网络安全项目与行业合作总监
Director of Cybersecurity Programs & Sector Engagement
我们是谁
NGO-ISAC 是一家 501(c)(3) 非营利组织,致力于加强美国非营利组织的安全性。我们是非政府组织的领先网络安全社区,为包括智库、人权组织、基金会、环保组织、医疗类非营利组织在内的 400 多家成员服务,并与大小不一的私营部门组织合作。我们是支撑公民社会在日益数字化的世界中正常运作的网络安全支柱。
我们的使命:通过战略情报、最佳实践和沉浸式教育提升非政府组织的网络安全成熟度,培养有韧性且协作的安全文化。
你是什么样的人
NGO-ISAC 正在招聘一位领导者,负责构建并运营其网络安全项目和行业参与工作。目前这一职能仍在建设中,该职位的人将负责设计整个体系。他们将确定威胁情报共享和集体防御的方向,创建提升成员安全成熟度的项目和资源,并代表 NGO-ISAC 在政府、行业和更广泛的网络安全社区中发声。风险直接明确:当一个非营利组织或新闻编辑室被入侵时,人们可能被监视或拘留。这个职位将建立帮助成员预防和应对这些攻击的项目。
这是一个高级职位,拥有实际的决策权和行动权限,对 NGO-ISAC 的预算、战略和共同领导负责。适合一位自信、善于协作、尊重他人知识并乐于接受反馈的专家。
该职位为全职远程办公,仅限美国境内。我们优先考虑东海岸的候选人,以确保时区重叠和偶尔的线下活动;需要出差。
该职位负责 NGO-ISAC 所产出的内容:课程、情报产品、技术内容及其准确性。会员事务负责会员交易:谁加入、谁续费、支付金额以及记录信息。社区与合作伙伴负责会员关系:参与、召集和同行社区。它还负责从同行组织到商业和技术合作伙伴的所有合作关系;该职位评估技术合作伙伴的技术匹配度。这三个职能通过不同的工作服务于相同的组织。
你将做什么
网络安全项目和会员支持
- 开发适合非营利组织实际运作方式和资源能力的安全计划。
- 设计可扩展的项目,例如安全评估、韧性指南
查看英文原文
Who We Are
NGO-ISAC is a 501(c)(3) nonprofit that strengthens the security of U.S.-based nonprofits. We are the leading cybersecurity community for non-governmental organizations, serving 400+ members including think tanks, human rights organizations, foundations, environmental groups, and healthcare nonprofits and partnering with private sector organizations both large and small. We're the cybersecurity backbone keeping civil society functioning in an increasingly digital world.
Our mission: Boost cybersecurity maturity in NGOs through strategic intelligence, best practices, and immersive education, fostering a resilient and collaborative security culture.
Who You Are
NGO-ISAC is hiring a leader to build and run its cybersecurity programs and sector engagement work. Much of this function is still being built, and the person in this role will design it. They will set the direction for threat intelligence sharing and collective defense, create the programs and resources that raise members' security maturity, and represent NGO-ISAC across government, industry, and the wider cybersecurity community. The stakes are direct: when a nonprofit or a newsroom is compromised, people can be surveilled or detained. This role builds the programs that help members prevent and recover from those attacks.
This is a senior role with real ownership and the authority to act on it, accountable to NGO-ISAC's budget, strategy, and shared leadership. It suits a confident expert who collaborates well, respects what others know, and stays open to feedback.
This role is fully remote within the United States. We prefer candidates on the East Coast for time-zone overlap and the occasional in-person event; travel required.
This role owns what NGO-ISAC produces: curriculum, intelligence products, technical content, and its accuracy. Membership owns the member transaction: who joins, who renews, what they pay, and what the record says. Community & Partnerships owns the member relationship: engagement, convening, and peer community. It also owns partnerships, from peer organizations through commercial and technology partners; this role assesses the technical fit of technology partners. All three functions serve the same organizations through different work.
What You'll Do
Cybersecurity programs and member support
- Develop security initiatives suited to how nonprofits actually work and what they can resource.
- Design programs that scale, such as security assessments, resilience guidance, and training.
- Develop and deliver member training, such as phishing simulations, incident-response drills for non-technical staff, and executive security briefings.
- Spot emerging threats to civil society and get ahead of them.
- Produce practical tools and resources that raise security maturity across the sector.
- Make sure programs deliver measurable value to members.
- Work with Community & Partnerships, the member-facing liaison for programming, on member needs, program feedback, and the framing and accessibility of content, with this role deciding what is published.
Threat intelligence and collective defense
- Run the collection, analysis, and sharing of threat intelligence relevant to nonprofits.
- Coordinate intelligence sharing among members.
- Grow and manage the intelligence-sharing platform and its governance, coordinating with Community & Partnerships, which owns broader community engagement channels.
- Govern intelligence sharing under Traffic Light Protocol, protecting member identity.
- Issue alerts and guidance on emerging threats.
- Support members during incidents that affect the sector.
- Maintain relationships with other ISACs and information-sharing networks.
Sector leadership and strategic engagement
- Build relationships with CISA, the National Council of ISACs, and peer ISACs.
- Assess the technical fit of technology and commercial partners, supporting the partnership program owned by Community & Partnerships.
- Take part in working groups and joint initiatives.
- Represent NGO-ISAC at conferences, forums, and sector convenings.
- Contribute thought leadership on the threats facing civil society.
Development and funding support (In partnership with the COO)
- Translate program impact into propositions that funders can support.
- Contribute to grant proposals and funder conversations.
- Build relationships with partners whose interests align with the sector's security.
Team leadership
- Manage and mentor program staff.
- Set clear priorities and objectives.
- Deliver programs and services reliably.
- Coordinate across the organization to support the work.
What You Bring
Required
- 8 or more years in cybersecurity, threat intelligence, or information security.
- Experience in collaborative security settings such as ISACs, government partnerships, nonprofits, or multi-organization efforts.
- A record of turning security expertise into working programs or services.
- Strong grasp of the current threat environment.
- Experience coordinating security work across multiple organizations.
- Clear communication with both technical and non-technical audiences.
- Experience leading teams or programs.
Preferred
- Experience with nonprofits, humanitarian organizations, or civil society groups.
- Familiarity with frameworks such as NIST CSF, CIS Controls, or ISO 27001.
- Familiarity with Traffic Light Protocol, MITRE ATT&CK, or open-source intelligence.
- Certifications such as CISSP, GCTI, or CEH.
- A degree in information technology, cybersecurity, management, or a related field.
- Experience with threat intelligence or information-sharing programs.
NGO-ISAC encourages candidates to apply even if they do not meet every qualification listed.
What We Offer
We want our people well and steady while they do work that matters, so the benefits are built to back that up.
You get medical, dental, and vision insurance, with FSA options to stretch what you spend on care. Paid time off is unlimited, and we want you to use it. We contribute to a 403(b) for your retirement and fund professional development so you can keep building the skills and credentials your work depends on. Because we are a 501(c)(3), your time here counts as qualifying employment toward Public Service Loan Forgiveness, which can clear federal student debt for people who spend their careers in mission work. Wellness benefits round it out.
The work/life balance line is not decoration. This is a place where you can do serious work and still have a life.
Compensation: $115-$150k, commensurate with experience.
We're looking for someone who can grow with us - from startup energy to an established organization. If you're excited about protecting civil society and building something meaningful, we want to hear from you.
NGO-ISAC is an equal opportunity employer who values diversity and hires for talent, passion, and compassion. In compliance with federal law, all people hired will be required to submit satisfactory proof of identity and legal authorization.
#INDAN
Originally posted on Himalayas