Regional Information Security Officer
Zeiss Group · New York
📍 White Plains, NYvia workdayFirst listed here 2026-09-20
Apply on company site ↗
Career Moonshot pulls this listing straight from the employer's hiring system — no recruiter middleman, no reposts. Applying takes you directly to Zeiss Group.
About Us:
ZEISS is a global technology and innovation leader in optics and optoelectronics. Founded in Germany in 1846, ZEISS operates in 50+ countries and offers career opportunities across engineering, manufacturing, research, sales, and technology.
As a foundation-owned company, ZEISS is committed to responsibility, quality, and continuous innovation. Employees help shape the future through cutting-edge technology and impactful work. With a strong North American presence since 1925 and 20+ locations, ZEISS partners with industries including semiconductor, automotive, biomedical research, and medical technology, and is a leading manufacturer of eyeglass lenses, camera and cinema lenses, and precision optical systems.
What’s the role?
The Regional Information Security Officer (RISO) is a key member of the ZEISS regional IT and Information Security team (CIT-R) and the liaison with Corporate Information Security (CIT-I) reporting to and representing its head in the respective ZEISS region by mirroring CIT-I organization, acting as a 2nd line-of-defense function for all information security domains.
The RISO contributes to the overall Corporate Information Security strategy and oversees the effectiveness of the 1st line-of-defense, meeting the requirements of key stakeholders such as other ZEISS Business Support functions and Business Segments - or SBUs – in the respective ZEISS region.
The RISO is an experienced information security professional, with expertise in cyber-defense and IT infrastructure and application security, as well as physical and information security, incident response, with the technical and business acumen to translate that vision into a tangible risk-based security roadmap in the respective ZEISS region.
The RISO as the CIT-I representative within the region must build strong relationships with the business and technical leadership in the region to assess the implementation of corporate information security standards by identifying gaps in security controls and advising on the appropriate execution of ZEISS information security strategy.
Sound Interesting?
Here’s what you’ll do:
Serve as an independent 2nd Line-of-defense having a clear security governance and advisory role representing Corporate Information Security (CIT-I) in the respective region.
Contribute to the designing and driving of information security policies, standards, and processes to maintain and improve the company's overall security posture from a regional perspective.
Review and interpret CSOPs, SSOPs and other InfoSec-relevant Documents/Directives for language and applicability to various scenarios within assigned region.
Direct the regional information security team to enable 1st Line-of-defense organizations (e.g., regional or local IT team, Digital Units, HR) to implement and improve the operationalization of security standards and processes.
Communicate and coordinate ZEISS information security strategy, programs, and services with a diverse group of business stakeholders.
Continuously monitor and improve security posture and maturity in the region based on new challenges or changes in the overall threat landscape, tracking and actively advising on the prioritization of the mitigating actions.
Proactively consult the 1st Line-of-defense organizations and business with respect to security-relevant topics like e.g. need-to-know-, least privilege-, security-by-design-, security-by-default principles and their application and implementation in respective endeavors, business and solution designs, developments and the like.
Ensure that M&A projects and post-merger integrations (PMIs) comply with ZEISS security standards and policies, to avoid introducing unnecessary risk to the global organization.
Review security concepts for central Business Supporting Functions (e.g., CIT, ZDP and all other BSF within CZAG) within the region and regional demands outside of the BISO responsibility.
Address incident tickets & service requests related to regional topics and not covered by other CIT-I or 1st line-of-defense teams.
Participate in the security risk management of the 2nd line-of-defense, as well as in the aggregation of security risks of the 1st line-of-defense in the respective ZEISS region.
Support the regional information security incident response in the respective ZEISS region, looking beyond the individual results to find overarching insights (both successes and shortcomings) and identifying the critical efforts, driving the sustainable and timely closure of potential gaps and vulnerabilities.
Serves as a supporting role for the security incident response process, collaborating with 1st line-of-defense teams (including CIRT/SOC, CIT, regional IT, local IT, and Business IT) to assist in preparing for, mitigating, or resolving security incidents affecting the region during the investigation and response phases.
Be the primary escalation contact for information security topics in the region.
Participate in the CIDA (Cyber Incident Decision Authority) for security incidents occurring in the respective ZEISS region.
Conduct regional investigations (e.g., eDiscovery) and digital evidence gathering and analysis, supporting the HR and Legal departments and Law Enforcement within the region.
Cooperate with the region's HR and Legal departments to set and release litigation holds on user data to support data preservation orders as needed.
Advise on, proactively consult (also in cases of unavailable central standards or workarounds) and assess information security in various scenarios to ensure security maturity, following a risk-based approach in alignment with central InfoSec functions. Provide information security thought leadership with an understanding of the overall business organization, culture, audience, and climate.
Definition, assessment, and approval authority (including veto rights in alignment with Corporate Information Security team in t
More New York jobs
New York jobs · Browse all locations