Information Technology
Information Security Officer Job Description
An Information Security Officer is the senior manager or executive responsible for defining, implementing, and enforcing an organization's information security program. They translate business risk appetite into security policy, oversee technical controls across networks, endpoints, and cloud environments, manage compliance obligations across frameworks like NIST, ISO 27001, and SOC 2, and serve as the primary escalation point when a security incident threatens operations or data. CISA's NICE workforce framework also lists this work role under the alternate title Information Systems Security Officer (ISSO).
Last updated
Role at a glance
- Typical education
- Bachelor's degree in computer science, cybersecurity, or a related field; master's or JD common at senior levels.
- Typical experience
- 8 to 12 years of progressive security experience, including 3 to 5 years in a leadership role.
- Key certifications
- CISSP (ISC2), CISM (ISACA, job practice updates November 3, 2026), CRISC, CIPP/US.
- Top employer types
- Financial services, healthcare, and mid-market enterprises with growing security and compliance obligations.
- Growth outlook
- Shaped by the threat environment and the SEC's 2023 cybersecurity disclosure rule, which remains in force.
- AI impact (through 2030)
- Augmentation, not displacement: ISC2's global 2025 study found 28% of respondents have integrated AI tools and 63% of those deploying them report a productivity gain, while adding AI governance to the officer's scope.
Duties and responsibilities
- Develop and maintain the organization's information security program, policies, and standards aligned to NIST CSF, ISO 27001, or SOC 2 controls.
- Own the risk register, identifying, assessing, prioritizing, and tracking remediation of security risks across every business unit and vendor.
- Lead incident response, coordinating detection, containment, eradication, and post-incident review for security events and confirmed data breaches.
- Manage vendor relationships for SIEM, EDR, vulnerability management, and identity governance platforms, including renewal and performance reviews.
- Report security posture, key risk indicators, and material incidents to executive leadership, audit committees, and board members on a set cadence.
- Oversee the vulnerability management program, directing scan cadence, patch SLA enforcement, risk-based prioritization, and documented exceptions.
- Commission or review third-party risk assessments of vendors, cloud providers, and business partners that handle sensitive organizational data.
- Run security awareness training and phishing simulation programs aimed at reducing human-factor risk across the employee population.
- Maintain compliance with applicable regulatory requirements, including HIPAA, PCI DSS, GDPR, CMMC, and state-level privacy statutes.
- Coordinate with legal, HR, and operations on insider threat investigations, forensic evidence preservation, and required regulatory breach notifications.
Overview
An Information Security Officer sits at the intersection of technology, risk management, and organizational leadership. The role exists because protecting information assets is not a technical problem IT solves quietly in the background, it is a business risk that requires someone with authority, cross-functional relationships, and a coherent strategy to manage it continuously. CISA's NICE cybersecurity workforce framework lists "Information Systems Security Officer (ISSO)" as an official alternate title for this same work role, alongside Cybersecurity Officer and Enterprise Security Officer, which is why the exact title varies by employer even as the job stays consistent.
On any given week, an Information Security Officer might review a third-party penetration test and prioritize findings with the infrastructure team, present a security metrics dashboard to the CFO, walk procurement through vendor due diligence requirements for a new SaaS contract, manage the response to a credential stuffing attack flagged by the SIEM, and sign off on a business unit's exception request to delay a patch on a critical production system. None of those activities happen in isolation. Each one connects back to the security program framework and the risk register the officer owns, and to the resource and staffing decisions CISA's framework calls out as a core part of the role.
The incident response dimension is where judgment is most visible. When a ransomware event or a data breach unfolds, the Information Security Officer directs containment decisions, coordinates with legal on notification timelines, manages external forensic vendors, and serves as the face of the security organization to executives and, sometimes, regulators. The quality of the post-incident review that follows, whether findings actually change future behavior, is a direct reflection of how seriously the organization treats the role.
Governance is the other half of the job. Information Security Officers write and maintain security policies, manage audit relationships for SOC 2 or ISO 27001 certifications, track regulatory change, and make sure compliance obligations are wired into business processes rather than treated as annual checkbox exercises. At companies subject to the SEC's cybersecurity disclosure rule, adopted in 2023 and still in force, the officer works with legal and the audit committee to ensure material incidents are disclosed within four business days of a materiality determination and that the annual description of board oversight stays accurate.
A newer piece of the job is governing artificial intelligence itself, both as an attack tool adversaries use and as a defensive capability the security team deploys. ISC2's 2025 Cybersecurity Workforce Study, a global survey, found that 28% of respondents have already integrated AI tools into their operations, with another 19% actively testing them, and most of those using AI report a productivity gain. That puts AI tool evaluation and governance squarely on the Information Security Officer's plate alongside the traditional program.
Organizations that treat the role as a compliance function rather than a risk management function tend to underinvest in it until something goes wrong. The ones that get it right give the Information Security Officer real authority, an adequate budget, and a seat at the table when decisions with security implications are being made.
Qualifications
Education
- Bachelor's degree in computer science, information systems, cybersecurity, or a related field is the standard baseline.
- A master's in cybersecurity or information assurance, or an MBA with a technology concentration, is common at the senior level.
- Some Information Security Officers at mature organizations hold JD degrees given the overlap with privacy law and regulatory compliance.
Certifications
- CISSP (ISC2) is a widely requested credential and demonstrates cross-domain security knowledge across eight practice areas.
- CISM (ISACA) is a governance-focused alternative preferred by audit-heavy organizations; its job practice areas update on November 3, 2026.
- CRISC is a risk-management credential valued in financial services and other regulated industries.
- CIPP/US or CIPP/E adds privacy depth for organizations with significant data controller obligations.
- Security+ works as a baseline entry point but is not sufficient on its own at the senior Information Security Officer level.
Technical background typically held before the role
- Security architecture or engineering, spanning firewalls, SIEM, identity, and cloud security.
- Incident response or threat intelligence work.
- Penetration testing or red team experience, which builds the adversarial perspective that improves defensive decision-making.
- GRC (governance, risk, and compliance) program management.
Tools and platforms commonly used
- SIEM: Splunk, Microsoft Sentinel, IBM QRadar.
- EDR/XDR: CrowdStrike Falcon, SentinelOne, Microsoft Defender.
- Vulnerability management: Tenable Nessus, Qualys, Rapid7 InsightVM.
- Identity governance: SailPoint, Saviynt, and CyberArk for privileged access management.
- GRC platforms: ServiceNow GRC, Archer, OneTrust.
Experience benchmarks
- Roughly 8 to 12 years of progressive security experience is typical for the title.
- At least 3 to 5 years in a leadership or program management capacity.
- Demonstrated ownership of a security audit relationship, such as SOC 2, ISO 27001, or PCI DSS, from readiness through report issuance.
- Board or executive communication experience: the ability to translate technical risk into financial and business terms is what separates this role from a purely technical security manager, and CISA's NICE framework describes advising senior leadership as part of the work role.
- Direct experience acquiring and managing resources, including budget, staffing, and leadership support, since CISA's NICE framework lists resourcing as a core responsibility of the role rather than a side task.
- Familiarity with coordinating cybersecurity inspections, tests, and reviews across a network environment, and with continuously validating the organization against its own policies, guidelines, and applicable regulations.
Career outlook
Information Security Officers work against a threat environment that includes organized ransomware groups and an attack surface that spans cloud services, remote work, and third-party SaaS tools. ISC2's global 2025 Cybersecurity Workforce Study found that 63% of respondents at organizations using AI security tools report a significant productivity boost and that 73% said AI will create more specialized cybersecurity skills, which suggests AI is adding to the work rather than replacing it.
Regulation shapes the role as well. The SEC's cybersecurity disclosure rule, formally Release 33-11216 and adopted in July 2023, requires public companies to disclose material cyber incidents on Form 8-K within four business days of determining that an incident is material and to describe annually how leadership oversees cybersecurity risk. That disclosure obligation makes cybersecurity an executive and board accountability item, and the Information Security Officer is often the person who supplies the answers boards and audit committees need.
Healthcare and financial services are regulated sectors where the role is well established. HIPAA enforcement, PCI DSS version 4.0 requirements, and state financial regulator rules such as NYDFS 23 NYCRR 500 require ongoing program management that cannot be fully outsourced. Mid-market companies that rely on IT generalists for security may create a dedicated Information Security Officer position as their risk exposure, customer security questionnaires, and compliance obligations grow.
The role calls for an uncommon mix: technical credibility, governance experience, and the executive communication skills needed to explain risk to people who do not work in security. Building all three usually takes years in several different security jobs. Pay for the related Information Security Manager title sits in the band shown on this page, generally below CISO-level pay at large enterprises.
Looking ahead, the role also involves risk quantification, translating security gaps into financial exposure using frameworks like FAIR, and AI governance specifically: evaluating vendor AI tools, setting policy for employee use of generative AI, and updating threat models for AI-assisted attacks such as automated phishing and deepfakes. ISACA's updated CISM job practice takes effect November 3, 2026, so candidates preparing for that credential should review the revised practice areas before scheduling the exam.
For senior security professionals considering the role, the career path typically leads to CISO, VP of Security, or, in some organizations, Chief Risk Officer. The title is also a credible launching point for independent advisory work, audit committee board service, or cybersecurity consulting.
Sample cover letter
Dear Hiring Manager,
I'm applying for the Information Security Officer position at [Organization]. I've spent the last nine years in information security, the past four as senior security manager at [Company], a 1,200-person financial services firm with PCI DSS, SOC 2 Type II, and NYDFS 23 NYCRR 500 compliance obligations.
In that role I built the security program from a collection of inherited controls into a documented, audited framework mapped to NIST CSF. That included owning two SOC 2 Type II audit cycles from readiness assessment through report issuance, closing 23 NYCRR 500 gaps identified in a state exam, and standing up a vulnerability management program that cut our critical patch SLA from 45 days to 9 over 18 months.
The incident I'm most proud of managing was a business email compromise event that surfaced while our CEO was traveling. I directed containment within 40 minutes of initial detection, coordinated with outside counsel on notification obligations, and had a board-ready summary prepared before the executive team convened the next morning. The post-incident review identified two control gaps, MFA enforcement on legacy email clients and wire transfer authorization thresholds, that we closed before the quarter ended.
I hold an active CISSP and CISM, present to our audit committee twice a year, and have started evaluating our first AI-assisted SIEM correlation tools with the same scrutiny I'd apply to any new control. I'm comfortable translating security risk into financial terms and working with business leaders who do not have security backgrounds.
[Organization]'s growth trajectory and the regulatory complexity of your sector are exactly the environment where I do my best work. I would welcome the opportunity to discuss the role.
[Your Name]
Frequently asked questions
- What does an Information Security Officer do?
- An Information Security Officer is the senior manager or executive responsible for defining, implementing, and enforcing an organization's information security program. They translate business risk appetite into security policy, oversee technical controls across networks, endpoints, and cloud environments, manage compliance obligations across frameworks like NIST, ISO 27001, and SOC 2, and serve as the primary escalation point when a security incident threatens operations or data. CISA's NICE workforce framework also lists this work role under the alternate title Information Systems Security Officer (ISSO).
- What are the main duties of an Information Security Officer?
- Core duties include: develop and maintain the organization's information security program, policies, and standards aligned to NIST CSF, ISO 27001, or SOC 2 controls; own the risk register, identifying, assessing, prioritizing, and tracking remediation of security risks across every business unit and vendor; and lead incident response, coordinating detection, containment, eradication, and post-incident review for security events and confirmed data breaches.
- What is the difference between a Chief Information Security Officer (CISO) and an Information Security Officer?
- The CISO is typically a C-suite executive with organization-wide authority, budget ownership, and direct board access. The Information Security Officer often sits one level below, managing a division, subsidiary, or business unit, or serving as the senior security practitioner at a mid-market company that has no separate CISO title. CISA's NICE workforce framework lists Information Systems Security Officer (ISSO) as an official alternate title for this same work role, which is why usage varies by employer.
- Which certifications matter most for an Information Security Officer?
- CISSP (ISC2) is a widely requested senior-level credential, covering eight security domains. CISM (ISACA) is preferred by governance-heavy organizations and is getting a job-practice update effective November 3, 2026. CRISC and CIPP/US or CIPP/E add risk and privacy depth for regulated industries, while Security+ functions as an entry point rather than a senior qualification.
- How is AI changing the work of an Information Security Officer?
- ISC2's 2025 Cybersecurity Workforce Study, a global survey, found 28% of respondents have already integrated AI tools into operations, with another 19% actively testing them, and 63% of those deploying AI tools report a significant productivity boost. The same study found 73% said AI will create more specialized cybersecurity skills, and AI governance and tool oversight are becoming part of the Information Security Officer's scope.
- Is an Information Security Officer personally liable if the organization suffers a breach?
- Disclosure stakes are higher under the SEC's cybersecurity disclosure rule, which requires public companies to report material incidents on Form 8-K within four business days of determining materiality and to describe annually how leadership oversees cybersecurity risk. Information Security Officers should confirm their employment agreement addresses indemnification, that D&O insurance covers security roles, and that risk decisions are documented and escalated to the appropriate business authority.
- Does an Information Security Officer need a hands-on technical background?
- Many Information Security Officers worked earlier in network security, incident response, or security architecture, which lets them pressure-test vendor claims and direct technical staff credibly. The senior role also demands governance and communication skill: technical depth alone does not prepare someone to present to a board or negotiate security investment with a CFO.
Sources
Salary figures and role details on this page were checked against the following sources. Dates show when each was last reviewed.
- Information Security Analysts, BLS Occupational Employment and Wage Statistics (May 2025)Checked Sep 21, 2026
- Computer and Information Systems Managers, BLS Occupational Employment and Wage Statistics (May 2025)Checked Sep 21, 2026
- Information Security Manager Salary, PayScale (2026)Checked Sep 21, 2026
- Chief Information Security Officer with Cyber Security Skills Salary, PayScale (2026)Checked Sep 21, 2026
- 2025 ISC2 Cybersecurity Workforce Study, ISC2 (December 2025)Checked Sep 21, 2026
- Certification: CISM Job Practice Update 2026, ISACAChecked Sep 21, 2026
- Information Systems Security Manager work role, CISA NICE Cybersecurity Workforce FrameworkChecked Sep 21, 2026
- Cybersecurity Risk Management, Strategy, Governance and Incident Disclosure, SEC Office of the Advocate for Small Business Capital Formation (2023)Checked Sep 21, 2026
Related job descriptions
See all Information Technology jobs →- Director of Information Security$145K–$225K
A Director of Information Security leads an organization's cybersecurity strategy, program management, and risk governance across enterprise IT and OT environments. Reporting to the CISO or CIO, they own security architecture, incident response capability, compliance posture, and a team of analysts, engineers, and architects. The role sits at the intersection of technical depth and executive communication — translating threat intelligence and vulnerability data into business risk decisions that boards and leadership teams can act on.
- Information Security Analyst$75K–$200K
Information Security Analysts design, implement, and monitor the controls that protect an organization's networks, systems, and data from unauthorized access, breaches, and cyberattacks. They sit between IT operations and risk management, running vulnerability scans, investigating alerts, and translating technical findings into guidance for engineering teams and leadership. The U.S. Bureau of Labor Statistics projects the occupation to grow 21 percent from 2025 to 2035, far faster than average. Many security tools now include AI-assisted detection, and analysts are expected to validate automated alerts rather than accept them as given.
- Information Security Engineer$95K–$155K
Information Security Engineers design, implement, and maintain the technical controls that protect an organization's networks, systems, and data from compromise. They sit at the intersection of engineering and defense — building security architecture, running vulnerability programs, responding to incidents, and translating threat intelligence into hardened configurations. The role demands hands-on technical depth across identity, network, endpoint, and cloud domains.
- Information Security Manager$105K–$165K
Information Security Managers lead an organization's efforts to protect information systems, networks, and data from unauthorized access, breaches, and compliance failures. They own the security program — setting policy, managing a team of analysts and engineers, coordinating incident response, and translating technical risk into business language for senior leadership. The role sits at the intersection of technical depth and organizational authority.
- Information Security Specialist$78K–$130K
Information Security Specialists design, implement, and monitor technical controls that protect an organization's networks, systems, and data from unauthorized access, breaches, and compliance failures. They sit at the intersection of engineering and risk management — configuring firewalls and SIEM platforms one day, briefing leadership on threat exposure the next. The role spans prevention, detection, and response across the full attack surface.
- Senior Information Security Analyst$105K–$155K
Senior Information Security Analysts protect organizations from cyber threats by monitoring security systems, investigating incidents, assessing vulnerabilities, and driving security improvements across the technology environment. They lead security operations activities, mentor junior analysts, contribute to security architecture decisions, and serve as the technical escalation point for complex security incidents and risk assessments.