Full-Time

Vice President

Cybersecurity, Deputy Chief Information Security Officer

The New York Times

The New York Times

10,001+ employees

Subscription-based digital and print journalism

Compensation Overview

$275k - $290k/yr

+ Annual bonus + Restricted stock

New York, NY, USA

Hybrid

Three or more days in the New York City office per week are typically expected.

Category
IT & Security (1)
Required Skills
Incident Response
Cybersecurity
Vulnerability Analysis
SOC 2
AWS
Risk Management
HIPAA
Google Cloud Platform

Get referred to The New York Times

See people who can refer or advise you

Requirements
  • 12+ years of progressive experience in cybersecurity or information security, including leadership of large, complex security programs.
  • Experience leading multiple security domains, such as security engineering, security operations, incident response, cloud security, identity, application security or governance, risk and compliance.
  • Prior experience in a Vice President, Head of Security, Deputy Chief Information Security Officer or similar senior leadership role with accountability for both strategy and execution.
  • Deep technical understanding of modern security architectures, including cloud platforms such as AWS or GCP, network, endpoint, identity and application security.
  • A proven track record leading major incident response efforts and security crisis management, including communication with executives and external stakeholders.
  • Strong familiarity with industry frameworks and standards such as NIST Cybersecurity Framework 2.0, ISO 27001, SOC 2, PCI, HIPAA and data protection regulations.
  • Experience partnering closely with Legal, Privacy, Human Resources, Finance, Internal Audit and external regulators or auditors.
  • Expertise building and leading diverse teams, including developing senior managers and cross-functional leaders.
Responsibilities
  • Lead and integrate core security functions, including security architecture and engineering, threat detection and incident response, security operations, identity and access management, and risk and compliance.
  • Own day-to-day cybersecurity program execution, including annual planning, roadmap delivery, operational reviews and metrics.
  • Serve as the primary operational escalation point for significant security risks and incidents, partnering with Global Security, Legal, Communications, Enterprise Technology and business leaders.
  • Act as a visible security leader with executives, senior editors and technology leaders, helping them understand risk, tradeoffs and priorities in practical terms.
  • Serve as acting Chief Information Security Officer when needed, including during executive forums, audits and key stakeholder meetings.
  • Own execution of the cybersecurity strategy and roadmap, translating high-level risk and board-level objectives into concrete programs, projects and measurable outcomes.
  • Manage the cybersecurity budget, including coordinating with Finance, setting multi-year forecasts and managing billing workflows for cybersecurity vendors.
  • Establish and run cybersecurity operating rhythms, including staff meetings, portfolio reviews, operational reviews, objectives and key results, and metrics.
  • Partner with the Chief Information Security Officer on multi-year planning, budget development and investment prioritization across tools, people and services.
  • Drive continuous improvement using internal metrics, external benchmarks and findings from assessments, incidents and exercises.
  • Provide senior leadership across security engineering, architecture and operations, ensuring the security stack is robust, observable and well integrated with Enterprise Technology and Developer Platforms.
  • Guide the evolution of core controls such as endpoint protection, endpoint detection and response, security information and event management, email security, web security, vulnerability management, secrets management, mobile device management and identity governance.
  • Partner with Enterprise Technology, Developer Platforms and product engineering to embed secure-by-design patterns, guardrails and self-service controls into platforms and workflows.
  • Provide oversight and strategic direction for identity and access management, including identity platforms, access orchestration and privileged access.
  • Ensure operational excellence for security tooling, including lifecycle management, vendor relationships and integration with incident response and monitoring workflows.
  • Oversee threat detection, monitoring and incident response programs, including an automation-forward security operations center capability.
  • Serve as senior escalation leader for high-severity incidents, driving real-time decision-making, cross-functional coordination and executive communications.
  • Ensure playbooks, tabletop exercises, red-team and purple-team activities, and crisis management plans are in place, tested and regularly updated.
  • Partner with Global Security, Business Continuity and Enterprise Technology on integrated resilience programs, including disaster recovery, crisis response and resilience exercises.
  • Ensure post-incident reviews lead to durable improvements in controls, processes and architecture.
  • Lead cybersecurity governance and risk management frameworks in alignment with NIST Cybersecurity Framework 2.0 and other relevant standards.
  • Drive the development and use of risk metrics, control health indicators and dashboards to communicate security posture to executives, the Audit Committee and other stakeholders.
  • Support security education programs and a metrics-driven approach to providing relevant training and resources to staff.
  • Partner with newsroom teams to support the unique threat models of journalists and other high-risk users.
  • Ensure security measures and controls enable high-stakes newsgathering, international reporting and sensitive investigative work.
  • Support programs that protect journalists and high-risk staff across travel, field operations, online harassment and digital threats.
  • Lead, mentor and develop senior managers and staff across multiple security disciplines, building a high-performing, inclusive and collaborative team.
  • Foster a growth-minded, metrics-driven, blameless culture focused on learning and continuous improvement.
  • Support career paths, succession planning and leadership development across cybersecurity, including preparing future Chief Information Security Officer-level leaders.
  • Champion security awareness and education programs that engage staff at all levels in shared security ownership.
  • Engage in cross-industry collaboration and knowledge sharing to keep the organization up to date on security events, techniques and industry norms.
Desired Qualifications
  • Experience securing media, news, technology or similarly fast-paced, high-profile environments with unique threat models.
  • Background working directly with or supporting newsroom, high-risk user or investigative teams.
  • Experience presenting to boards or audit committees and supporting public-company security and risk disclosures.
  • Experience operating in a global context, including international offices, complex regulatory environments and cross-border data considerations.
  • Prior experience shaping artificial intelligence governance, artificial intelligence security or emerging-technology security programs.

The New York Times provides digital and print news across politics, business, technology, culture, and more for a global audience. It earns revenue from recurring subscriptions for digital and print editions and from online advertising, including sponsored content. It enhances value with subscriber services like NYT Cooking and other offerings, delivered through a digital platform, newsletters, and mobile apps. Its goal is to deliver trusted information and insightful analysis at scale while expanding its digital reach and subscriber value.

Company Size

10,001+

Company Stage

IPO

Headquarters

New York City, New York

Founded

1850

Get referred to The New York Times

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • Q2 2026 revenue rose 11.2% to $762.5 million, with digital ads up 20.7%.
  • Q1 2026 added 310,000 digital-only subscribers, lifting total subscribers to 13.08 million.
  • Price hikes lifted ARPU to $9.94, while family bundles expand household monetization.

What critics are saying

  • EEOC sued NYT on May 5, 2026 over alleged white male promotion discrimination.
  • NYT countersued EEOC on July 10, 2026, extending costly leadership distraction into 2027.
  • OpenAI and Microsoft litigation threatens huge legal expense and exposes NYT content monetization limits.

What makes The New York Times unique

  • 13.35 million digital subscribers and a 2027 target anchor The Times’ bundle scale.
  • Family subscriptions bundle News, Games, Cooking, Audio, Wirecutter, and The Athletic into one account.
  • NYT owns premium habits like Wordle, Cooking, and Wirecutter that deepen daily engagement.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Remote Work Options

Hybrid Work Options

Growth & Insights and Company News

Headcount

6 month growth

-16%

1 year growth

-16%

2 year growth

-18%
Fortune
May 26th, 2026
Bolt CEO defends firing entire HR team as EEOC chair backs discrimination lawsuit against NYT

Bolt CEO Ryan Breslow sparked controversy at the Fortune Workplace Innovation Summit by revealing he fired his entire HR team, claiming they "created problems that didn't exist". The comments came one month after laying off roughly 30% of staff and amid reports of equity-for-salary arrangements and unpaid contractors, which Breslow denied. The summit also featured Andrea Lucas, chair of the Equal Employment Opportunity Commission, defending her agency's lawsuit against The New York Times for allegedly discriminating against a white male editor. Lucas rejected suggestions the case was politically motivated, stating "civil rights should be for everyone". Other summit discussions focused on AI's potential to reshape up to 50% of work hours within five years, according to McKinsey, alongside workplace culture topics including four-day workweeks and pay transparency.

RTTNews
Feb 18th, 2026
Berkshire Hathaway Discloses $350 Million Stake In The New York Times

Berkshire Hathaway, the conglomerate led by Warren Buffett, has disclosed a new $350 million investment in The New York Times Company..

Wikipedia
Dec 1st, 2025
Andrew Ross Sorkin

In October 2001, while a journalist at The New York Times, Sorkin started DealBook, a newsletter about deal-making and Wall Street.[19] DealBook was one of the first financial news aggregation services on the Internet.

Bloomberg
Aug 26th, 2025
Fivespan Takes Stake in New York Times (NYT)

The financiers that led a high-profile activist campaign at the New York Times Co. three years ago have now taken a stake in the iconic newspaper company via their new investment firm.

SBJ Media
Dec 27th, 2023
New York Times sues OpenAI, Microsoft

The New York Times has filed suit against OpenAI and Microsoft.