About this role
Job title: Chief Information Security Officer (CISO)
About the Role The Chief Information Security Officer (CISO) owns enterprise security strategy, risk management, and compliance for the FAL Group under Fortive. This is a senior leadership role reporting to the Chief Digital and Services Officer at Accruent, with dotted-line visibility to executive teams across Accruent, Gordian, ServiceChannel, and Fortive. The CISO protects customer data, enables enterprise sales through security readiness, and builds a security program that scales with growth across operating companies.
What You'll Do
- Own and continuously evolve the company’s information security strategy, aligned to business objectives and Fortive baseline posture, while tailoring programs to each operating company.
- Lead and develop a high-performing security organization spanning security operations, vulnerability and threat management, security engineering, governance/risk/compliance (GRC), application security, AI security, and incident response.
- Set and manage the security budget, including build-vs-buy decisions on tooling and managed services, and ensure staffing and development across Accruent, Gordian, ServiceChannel, and Fortive security communities.
- Establish security architecture standards across cloud infrastructure, AI, application development, and data platforms.
- Be the consistent voice for security across the three businesses, translating asks from Fortive, calibrating messaging to executive teams, and insulating operating companies from unnecessary business impact.
- Maintain visibility of security posture and strategic programs to the executive teams, owning cyber considerations for enterprise risk management initiatives.
- Chair and lead the Information Security Council (ISC) at each operating company, raising security awareness and driving resolution of critical cyber risk.
- Lead compliance and certifications (SOC 2 Type II, ISO 27001, Cyber Essentials Plus, CMMC, ISO 42001, HIPAA, GDPR, CCPA, SOX as relevant) and manage end-to-end audit cycles with minimal business disruption.
- Maintain a current risk register with assigned owners and deadlines, escalating appropriately to executive risk management with information security councils at each operating company.
- Own the enterprise risk management program including third-party/vendor risk assessments for the supply chain and subprocessors.
- Build and maintain the incident response plan; lead responses to security incidents with coordination from Legal, Communications, and executive leadership; conduct regular tabletop exercises.
- Lead regular response tests, tabletop exercises, and resiliency drills with key business areas and executive teams across all three operating companies.
- Report security posture, risk trends, and program maturity to the Fortive security team and Fortive CISO on a monthly basis; advise the executive team on emerging threats and regulatory changes.
What We're Looking For
- 10+ years in information security, with 5+ years in a senior leadership role (CISO, VP Security, Director of Security or equivalent) at a SaaS or data-intensive company.
- Demonstrated ownership of SOC 2 and/or ISO 27001 programs, including direct experience managing audit cycles to successful certification.
- Experience managing executive stakeholders at multiple lines of business.