
Role Overview for Chief Information Security Officer – Raleigh, NC
JRG Partners is proud to partner with a pioneering medical device company in their search for a visionary Chief Information Security Officer (CISO) based in the vibrant tech hub of Raleigh, North Carolina.
This is not merely a technical leadership role; it is a strategic executive position critical to the company’s mission of improving patient outcomes through innovative technology. Our client is at the forefront of developing life-saving and life-enhancing medical devices, and the security and integrity of these products, and the data they generate, are paramount to patient safety and trust.
As the CISO, you will be the senior-most executive responsible for establishing and maintaining a comprehensive, enterprise-wide information security and risk management program. You will be tasked with protecting the company’s most critical assets: its patient data, intellectual property, and brand reputation. In an industry defined by stringent regulatory oversight and the increasing threat of sophisticated cyber-attacks, your leadership will directly impact the company’s ability to innovate, operate, and grow securely.
You will serve as a trusted advisor to the executive leadership team and the Board of Directors, translating complex cybersecurity risks into actionable business insights and strategic initiatives.
This role demands a leader who can balance the demands of robust security with the need for business agility and innovation. You will be responsible for building and maturing a world-class security organization, fostering a culture of security awareness that permeates every department, from R&D to manufacturing and sales.
You will lead the charge in navigating the complex regulatory landscape, ensuring that our client not only meets but exceeds compliance standards for data protection and device security. This is a unique opportunity to shape the future of cybersecurity at a company that is making a tangible difference in people’s lives, all while being based in one of the nation’s fastest-growing and most dynamic technology centers.
Key Responsibilities of Chief Information Security Officer – Raleigh, NC
Strategic Leadership & Program Development
Develop, implement, and monitor a strategic, comprehensive enterprise information security and IT risk management program. This includes defining security policies, standards, and procedures in alignment with business objectives and regulatory requirements.
Governance, Risk & Compliance (GRC)
Establish and lead the GRC function to ensure the organization meets all legal, regulatory, and contractual security obligations. This includes conducting regular risk assessments, managing the security audit process, and ensuring compliance with frameworks such as HIPAA, HITECH, GDPR, and FDA cybersecurity guidance for medical devices.
Product Security (SecDevOps)
Partner closely with Engineering and Product Development teams to integrate security into the entire System Development Life Cycle (SDLC). Champion the security of connected medical devices, from design and development to post-market surveillance, protecting them from vulnerabilities and threats.
Security Operations & Incident Response
Oversee the continuous monitoring and protection of information processing assets. Lead the Security Operations Center (SOC) and the Computer Security Incident Response Team (CSIRT), ensuring rapid detection, effective response, and thorough remediation of all security incidents.
Threat Intelligence & Vulnerability Management
Develop and maintain a proactive threat intelligence program to anticipate and mitigate emerging threats. Implement a robust vulnerability management program to identify, assess, and remediate security weaknesses across the IT and product landscape.
Data Protection & Privacy
Architect and implement comprehensive data protection strategies to safeguard sensitive data, including Protected Health Information (ePHI) and corporate intellectual property. This involves overseeing data loss prevention (DLP), encryption, access control, and data classification initiatives.
Third-Party Risk Management
Establish and manage a program to assess and mitigate the security risks associated with third-party vendors, suppliers, and partners, ensuring the entire supply chain adheres to the company’s security standards.
Budget & Resource Management
Develop and manage the annual information security budget, ensuring strategic allocation of resources to address the most critical risks. Build, mentor, and lead a high-performing team of security professionals.
Executive & Board Communication
Effectively communicate the status of the information security program and the organization’s risk posture to the executive leadership team and the Board of Directors in a clear, concise, and business-oriented manner.
Security Awareness & Culture
Champion and lead the development of a corporate-wide security awareness and training program to foster a strong security-first culture among all employees and contractors.
Requirements for the Chief Information Security Officer – Raleigh, NC
Executive Experience
A minimum of 15 years of progressive experience in information security and risk management, with at least 7 years in a senior leadership capacity (e.g., CISO, VP of Security, Senior Director of Security) with demonstrable experience managing teams and budgets.
Industry Expertise
Proven experience working within a highly regulated industry is mandatory. Strong preference will be given to candidates with direct experience in medical devices, healthcare, pharmaceuticals, or biotechnology.
Regulatory Acumen
Deep and practical knowledge of relevant legal and regulatory requirements, including HIPAA/HITECH, FDA premarket and postmarket cybersecurity guidance, GDPR, and CCPA.
Technical Breadth and Depth
Comprehensive knowledge of security frameworks (e.g., NIST CSF, ISO 27001/27002), security architecture, cloud security (AWS/Azure), network and endpoint security, application security (SAST/DAST), and modern identity and access management (IAM) principles.
Educational Background
A Bachelor’s degree in Computer Science, Information Security, Engineering, or a related field is required. A Master’s degree (e.g., MBA or M.S. in Cybersecurity) is highly preferred.
Professional Certifications
Advanced professional security certifications such as Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified in Risk and Information Systems Control (CRISC), or Certified Information Systems Auditor (CISA) are strongly desired.
Leadership & Communication Skills
Exceptional ability to lead and motivate cross-functional teams. Must possess outstanding communication and interpersonal skills, with the proven ability to articulate complex security concepts to technical and non-technical audiences, including executive leaders and board members.
Business Acumen
A strategic thinker with a strong understanding of business principles and the ability to align security initiatives with broader corporate objectives and drive business value.
Benefits & Perks Offered
Our client is committed to investing in their people and offers a comprehensive and competitive executive compensation and benefits package, including:
Executive Compensation
A highly competitive base salary, a significant annual performance-based bonus, and a meaningful long-term equity incentive package.
Comprehensive Health & Wellness
Premier medical, dental, and vision insurance plans for you and your eligible dependents, along with a Health Savings Account (HSA) with a generous employer contribution. Includes access to wellness programs and mental health resources.
Retirement Savings
A robust 401(k) retirement plan with a strong company matching contribution to help you prepare for your future.
Work-Life Balance
A generous paid time off (PTO) policy, numerous paid holidays, and flexible work arrangements to support a healthy work-life integration.
Professional Growth
A dedicated budget for continuous learning, including attendance at major industry conferences, advanced training, and support for obtaining and maintaining professional certifications.
Relocation Support
A comprehensive relocation package is available for the successful candidate and their family to move to the beautiful Raleigh, NC area.
Additional Perks
A modern and collaborative office environment, employee recognition programs, and regular company-sponsored social and community events.
How to Apply
JRG Partners has been exclusively retained for this critical CISO search. We are seeking a transformative security leader who is passionate about protecting technology that saves lives. If you possess the requisite experience and are ready to take on this challenging and rewarding executive role, we encourage you to apply.
To be considered for this opportunity, please submit your resume and a cover letter detailing your qualifications and your vision for a modern security program in the medical device industry. Applications should be submitted directly through our portal. For more information about our expertise in this domain, please visit the homepage for our specialized Information Technology and Cybersecurity recruitment team.
We are an equal opportunity employer and value diversity. All employment is decided on the basis of qualifications, merit, and business need. We look forward to reviewing your application and discussing this exceptional opportunity with you.
