Skip to content
Aramis:Insight

Roles

Deputy CISO

You back up the CISO across strategy, policy, running the program, and leading people.

Competency areas

  • Systems Security Management
  • Executive Cybersecurity Leadership
  • Cybersecurity Policy and Planning
  • Program Management
  • Cybersecurity Workforce Management

Sample questions

Three real questions from this role's assessment, with the answer, the reasoning, and the NICE statement each one measures. The full assessment draws from hundreds like these.

Sample question 1

Cielo Financial Group finished acquiring a payments startup six months ago. The cybersecurity strategic plan you maintain for the GRC team was last formally reviewed fourteen months ago, before the acquisition, and still reflects only the parent company's risk profile, regulatory scope, and staffing assumptions. The CISO asks you to prepare the plan for next month's board cybersecurity update. What should you do?

  1. A.Present the existing plan to the board unchanged, since it was formally approved only fourteen months ago and remains within the organization's normal two-year strategic-plan review cycle, so no revision is warranted until that scheduled cycle arrives regardless of the acquisition.
  2. B.Attach a short appendix summarizing the acquisition's cybersecurity risks to the existing plan for the board's awareness, since the plan's core objectives, regulatory scope, and resourcing assumptions do not need to change, only supplementary background material does.
  3. C.Set the existing plan aside and draft an entirely new strategic plan for the combined organization from scratch, since a plan written before a material acquisition offers no valid starting point once the business it describes has changed shape.
  4. D.Revise the plan's risk profile, regulatory scope, and resourcing assumptions to reflect the combined organization, then bring that updated plan to the board, since ongoing organizational change means the plan itself needs updating, not just a status report.
Show the answer and reasoning

Correct answer: D

Option D is correct because maintaining a strategic plan means keeping it current against real organizational change; a material acquisition that introduces a different risk profile and new regulatory exposure requires revising the plan's risk profile, regulatory scope, and resourcing assumptions before it is presented as the organization's current strategy. The present-unchanged option is wrong because a scheduled review cycle is a floor, not a ceiling; a material event like an acquisition is itself a trigger for review regardless of where the organization sits in its normal cycle. The appendix-only option is wrong because it treats the acquisition as background context rather than something that changes the plan's substance, when the acquisition actually alters the very risk profile, regulatory scope, and resourcing assumptions the plan is built on. The rebuild-from-scratch option is wrong because discarding the prior plan's objectives and risk work throws away a valid baseline that still applies to the parent organization; the correct response is to revise and extend that baseline for the combined entity, not treat it as worthless.

This question measures: T1146: Maintain strategic plans

Sample question 2

Your organization's risk acceptance process requires business unit leaders to sign off on accepted risks. An audit reveals that most sign-offs occur without evidence that leaders understood the risks they accepted.

Your organization's CISO has asked you to recommend improvements to the risk acceptance process after discovering that several high-risk vulnerabilities were approved without executives understanding the potential business impact. Which governance enhancement would best ensure meaningful risk acceptance decisions?

  1. A.Implement automated risk acceptance for findings that meet predefined criteria based on vulnerability severity ratings and asset criticality scores
  2. B.Streamline the approval workflow by allowing department heads to accept risks below a predetermined risk score threshold without additional review
  3. C.Consolidate risk acceptance authority within the information security team to leverage their technical expertise in evaluating cybersecurity threats
  4. D.Require risk owners to attend presentation sessions where technical and business implications are explained before documenting their informed acknowledgment.
Show the answer and reasoning

Correct answer: D

Requiring risk owners to attend presentation sessions where technical and business implications are explained before documenting acknowledgment directly addresses the core problem, executives accepting risks without understanding them. This governance enhancement maintains appropriate business ownership of risk decisions while ensuring decision-makers have the necessary context for informed choices rather than rubber-stamp approvals. Consolidating authority within the information security team incorrectly removes business ownership and may lack business context. Streamlining approvals by allowing department heads to bypass review would worsen the problem by reducing oversight and enabling more uninformed approvals. Implementing automated risk acceptance removes human judgment entirely, which fails to address the need for informed business decision-making.

This question measures: K0675: Knowledge of risk management processes

Sample question 3

Before a draft data-retention policy goes to the board, you are asked to evaluate it. The entire operative text reads: "Data will be retained only as long as necessary and disposed of securely." Evaluating the policy as an instrument the organization must operate under, what is its most significant weakness?

  1. A.It uses the passive voice, which weakens the authority of a governance document.
  2. B.It does not cite the specific statutes that impose retention obligations on the company.
  3. C.It states a principle but sets no retention period or owner, so it cannot be enforced or audited.
  4. D.It should be merged with the acceptable-use policy to reduce the number of governance documents.
Show the answer and reasoning

Correct answer: C

A policy has to be operable: without a defined retention period, a disposal standard, or a named owner, "as long as necessary" cannot be applied consistently, enforced, or tested in an audit, which is the core defect here. The passive voice is a style observation that does not change whether the policy can be carried out. Citing specific statutes would help, but a policy can be enforceable without reciting the law, so the missing citations are not the governing weakness. Merging it with the acceptable-use policy is a document-count preference that leaves the same substantive gap unaddressed.

This question measures: S0416: Skill in evaluating policies

Measure yourself against this role

Job description templates

Three ready-to-edit drafts for hiring managers and recruiters: copy one, replace the bracketed lines, and post it. Responsibilities and requirements are drawn from the same NICE statements this role is measured against.

Statements use the official NICE Framework wording, which is published in English.

Deputy CISO: Junior

We are hiring a junior Deputy CISO. You back up the CISO across strategy, policy, running the program, and leading people. At this level you take on well-defined parts of the work, with senior colleagues to learn from, and grow into the rest.

[Company] provides [what you do]. The security function is [size and shape: e.g., a five-person team reporting to the CTO]. Replace this paragraph with your own.

Responsibilities

  • Resolve conflicts in laws, regulations, policies, standards, or procedures
  • Integrate leadership priorities
  • Conduct an effective enterprise continuity of operations program
  • Advise senior management on risk levels and security posture
  • Perform cost/benefit analyses of cybersecurity programs, policies, processes, systems, and elements
  • Advise senior management on organizational cybersecurity efforts
  • Advise senior leadership and authorizing official of changes affecting the organization's cybersecurity posture
  • Communicate the value of cybersecurity to organizational stakeholders
  • Pair with senior colleagues and grow through structured feedback.
  • Document what you do so the team learns with you.

Required knowledge

  • Risk management processes
  • Business continuity and disaster recovery (BCDR) policies and procedures
  • Enterprise cybersecurity architecture principles and practices
  • Risk management models and frameworks
  • Resource management principles and practices
  • Decision-making policies and procedures
  • Organization's security strategy
  • Organizational cybersecurity goals and objectives

Skills

  • Developing policy plans
  • Communicating effectively
  • Analyzing organizational objectives
  • Evaluating laws
  • Evaluating regulations

How to use this template

Copy the draft, replace every bracketed line, cut statements that do not apply to your opening, and add your compensation range and location policy. The statement lists come from the NIST NICE Framework v2.2.0, so candidates can be assessed against the same statements with Aramis:Insight.

Deputy CISO: Mid-level

We are hiring a mid-level Deputy CISO. You back up the CISO across strategy, policy, running the program, and leading people. You own this work day to day and work closely with the rest of the security team.

[Company] provides [what you do]. The security function is [size and shape: e.g., a five-person team reporting to the CTO]. Replace this paragraph with your own.

Responsibilities

  • Resolve conflicts in laws, regulations, policies, standards, or procedures
  • Integrate leadership priorities
  • Conduct an effective enterprise continuity of operations program
  • Advise senior management on risk levels and security posture
  • Perform cost/benefit analyses of cybersecurity programs, policies, processes, systems, and elements
  • Advise senior management on organizational cybersecurity efforts
  • Advise senior leadership and authorizing official of changes affecting the organization's cybersecurity posture
  • Communicate the value of cybersecurity to organizational stakeholders
  • Develop strategic plans
  • Maintain strategic plans
  • Determine if security engineering is used when acquiring or developing protection and detection capabilities
  • Determine if protection and detection capabilities are consistent with organization-level cybersecurity architecture

Required knowledge

  • Risk management processes
  • Business continuity and disaster recovery (BCDR) policies and procedures
  • Enterprise cybersecurity architecture principles and practices
  • Risk management models and frameworks
  • Resource management principles and practices
  • Decision-making policies and procedures
  • Organization's security strategy
  • Organizational cybersecurity goals and objectives
  • Organizational cybersecurity policies and procedures
  • Organizational cybersecurity workforce requirements
  • Risk mitigation principles and practices
  • Technology integration processes

Skills

  • Developing policy plans
  • Communicating effectively
  • Analyzing organizational objectives
  • Evaluating laws
  • Evaluating regulations
  • Establishing priorities
  • Preparing reports
  • Managing a workforce

How to use this template

Copy the draft, replace every bracketed line, cut statements that do not apply to your opening, and add your compensation range and location policy. The statement lists come from the NIST NICE Framework v2.2.0, so candidates can be assessed against the same statements with Aramis:Insight.

Deputy CISO: Senior

We are hiring a senior Deputy CISO. You back up the CISO across strategy, policy, running the program, and leading people. You set the direction for this work, mentor the people who do it, and answer for its results.

[Company] provides [what you do]. The security function is [size and shape: e.g., a five-person team reporting to the CTO]. Replace this paragraph with your own.

Responsibilities

  • Resolve conflicts in laws, regulations, policies, standards, or procedures
  • Integrate leadership priorities
  • Conduct an effective enterprise continuity of operations program
  • Advise senior management on risk levels and security posture
  • Perform cost/benefit analyses of cybersecurity programs, policies, processes, systems, and elements
  • Advise senior management on organizational cybersecurity efforts
  • Advise senior leadership and authorizing official of changes affecting the organization's cybersecurity posture
  • Communicate the value of cybersecurity to organizational stakeholders
  • Develop strategic plans
  • Maintain strategic plans
  • Determine if security engineering is used when acquiring or developing protection and detection capabilities
  • Determine if protection and detection capabilities are consistent with organization-level cybersecurity architecture
  • Align cybersecurity priorities with organizational security strategy
  • Manage cybersecurity budget, staffing, and contracting
  • Determine the effectiveness of enterprise cybersecurity safeguards
  • Communicate situational awareness information to leadership
  • Mentor junior team members and review their work.
  • Represent this function to leadership and to auditors or clients.
  • Set standards, select tooling, and own the roadmap for this area.

Required knowledge

  • Risk management processes
  • Business continuity and disaster recovery (BCDR) policies and procedures
  • Enterprise cybersecurity architecture principles and practices
  • Risk management models and frameworks
  • Resource management principles and practices
  • Decision-making policies and procedures
  • Organization's security strategy
  • Organizational cybersecurity goals and objectives
  • Organizational cybersecurity policies and procedures
  • Organizational cybersecurity workforce requirements
  • Risk mitigation principles and practices
  • Technology integration processes
  • Cybersecurity operation policies and procedures
  • Career paths

Skills

  • Developing policy plans
  • Communicating effectively
  • Analyzing organizational objectives
  • Evaluating laws
  • Evaluating regulations
  • Establishing priorities
  • Preparing reports
  • Managing a workforce
  • Performing risk assessments
  • Developing comprehensive cyber operations assessment programs

How to use this template

Copy the draft, replace every bracketed line, cut statements that do not apply to your opening, and add your compensation range and location policy. The statement lists come from the NIST NICE Framework v2.2.0, so candidates can be assessed against the same statements with Aramis:Insight.

Related roles

Roles with similar work or at a similar career stage. Each has its own job description templates and a free assessment.