Chief Information Security Officer – Chicago, IL

Chief Information Security Officer Chicago IL

Role Overview for Chief Information Security Officer – Chicago, IL

JRG Partners is proud to lead an exclusive, confidential search for a visionary and strategic Chief Information Security Officer (CISO) on behalf of our client, a pioneering leader in the medical device manufacturing industry. Based in the vibrant city of Chicago, IL, this executive will join a forward-thinking organization dedicated to improving patient outcomes through technological innovation. This is a rare opportunity to shape the future of cybersecurity in a sector where security is synonymous with patient safety.

The CISO will be the senior-most executive responsible for establishing and maintaining a comprehensive, enterprise-wide information security and risk management program. You will be tasked with safeguarding the company’s intellectual property, corporate data, and, most critically, the security and integrity of its life-saving medical devices. This role demands a unique blend of deep technical expertise, strategic business acumen, and inspirational leadership.

You will serve as a trusted advisor to the executive leadership team and the Board of Directors, providing guidance on the complex and evolving landscape of cybersecurity threats and regulatory requirements specific to the medical device industry. You will build and lead a world-class security organization, fostering a culture of security awareness and resilience that permeates every level of the company, from product development to corporate operations.

The ideal candidate is a seasoned security leader with demonstrable experience in highly regulated environments, particularly within medical devices, pharmaceuticals, or healthcare. You must be adept at navigating the intricate web of compliance standards, including HIPAA and FDA regulations, while simultaneously driving innovation in product security. Your mission will be to ensure that security is not a barrier but an enabler of business growth and patient trust.

You will be responsible for the full spectrum of security, from securing the connected ‘Internet of Medical Things’ (IoMT) ecosystem to protecting sensitive patient health information (PHI) and defending the corporate enterprise against sophisticated cyber threats. This role is pivotal to the company’s long-term success and its commitment to delivering safe and effective medical technology to the world.

Key Responsibilities of Chief Information Security Officer – Chicago, IL

The Chief Information Security Officer will have a broad and impactful set of responsibilities, encompassing strategic leadership, product security, enterprise risk management, and regulatory compliance. Success in this role requires a proactive and holistic approach to security.

Strategic Vision & Leadership

Develop, implement, and maintain a strategic, long-term information security vision and roadmap that aligns with the company’s business objectives. Champion and articulate the business value of security investments to executive stakeholders and the Board of Directors.

Team Development

Recruit, mentor, and lead a high-performing team of security professionals covering product security, security operations, governance, risk, and compliance (GRC). Foster a collaborative and innovative team culture.

Product Security (IoMT)

Embed security into the entire product development lifecycle (SDLC), from design and architecture to post-market surveillance. Oversee threat modeling, secure coding practices, vulnerability assessments, and penetration testing for all medical devices and associated software.

Regulatory Compliance & Governance

Establish and lead the GRC function to ensure full compliance with all relevant regulations and standards, including HIPAA, HITECH, GDPR, and ISO 27001. Act as the primary liaison for regulatory bodies and auditors on all cybersecurity matters.

FDA Cybersecurity Expertise

Serve as the subject matter expert on medical device cybersecurity regulations, ensuring all products and processes adhere to the U.S. Food and Drug Administration’s stringent guidelines. This includes a deep, practical understanding of the FDA’s premarket and postmarket cybersecurity guidance to ensure product safety and regulatory approval.

Enterprise Risk Management

Design and operate a comprehensive enterprise-wide security risk management framework. Conduct regular risk assessments of information systems, third-party vendors, and business processes to identify, quantify, and mitigate risks to an acceptable level.

Security Operations & Incident Response

Oversee the Security Operations Center (SOC) and mature the organization’s capabilities in threat detection, analysis, and response. Develop, maintain, and test a robust incident response plan to ensure swift and effective management of security breaches, particularly those involving medical devices or patient data.

Technology & Architecture

Provide security oversight and architectural guidance for all corporate and product technology initiatives, including cloud infrastructure (AWS, Azure), enterprise applications, and network design. Evaluate and deploy state-of-the-art security technologies.

Budget & Financial Management

Develop and manage the annual information security budget, ensuring optimal allocation of resources to address the most critical risks and support strategic initiatives.

Security Awareness & Culture

Drive a culture of security consciousness across the entire organization through a comprehensive awareness and training program tailored to different roles and responsibilities.

Requirements for the Chief Information Security Officer – Chicago, IL

We are seeking a distinguished and accomplished leader with a proven track record of success in building and managing robust security programs within complex, regulated industries.

Educational Background

A Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or a related field is required. A Master’s degree (MS or MBA) is highly preferred.

Professional Certifications

Must hold one or more top-tier security certifications, such as CISSP (Certified Information Systems Security Professional), CISM (Certified Information Security Manager), CISA (Certified Information Systems Auditor), or CRISC (Certified in Risk and Information Systems Control).

Executive Experience

A minimum of 15 years of progressive experience in information security, with at least 7 years in a senior leadership capacity (e.g., VP of Security, Security Director, CISO) with direct responsibility for strategy, budget, and team management.

Industry-Specific Expertise

Direct, hands-on experience in the medical device, pharmaceutical, or healthcare industry is mandatory. A deep understanding of the unique security challenges related to connected medical devices, patient data protection (PHI), and clinical environments is essential.

Regulatory Mastery

Expert-level knowledge of relevant legal and regulatory frameworks, including HIPAA, HITECH, GDPR, CCPA, and most importantly, FDA 510(k) and PMA submission processes as they relate to cybersecurity.

Technical Acumen

Broad and deep technical knowledge across multiple security domains, including cloud security (IaaS, PaaS, SaaS), application security (SAST, DAST), network security, identity and access management (IAM), cryptography, and securing embedded systems/IoT.

Leadership & Communication Skills

Exceptional executive presence with the ability to communicate complex security concepts to a variety of audiences, from engineers to the Board of Directors. Proven ability to influence and build consensus across disparate business units.

Business Acumen

Strong financial and business sense, with the ability to translate security risks into business terms and build a compelling business case for security investments.

Strategic Mindset

A strategic thinker who can anticipate future threats and trends and develop proactive, forward-looking security strategies.

Benefits & Perks Offered

Our client offers a highly competitive executive compensation and benefits package designed to attract and retain top-tier talent. They are committed to investing in their employees’ professional growth and personal well-being.

Executive Compensation

A highly competitive base salary, annual performance-based bonus, and a significant long-term incentive plan (equity/stock options).

Comprehensive Health Coverage

Premium medical, dental, and vision insurance plans for you and your dependents.

Retirement Savings

A robust 401(k) plan with a generous company match to help you plan for your future.

Work-Life Balance

Generous Paid Time Off (PTO), company holidays, and flexible work arrangements.

Professional Development

A substantial budget for conferences, training, certifications, and other professional growth opportunities.

Relocation Assistance

A comprehensive relocation package is available for the right candidate.

Impactful Work

The unparalleled opportunity to protect technology that directly saves lives and improves patient health outcomes on a global scale.

How to Apply

This is an exclusive and confidential search conducted by JRG Partners. If you are a transformative security leader with the experience and passion to secure the future of medical technology, we invite you to apply. Your application will be handled with the utmost discretion.

To express your interest in this pivotal Chief Information Security Officer role, please submit your resume and a cover letter outlining your suitability for the position. For more information about our expertise in this domain, please visit our Technology & Cybersecurity Executive Search practice page. We look forward to connecting with you and discussing this exciting opportunity in more detail.

Job Category: Executive
Job Type: Full Time
Job Location: Chicago, IL

Apply for this position

Allowed Type(s): .pdf, .doc, .docx, .rtf
This entry was posted in . Bookmark the permalink.