IDC Research Inc. is seeking a senior cybersecurity leader to set and execute the organizationβs enterprise security direction across risk, compliance, and secure engineering. In this role, you will guide the cybersecurity strategy and architecture, lead day-to-day risk decisions, and help evolve the way IDC handles security for pilots and enterprise initiatives. The position also serves as Deputy CISO, operating with full delegated authority on the CISOβs behalf when needed.
Working onsite in Boston, MA, this leadership role centers on replacing per-project security gatekeeping with pre-approved patterns, guardrails, and fast risk determinations that keep delivery moving while maintaining control coverage.
Key Responsibilities
- Own enterprise cybersecurity strategy and a multi-year architecture roadmap aligned to business priorities and AI/automation goals.
- Design and maintain a library of pre-approved security patterns and guardrails that enables pilots and new projects to launch without a bespoke review cycle.
- Serve on and support the AI Governance Council as a security authority by pre-clearing model, data, and vendor patterns rather than gating individual AI and platform pilots.
- Lead security for AI platforms and pilots, including prompt-injection defense, runtime AI protection, agentic SOC coverage, PII detection, and red-team/canary testing.
- Partner with the AI & Automation team to embed security into the 5-day intake-to-ship pilot lifecycle from day one.
- Own identity and access management, zero-trust architecture, and SSO/SAML standards across IDCβs enterprise application portfolio.
- Own security engineering, including Quanta Cyber Guidance (secure-by-design reference architecture and build standards) and keep it current as the Quanta platform expands.
- Own the enterprise penetration testing program across internal, external, and third-party engagements for Quanta and the broader application portfolio, ensuring findings are tracked through verified remediation.
- Own secure coding standards and embedded security tooling in engineering pipelines, including SAST, DAST, and dependency and vulnerability scanning.
- Own the enterprise technology risk register, driving risk identification, quantification, and mitigation tracking across infrastructure, applications, and AI initiatives.
- Set risk appetite and tolerance thresholds with the CIO and executive leadership, making accept/mitigate/escalate decisions to keep pre-cleared pilots moving.
- Author and maintain enterprise security and risk policies, standards, and control frameworks to ensure consistent enforcement and support compliance and audit readiness globally.
- Drive certification and regulatory compliance programs including SOC 2 Type II, ISO 27001, GDPR, and market-specific frameworks such as MLPS/ICP for China operations on defined timelines.
- Own the enterprise audit calendar and act as a liaison to internal and external auditors to keep evidence and control documentation audit-ready.
- Manage vendor security and compliance risk assessments to meet committed SLAs so third-party reviews do not block delivery.
- Own incident response, threat detection, and security logging/monitoring across the global estate, including SIEM and cloud-native logging.
- Act as Deputy CISO, with full authority to represent the CISO in their absence across day-to-day security, risk, and compliance decisions.
- Build, lead, and develop a global cybersecurity, risk, and compliance team, including succession planning for key roles.
- Partner with the CISO to prepare risk posture, compliance status, and audit program health for the CIO, executive leadership, and the Audit Committee, and represent the program directly when the CISO is unavailable.
- Partner with Infrastructure, Applications, and Data leadership to embed security and compliance checkpoints directly into CI/CD and rapid deployment pipelines.
Requirements
- 12+ years in cybersecurity, including 5+ years in a senior leadership role owning strategy, architecture, risk, and a team.
- Experience operating as a deputy or right hand to a CISO or equivalent security executive, including delegated authority in their absence.
- Demonstrated experience securing SaaS, cloud, and AI/LLM platforms at enterprise scale.
- Direct ownership of an enterprise technology risk management program, including risk registers, risk quantification, and executive/board-level risk reporting.
- Working knowledge of major compliance frameworks including SOC 2, ISO 27001, and GDPR, with China-specific frameworks like MLPS/ICP considered a strong plus.
- Hands-on experience with modern threat defense tooling, zero-trust architecture, and identity management.
- Experience owning security engineering, including secure architecture guidance for a core platform and a penetration testing program through remediation.
- Proven ability to balance security rigor with delivery speed in agile, DevOps, and/or CI/CD environments.
- Bachelorβs degree in computer science, Information Security, or related field; CISSP, CISM, or equivalent certification preferred.
Technologies
- AI Governance Council
- Prompt-injection defense, runtime AI protection, agentic SOC coverage
- PII detection, red-team, canary testing
- Identity and access management, zero-trust architecture, SSO, SAML
- Quanta Cyber Guidance; Quanta platform; secure-by-design reference architecture
- SAST, DAST, dependency and vulnerability scanning
- SOC 2 Type II, ISO 27001, GDPR, MLPS/ICP
- SIEM, cloud-native logging
- CI/CD
Benefits
- 15 vacation days (prorated based on start date)
- 12 company-paid holidays
- 6 paid sick days (prorated based on start date; may vary by state)
- Medical, dental, and vision coverage
- 2 floating holidays (prorated based on start date)
- 1 volunteer day
- 401(k) company match (IDC matches 3% on the first 6% of employee contributions)
- Company-paid short-term disability
- Company-paid life insurance
- Company-paid parental leave
Compensation Transparency
The base salary range for this role is $165,800 USD β $290,220 USD annually, depending on location and experience. This role is also eligible for a variable incentive of up to 25% of base salary.
First 12 Months Success Indicators
- A published library of pre-approved security patterns in active use, reducing time-to-ship for new pilots and applications.
- SOC 2 Type II and ISO 27001 programs on track against agreed timelines with no material findings.
- AI pilots ship through the standard lifecycle with security built in from intake rather than bolted on before launch.
- Vendor risk reviews consistently meet SLA, with the team recognized as enabling delivery.
- The enterprise risk register is current and actively used to drive prioritization, with clear owners and mitigation timelines.
Remote Work States
Arizona (AZ), California (CA), Colorado (CO), Connecticut (CT), Washington D.C. (DC), Florida (FL), Georgia (GA), Illinois (IL), Indiana (IN), Kansas (KS), Massachusetts (MA), Maryland (MD), Maine (ME), Michigan (MI), Minnesota (MN), Missouri (MO), Mississippi (MS), North Carolina (NC), New Hampshire (NH), New Jersey (NJ), New York (NY), Ohio (OH), Oregon (OR), Pennsylvania (PA), Rhode Island (RI), South Carolina (SC), Tennessee (TN), Texas (TX), Utah (UT), Virginia (VA), Vermont (VT), Washingto