Regional Information Security Officer
ZEISS Group · White Plains, NY · via manual_submit
🗓 Posted: not published by source · Found by agent: 2026-09-13 17:00
Application documents
Score breakdown
| Component | Raw | Weight | Contribution | Evidence |
|---|---|---|---|---|
| keywords | 100.0% | 30 | 30.0 | cybersecuritycyber securitysocincident responsegovernanceregulatoryrisk managementcomplianceinfosecinformation security |
| seniority | 20.0% | 25 | 5.0 | |
| location | 100.0% | 20 | 20.0 | nyc-metrowhite plains |
| salary | 0.0% | 15 | 0.0 | below-min:$170,000 |
| company | 40.0% | 10 | 4.0 |
Telegram alerts
2026-09-16T19:58:38+00:00 → chat 5272237815 · sent
Synthesis sent: Regional Information Security Officer for ZEISS in White Plains, NY, acting as a 2nd line-of-defense liaison between Corporate Information Security (CIT-I) and regional IT/business teams. Reports to and represents the head of Corporate Information Security for the region, overseeing security governance, incident response, and compliance. Salary range $136,000–$170,000.
full message
Resume customization
Variant Lucian_Lipinsky_CV__JPMC__2026.docx engine claude 16809 in / 5952 out tokens ✓ 10/10 review passed
⬇ Download tailored resume (.docx) · 📝 What changed (changelog)
Keywords injected / gaps: second line of defenseregulatory expectationsregionalrisk governanceincident responsesecurity posturecross-functional
10-pass quality review
| # | Pass | Status | Detail |
|---|---|---|---|
| 1 | Grammar | APPROVED | Grammar is correct throughout, no sentence errors found. |
| 2 | Spelling | APPROVED | No spelling errors detected in customized resume. |
| 3 | Formatting consistency | APPROVED | 1 font(s), 5 size(s), consistent bullets |
| 4 | Logical layout | APPROVED | Section order mirrors base, logical and consistent flow. |
| 5 | LLM-artifact detection | APPROVED | no em dashes or LLM filler phrases detected |
| 6 | Job-description alignment | APPROVED | Regional/ISO terms integrated naturally, matching posting focus. |
| 7 | Accomplishments emphasis | APPROVED | Key metrics (45 countries, $1.7T AUM) retained and visible. |
| 8 | No fabrication | APPROVED | No new employer, title, metric, or date introduced; reframing only. |
| 9 | Consistency with base CV | APPROVED | No contradictions in titles, dates, or employers versus base. |
| 10 | Human readability | APPROVED | Reads naturally, professional tone consistent with human authorship. |
Text preview
Lucian Lipinsky de Orlov lucian@lipinskyllc.com ▪ 914-656-0324 ▪ linkedin.com/in/lipinsky/ Senior cybersecurity risk executive | global financial services Second line of defense leadership | regulatory & incident advisory Identity, Data & Privacy Risk | Cybersecurity Education Senior cybersecurity and risk executive with 20+ years of experience across global financial institutions, asset managers, and advisory roles, including second line of defense oversight and regional risk governance. Deep background in cyber risk oversight, identity security, data protection, and incident response, with a demonstrated ability to translate complex technical risk into clear, executive-level guidance. Extensive experience engaging senior leadership, regulators, and cross-functional stakeholders across multiple regions and business units. Proven educator and speaker with strong judgment, discretion, and credibility in building security governance programs that align with regulatory expectations. Professional Experience Highlights American Express - New York, NY Senior Director, Risk & Information Security 2025 - Present Cybersecurity Technology & Resiliency Risk Oversight Senior Director within American Express' global cyber risk oversight organization, leading a distributed team focused on data security, privacy, and identity & access management (IAM). Lead cross-regional cyber risk oversight for data protection, privacy, and identity security across enterprise platforms Advise senior executives on cyber risk exposure, control effectiveness, and practical risk-reduction actions impacting customers, employees, and business operations. Translate complex cybersecurity, privacy, and IAM risks into clear, practical guidance to support executive decision-making and risk awareness among non-technical stakeholders. Partner with technology, legal, privacy, and business leadership to align cyber risk posture with regional and global regulatory expectations Lead, coach, and set standards for a global team of senior cyber risk professionals. Citigroup - New York, NY Senior Vice President, Cyber Operational Risk Officer 2023 - 2025 Senior cyber risk leader within Citi's Second Line of Defense providing independent challenge and advisory oversight across vulnerability management, incident response, threat intelligence, security operations, and policy governance. Advised regional and senior leadership on cyber risk exposure, residual risk, and prioritization across global operations Translated technical findings into executive decision briefs for non-technical leadership. Acted as regional liaison to global regulators on cybersecurity posture and resilience, coordinating remediation strategy in a second line of defense capacity Oversaw global adversarial emulation exercises focused on preparedness, judgment, and incident response readiness across regions Reviewed and modernized cybersecurity policies, standards, and guidelines to meet regional and global regulatory expectations. Franklin Templeton Investments - New York, NY Global Director of Security and Risk (CISO) 2019 - 2023 Advised UHNW individuals and family offices within Franklin Templeton's Fiduciary Trust subsidiary on personal and family office cybersecurity risks, including digital assets, privacy exposure, identity compromise, and secure handling of sensitive financial information. Executive accountable for global cybersecurity and risk management across 45 countries supporting $1.7T AUM. Advised executive leadership on cyber risk tradeoffs, investment decisions, and incident preparedness. Led incident response planning, executive tabletop exercises, and crisis simulations. Architectural advisor to the world's first SEC-approved tokenized government money fund, advising on blockchain, cryptography, and operational risk. QuSecure - San Mateo, CA Board Advisor (Quantum Security) 2020 - 2023 Provided technical guidance on post-quantum cryptography architecture and applicability in regulated financial services environments. Translated complex quantum and cryptographic concepts into clear, credible narratives for executive leadership, potential investors, and media. Citihub - New York, NY Partner, CISO-for-Hire 2008 - 2015 Served as trusted cybersecurity advisor to C-suite executives across financial services and other industries. Delivered executive briefings, tabletop exercises, and strategic cyber guidance aligned to business risk. Deloitte Consulting - New York, NY Senior Manager, Security SME 2003 - 2008 Advised capital markets, wealth management, and retail banking clients on technology and security risk. Led large-scale regulatory and security initiatives and delivered C-level presentations. Thought Leadership & Education Fordham University - Three Minute Thesis (3MT) Competition First Place Winner (2018) Recognized for delivering advanced cybersecurity research on AI-driven threat detection to a non-technical audience in under three minutes, demonstrating exceptional clarity, discipline, and executive communication. Fordham University - Lincoln Center, New York, NY Adjunct Professor, Center for Cybersecurity 2019 - Present Teach undergraduate and graduate courses in computer security systems, encryption, operating system vulnerabilities, and disaster recovery. Program designated by NSA/DHS as a National Center of Academic Excellence in Cyber Defense Education. Education MS in Cybersecurity Fordham University, Graduate School of Arts and Sciences, New York, NY NSA and DHS National Center of Academic Excellence in Cyber Defense Education Certified MS in Advanced Technology, Specialization in Computer Science Thomas J. Watson School of Engineering, Applied Science, and Technology Graduated School of State University of New York, Binghamton, NY BS in Computer Science State University of New York, Binghamton, NY Certification & Training ISACA CRISC - PMI Project Management Professional (PMP) - ITIL Foundation Certified - Certified Disciplined Agilist - Enterprise Lean Six Sigma Green Belt - CISSP (Candidate) - IBM Certified Professional - Project Management - New York State Notary Public
Full description (11689 chars)
Open source posting ↗About the job About Us ZEISS is a global technology and innovation leader in optics and optoelectronics. Founded in Germany in 1846, ZEISS operates in 50+ countries and offers career opportunities across engineering, manufacturing, research, sales, and technology. As a foundation-owned company, ZEISS is committed to responsibility, quality, and continuous innovation. Employees help shape the future through cutting-edge technology and impactful work. With a strong North American presence since 1925 and 20+ locations, ZEISS partners with industries including semiconductor, automotive, biomedical research, and medical technology, and is a leading manufacturer of eyeglass lenses, camera and cinema lenses, and precision optical systems. What’s the role? The Regional Information Security Officer (RISO) is a key member of the ZEISS regional IT and Information Security team (CIT-R) and the liaison with Corporate Information Security (CIT-I) reporting to and representing its head in the respective ZEISS region by mirroring CIT-I organization, acting as a 2nd line-of-defense function for all information security domains. The RISO contributes to the overall Corporate Information Security strategy and oversees the effectiveness of the 1st line-of-defense, meeting the requirements of key stakeholders such as other ZEISS Business Support functions and Business Segments - or SBUs – in the respective ZEISS region. The RISO is an experienced information security professional, with expertise in cyber-defense and IT infrastructure and application security, as well as physical and information security, incident response, with the technical and business acumen to translate that vision into a tangible risk-based security roadmap in the respective ZEISS region. The RISO as the CIT-I representative within the region must build strong relationships with the business and technical leadership in the region to assess the implementation of corporate information security standards by identifying gaps in security controls and advising on the appropriate execution of ZEISS information security strategy. Sound Interesting? Here’s What You’ll Do Serve as an independent 2nd Line-of-defense having a clear security governance and advisory role representing Corporate Information Security (CIT-I) in the respective region. Contribute to the designing and driving of information security policies, standards, and processes to maintain and improve the company's overall security posture from a regional perspective. Review and interpret CSOPs, SSOPs and other InfoSec-relevant Documents/Directives for language and applicability to various scenarios within assigned region. Direct the regional information security team to enable 1st Line-of-defense organizations (e.g., regional or local IT team, Digital Units, HR) to implement and improve the operationalization of security standards and processes. Communicate and coordinate ZEISS information security strategy, programs, and services with a diverse group of business stakeholders. Continuously monitor and improve security posture and maturity in the region based on new challenges or changes in the overall threat landscape, tracking and actively advising on the prioritization of the mitigating actions. Proactively consult the 1st Line-of-defense organizations and business with respect to security-relevant topics like e.g. need-to-know-, least privilege-, security-by-design-, security-by-default principles and their application and implementation in respective endeavors, business and solution designs, developments and the like. Ensure that M&A projects and post-merger integrations (PMIs) comply with ZEISS security standards and policies, to avoid introducing unnecessary risk to the global organization. Review security concepts for central Business Supporting Functions (e.g., CIT, ZDP and all other BSF within CZAG) within the region and regional demands outside of the BISO responsibility. Address incident tickets & service requests related to regional topics and not covered by other CIT-I or 1st line-of-defense teams. Participate in the security risk management of the 2nd line-of-defense, as well as in the aggregation of security risks of the 1st line-of-defense in the respective ZEISS region. Support the regional information security incident response in the respective ZEISS region, looking beyond the individual results to find overarching insights (both successes and shortcomings) and identifying the critical efforts, driving the sustainable and timely closure of potential gaps and vulnerabilities. Serves as a supporting role for the security incident response process, collaborating with 1st line-of-defense teams (including CIRT/SOC, CIT, regional IT, local IT, and Business IT) to assist in preparing for, mitigating, or resolving security incidents affecting the region during the investigation and response phases. Be the primary escalation contact for information security topics in the region. Participate in the CIDA (Cyber Incident Decision Authority) for security incidents occurring in the respective ZEISS region. Conduct regional investigations (e.g., eDiscovery) and digital evidence gathering and analysis, supporting the HR and Legal departments and Law Enforcement within the region. Cooperate with the region's HR and Legal departments to set and release litigation holds on user data to support data preservation orders as needed. Advise on, proactively consult (also in cases of unavailable central standards or workarounds) and assess information security in various scenarios to ensure security maturity, following a risk-based approach in alignment with central InfoSec functions. Provide information security thought leadership with an understanding of the overall business organization, culture, audience, and climate. Definition, assessment, and approval authority (including veto rights in alignment with Corporate Information Security team in the case of critical risks for the entire ZEISS Group) of information security regional requirements in 1st line-of-defense processes (e.g. Corporate IT), architecture, key projects, procurement or demand process, change process, incident process, procedures, services, systems or network security mechanisms, etc. Evaluate risks associated to key projects and proactive consulting on their mitigation, including post M&A (Mergers and Acquisitions) integrations, and defining the security requirements that must be met to maintain a consistent level of security. Guide local information security assessment (e.g., WISA) with local and regional IT personnel, and conduct on-site visits to evaluate and ensure compliance with security standards in a governance and consulting capacity, reporting and sharing the findings and recommendations with legal entity management, BISO and 1st line-of-defense teams (e.g., regional, and local) as a corrective action plan. Support the a chievement, maintenance, and periodic assessment of regulatory certifications and compliance (e.g., CMMC, ISO27001, TISAX, HIPAA, CyberEssentials, NIS2, etc.). Assess, provide consultancy and support for the applicability of local information security regulatory requirements in the country or region, engaging internal Legal, Compliance, and Regulatory personnel as needed. Inform and provide oversight about legal and regulatory cybersecurity changes in the region to the head of Corporate Information Security, as well as to the required InfoSec teams. Monitor global/regional information security status (e.g., InfoSec KPIs) to provide guidance and consulting or advice to drive the implementation and maintenance of security measures by 1st line-of-defense teams. Support and collaborate on developing business-relevant metrics and key performance or risk indicators (KPI and KRI) supporting the measurement of information security program maturity. Understand the business workflows and engage with business leadership and teams to identify risks and business-aware mitigation strategies. Coordinate activities and share information with Corporate Health & Safety on physical and facility security topics and internal investigations as needed. Provide input to Business Information Security Officers (BISO) to assist in reviewing, approving, or responding to, information security contract amendments regarding products, services, purchase orders, and security questionnaires submitted by customers and government agencies. Identify and recommend security awareness initiatives (i.e., baseline evaluation, training, testing) in the respective ZEISS region based on KPI or job function (e.g., Finance personnel, Executives, IT administrators, etc.), helping the organization to meet the security challenges arising from the latest security threats and trends. Support and consult on key Corporate InfoSec (CIT-I) promoted programs in the respective region. Do you qualify? University degree in information security, information technology, engineering, cyber security, natural sciences, technology or similar. Minimum of 10 years of experience in information security, IT security, or a related field with proven track record in a leadership role within information security, preferably in a regional or global capacity. Experience in a technology-driven industry, with a preference for roles in manufacturing, healthcare, or other regulated sectors. Knowledge of the applicable international and regional regulatory requirements and standards in the areas of Cybersecurity and Data Protection. Hands-on experience with cybersecurity frameworks (e.g., NIST, ISO 27001) and risk management methodologies. Sound experience managing security projects from inception to completion, including the ability to prioritize tasks and manage multiple projects simultaneously. Experience working with cross-functional teams and engaging with senior leadership to drive security initiatives and foster a culture of security awareness. CISSP certification would be beneficial. The annual pay range for this position is $136,000 – $170,000. The pay offered for this role may be influenced by factors such as job location, scope of role, qualifications, education, experience, & complexity/specialization/scarcity of talent. This position is also eligible for a performance bonus or sales commissions. ZEISS also offers robust benefits, including medical plans, retirement savings plan and paid time off. We have amazing benefits to support you as an employee at ZEISS! Medical Vision Dental 401k Matching Employee Assistance Programs Vacation and sick pay The list goes on! The above is intended to describe the general content of and requirements for this job. It is not to be construed as an exhaustive statement of requirements, duties, or responsibilities. The Company reserves the right to interpret, amend, or otherwise modify, in whole or in part, any job description at any time, at its sole discretion. Your ZEISS Recruiting Team Jo Anne Mittelman Zeiss provides Equal Employment Opportunity without unlawful regard to an Applicants race, color, religion, creed, sex, gender, marital status, age, national origin or ancestry, physical or mental disability, medical condition, military or veteran status, citizen status, sexual orientation, pregnancy (includes childbirth, breastfeeding or related medical condition), genetic predisposition, carrier status, gender expression or identity, including transgender identity, or any other class or characteristic protected by federal, state, or local law of the employee (or the people with whom the employee associates, including relatives and friends). Benefits found in job post 401(k)