other
Posted Apr 28Information Security Officer, Affiliate Technology Services
at ACLU
New York, United StatesHybrid
Responsibilities
- Own and advance the security posture of ACLU consolidated affiliates, including baseline controls, risk visibility, and remediation coordination.
- Lead and manage the Affiliate Security Champion Program, including recruitment, training, engagement, and ongoing coordination.
- Conduct affiliate security assessments and risk reviews, translating findings into actionable recommendations.
- Support affiliate incident preparedness, response coordination, and post-incident improvement efforts.
- Develop guidance, standards, and scalable security practices appropriate for affiliate environments.
- Track and report affiliate security risk trends to national leadership. FUTURE ACLU'ERS WILL
Requirements
- experience in information security, risk management, or security governance. â˘
- Experience working in federated, multi-entity, or decentralized organizations.
- Strong understanding of security controls, identity, cloud/SaaS risk, and incident response fundamentals.
Benefits
- Center and embed the principles of equity, inclusion and belonging in their work by demonstrating commitment to diversity with an approach that respects and values multiple perspectives
- Relevant certifications (e.g., CISSP, CISM) preferred but not required. COMPENSATION The ACLU is committed to equity, transparency, and clarity in pay.
- Consistent with our compensation philosophy, there is a set salary for each role based on geographic work location.
- The annual salary for this position is $ 167,568 (Level E), reflecting the salary of a position based in New York, NY. Salaries are subject to a regional pay adjustment if authorization is granted to work outside of the location listed in this posting. For details on our pay structure, please visit: https://www.aclu.org/careers/ACLU_Geographic_Pay_Structure-July_2024.pdf WHY THE ACLU
- Time away to focus on the things that matter with a generous paid time-off policy
- benefits (including medical, dental and vision coverage, parental leave, gender affirming care & fertility treatment)
- We support employee growth and development through annual professional development funds, internal professional development programs and workshops OUR COMMITMENT TO ACCESSIBILITY, EQUITY, DIVERSITY & INCLUSION
- Accessibility, equity, diversity and inclusion are core values of the ACLU and central to our work to advance liberty, equality, and justice for all.
- For us diversity, equity, accessibility, and inclusion are not just check-the-box activities, but a chance for us to make long-term meaningful change.
- The Department of Education has determined that employment in this position at the ACLU does not qualify for the Public Service Loan Forgiveness Program.
Contact
- If you are a qualified individual with a disability and need assistance applying online, please email benefits.hrdept@aclu.org .
Additional details
- The ACLU seeks applicants for the full-time position of Information Security Officer, Affiliate Technology Services in the Information Security team of the ACLUâs National office in New York, NY or Washington, D.C. This is a hybrid role that has in-office
- requirements of two (2) days per week or eight (8) days per month.
- This role will lead security posture management across the ACLUâs technology consolidated affiliates while providing advisory security support to non-consolidated affiliates operating independently.
- This position sits at the intersection of security governance, affiliate technology services, and operational risk.
- You will partner closely with the IT PMO for Affiliate Technology Services to embed security into affiliate-facing programs and will independently own and manage the Affiliate Security Champion Program to scale security awareness, baseline controls, and engagement across the affiliate network.
- This position is part of a collective bargaining unit. It is represented by ACLU Staff United (ASU).
- The Information Security Officer will serve as a trusted security advisor to the affiliate technology leaders, executives, and national stakeholders â helping balance enterprise security expectations with the operational realities of a federated organization. YOUR DAY TO DAY
- Provide structured security advisory services to non-consolidated affiliates, tailored to varying maturity levels and resource constraints.
- Partner with the IT PMO for Affiliate Technology Services to ensure security
- requirements are embedded into affiliate technology planning, delivery, and sustainment.