are expected to be on camera during all video interviews. Being on camera fosters authentic connection, improves communication, and allows for full engagement from both candidates and interviewers. We understand that technical, bandwidth, or location-related challenges may occasionally prevent video use. If this applies, candidates are required to notify us in advance so we can explore appropriate accommodations.About Arctic WolfAt Arctic Wolf, we foster a collaborative and inclusive work environment that thrives on diversity of thought, background, and culture. This is reflected in our multiple awards, including Top Workplace USA (2021-2025), Best Places to Work – USA (2021-2025), Great Place to Work – Canada (2021-2024), Great Place to Work – UK (2024-2026), and Kununu Top Company – Germany (2024-2026). Our commitment to bold growth and shaping the future of security operations is matched by our dedication to customer satisfaction, with over 10,000 customers worldwide and more than 2,000 channel partners globally. As we continue to expand globally and enhance our technology, Arctic Wolf remains the most trusted name in the industry.Our ValuesArctic Wolf recognizes that success comes from delighting our customers, so we work together to ensure that happens every day. We believe in diversity and inclusion, and truly value the unique qualities and unique perspectives all employees bring to the organization. And we appreciate that—by protecting people’s and organizations’ sensitive data and seeking to end cyber risk— we get to work in an industry that is fundamental to the greater good.We celebrate unique perspectives by creating a platform for all voices to be heard through our Pack Unity program. We encourage all employees to join or create a new alliance. See more about our Pack Unity here.We also believe and practice corporate responsibility, and have recently joined the Pledge 1% Movement, ensuring that we continue to give back to our community. We know that through our mission to End Cyber Risk we will continue to engage and give back to our communities.All Wolves Receive Compelling Compensation And Benefits Packages, IncludingEquity for all employees Flexible time off and paid volunteer days RRSP and 401k match Training and career development programs Comprehensive private benefits plan including medical, mental health, dental, disability, life and AD&D, and value-added services Robust Employee Assistance Program (EAP) with mental health services Fertility support and paid parental leave Arctic Wolf is an Equal Opportunity Employer and considers applicants for employment without regard to race, color, religion, sex, orientation, national origin, age, disability, genetics, or any other basis forbidden under federal, provincial, or local law. Arctic Wolf is committed to fostering a welcoming, accessible, respectful, and inclusive environment ensuring equal access and participation for people with disabilities. As such, we strive to make our entire experience as accessible as possible and provide accommodations as required for candidates and employees with disabilities and/or other specific needs where possible. Please let us know if you require any accommodation by emailing recruiting@arcticwolf.com. View our Hiring Page to learn more about our application process.Security RequirementsConducts duties and responsibilities in accordance with AWN’s Information Security policies, standards, processes, and controls to protect the confidentiality, integrity and availability of AWN business information (in accordance with our employee handbook and corporate policies). Background checks are required for this position. This position may require access to information protected under U.S. export control laws and regulations, including the Export Administration Regulations (“EAR”). Please note that, if applicable, an offer for employment will be conditioned on authorization to receive software or technology controlled under these U.S. export control laws and regulations.

Cyber Leadership Index is not the employer and does not represent candidates for these roles. Verify all details with the employer before acting.