This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
ZGF is seeking an experienced Information Security Leader to continuously strengthen the firm’s security across all offices. This role is responsible for enterprise information security strategy, governance, risk management, compliance, and operational oversight. The individual will ensure that ZGF’s people, project information, client data, and intellectual property are protected in an increasingly complex and evolving threat landscape. The position reports to the Director of Information Technology and works closely with firm leadership, project teams, and external security partners.
Job Responsibility:
Lead ZGF’s enterprise information security program
Integrate a security mindset into the firm’s operations
Protect project data, client information, and intellectual property
Ensure compliance with appropriate frameworks (NIST 800-171, CMMC, etc.)
Provide clear governance over risk while enabling innovative design and delivery
Develop and maintain a firmwide information security strategy aligned with ZGF’s business objectives and risk tolerance
Translate the strategy into clear priorities, structured initiatives, and outcomes
Present quarterly updates to leadership on security posture, risks, and priorities
Serve as the firm’s authoritative voice on information security matters
Develop and document an information security program
Lead compliance related to NIST 800-171, CMMC, and other client-driven requirements
Oversee governance tools and compliance platforms currently in use
Conduct and oversee risk assessments, penetration testing, and vulnerability management programs
Ensure appropriate controls are documented, tested, and maintained
Coordinate cyber insurance requirements and external audit preparation
Evaluate, rationalize, and optimize ZGF’s security stack to minimize redundancy and ensure layered, well-integrated protections aligned with business risk
Provide leadership and oversight of all security operations
Coordinate closely with external MSSPs
Oversee incident response, escalation, and post-incident analysis
Strengthen disaster recovery and business continuity plans
Oversee firmwide identity and access management practices across hybrid AD / Entra environments
Enforce least privilege and Zero Trust principles
Govern privileged access, role-based access control, and MFA enforcement
Coordinate identity lifecycle integration with HR and IT systems
Lead firmwide security awareness initiatives
Strengthen a culture of accountability and vigilance without impeding design productivity or creativity
Ensure communication of risks and policies in language accessible to non-technical staff
Collaborate closely with Director of IT, Firmwide Technology Team, Operations Committee
Build trusted relationships with leaders across the firm to infuse security best practices into everyday operations
Requirements:
8–12+ years of experience in security, IT infrastructure, or related leadership roles