The opportunity
Harborline Systems Group is a fictional, growth-stage technology company used for this product demonstration. In this scenario, the company provides workflow and data platforms to regulated enterprise customers across North America.
We are seeking a Vice President of Cybersecurity & Resilience to turn a capable security program into an enterprise-scale, business-aligned operating model. Reporting to the Chief Technology Officer, this leader will own cybersecurity strategy, operations, resilience, governance, and executive risk communication while guiding a distributed team through the company’s next stage of growth.
The right candidate combines operational credibility with executive judgment. They can lead through a serious incident, build durable systems and leaders, challenge assumptions without creating gridlock, and explain risk in language that helps the business make decisions.
What you’ll lead
- Set and execute a three-year cybersecurity and operational resilience strategy aligned with enterprise growth, customer trust, and board-level risk priorities.
- Lead security operations, incident response, vulnerability management, identity and access management, cloud security, application security, governance, risk, and compliance.
- Build a measurable operating model across internal teams and strategic service providers, with clear service levels, controls, ownership, and executive reporting.
- Chair major-incident readiness and response, including tabletop exercises, crisis communications, executive decision support, and lessons-learned improvement plans.
- Partner with Product, Engineering, Legal, Privacy, Finance, and People leaders to embed practical security controls into business and technology programs.
- Develop leaders and succession depth across a distributed cybersecurity organization of approximately 45 employees and contractors.
- Present cyber-risk posture, program performance, material incidents, and investment recommendations to executive leadership and the board risk committee.
- Support acquisition diligence and post-close security integration for future growth opportunities.
What you bring
- 12+ years in cybersecurity, technology risk, or resilience, including at least 6 years leading multi-disciplinary teams.
- Demonstrated ownership of enterprise security operations and incident response in a regulated or high-availability environment.
- Experience translating technical risk into decisions, priorities, and investment cases for executives and boards.
- Track record designing metrics, improving control maturity, and delivering measurable reductions in operational or cyber risk.
- Working knowledge of NIST CSF, ISO 27001, SOC 2, privacy obligations, and risk-based control design.
- Strong cross-functional leadership with Product, Engineering, Legal, Privacy, Audit, and business teams.
- Bachelor’s degree or equivalent practical experience; relevant certifications such as CISSP, CISM, or CRISC are valued.
Additional strengths
These are useful, but they are not required to be considered.
- Experience supporting cybersecurity due diligence and integration during mergers or acquisitions.
- Familiarity with public-company cyber-risk disclosures and executive preparation for regulatory reporting.
- Experience modernizing security capabilities in cloud-first SaaS or platform environments.
How success will be measured
First 90 days
Establish trust, assess material risks, validate incident readiness, and align priorities with executive partners.
First 6 months
Publish the security and resilience roadmap, mature executive metrics, and clarify the operating model across teams and providers.
First year
Demonstrate measurable control improvements, stronger recovery readiness, leadership depth, and clearer risk-informed investment decisions.
Leadership impact
Build a culture where security is practical, accountable, evidence-based, and connected to customer and business outcomes.
Equal opportunity
In this fictional scenario, Harborline Systems Group evaluates candidates based on relevant skills, experience, and potential. The company would provide reasonable accommodations throughout an accessible hiring process.