Passer les menus de navigation
Logo Acorn

Chief Information Security Officer (CISO) / RSSI: Roles, Skills, and Career Path

The Chief Information Security Officer, or CISO (RSSI in French), defines the organization’s cybersecurity policy. They evaluate vulnerabilities, organize prevention, supervise incident response, and ensure the protection of systems, data, and business continuity. According to RSB internal data, the average salary observed among graduates with 0 to 2 years of experience is €51,100 gross annual including bonuses (based on graduates in France). Job opportunities are particularly located in consulting, IT services, cybersecurity software editing, and information systems departments.

RECOMMENDED COURSE

MSc Cyber Security and Risk Management

Combines governance, cybersecurity, and risk management to prepare students for leading information systems security.

Discover the programme

In figures:

€51,100
Average RSB salary, 0–2 years, annual with bonuses (France)
CONSULTING, IT
Recruiting sectors
86 %
of surveyed RSB graduates are satisfied or very satisfied with their job

This career is for you if…

  • You are interested in technology, risks, and data protection.
  • You can analyse a complex situation and prioritise tasks.
  • You are rigorous, discreet, and responsive.
  • You enjoy coordinating between technical teams and management.
  • You can make decisions under pressure.

Recommended programme

MSc Cyber Security and Risk Management

Combines governance, cybersecurity, and risk management to prepare students for leading information systems security.

Discover the programme

A typical day: Chief Information Security Officer (CISO) / RSSI

The day may start with reviewing security alerts and incidents. You interact with IT, business, legal, and compliance teams to assess risks and decide on actions. You might manage an audit, validate an architecture, prepare a crisis exercise, follow up on a remediation plan, or present cybersecurity indicators to the executive committee.

Main responsibilities

Governance and prevention

You define security rules, carry out or lead audits, map risks, and prioritise protective investments.

Incidents and resilience

You organise detection and incident response, coordinate teams in crisis situations, and test business continuity and disaster recovery plans.

What salary can you expect?

Level Gross annual salary (based in France) Source
Junior · 0–2 years €51,000 RSB internal data · employment survey
Mid-level · 3–5 years €60,000 RSB internal data · employment survey
Senior · 7+ years Varies depending on sector, scope, and responsibilities Remuneration may include variable components

Source: RSB internal employment survey, conducted with a sample of Alumni. Average gross annual salary, bonuses included among graduates working in France.

Which training path to become a Chief Information Security Officer (CISO) / RSSI?

The recommended route at RSB

The MSc Cyber Security and Risk Management is the primary specialised pathway. It combines governance, cybersecurity, and risk management to prepare students for leading information systems security.

Possible initial steps

The Bachelor in Management provides essential foundations in administration and management. It can be followed by the Master in Management (Programme Grande École) or a specialised MSc.

Skills to develop

A Master's-level qualification (5-year degree), internship or work-study experience, a high level of English proficiency, and mastery of field-specific tools facilitate access to initial roles.

Recruiting partner companies

WAVESTONE – NIJI – EY – SOPRA STERIA – TEHTRIS

Discover the associated RSB programme

Your first steps in the profession

You can start as a SOC Analyst, Cybersecurity Consultant, Security Auditor, or Cyber Risk Analyst. These initial experiences allow you to master the tools, methods, and mechanics of the sector.

Gaining autonomy

With experience, you can progress to roles such as Security Manager, Cybersecurity Project Manager, or Deputy CISO. You will oversee a broader scope, more complex projects, and increased coordination.

Reaching senior leadership roles

With several years of experience, you can advance to

  • CISO / RSSI
  • Director of Cybersecurity
  • Digital Risk Officer
  • Senior Cybersecurity Consultant

These careers might also interest you…

Discover professions that draw on similar or complementary skills.

Risk Manager Financial Analyst

Management / Strategy Consultant

FAQs about the Chief Information Security Officer (CISO) role

What is the difference between RSSI and CISO?

Both titles generally refer to the person responsible for information systems security. CISO is the English acronym for Chief Information Security Officer, while RSSI is its French equivalent.

Does a CISO need to be a technical expert?

They must understand technical challenges, but their role is also strategic and managerial: governance, budget, compliance, risk management, communication, and crisis handling.

Which skills are required?

Cyber risk management, network and systems security, auditing, governance, regulatory compliance, crisis management, leadership, and executive communication.

Which qualification should you pursue?

A 5-year degree (Master’s level) in cybersecurity, IT, risk management, or business management is generally expected. The MSc Cyber Security and Risk Management at Rennes School of Business is designed for this type of career.

What is the salary of a junior Chief Information Security Officer (CISO)?

A junior CISO earns a particularly high starting salary upon graduation. According to internal data from RSB (Rennes School of Business), the average salary observed among graduates with 0 to 2 years of experience reaches €51,100 gross annual including bonuses. This figure increases rapidly to €60,000 after 3 to 5 years of experience, driven by high demand in the tech job market. These figures are based on graduates working in France.

What types of companies hire a Chief Information Security Officer?

A CISO mainly works within cybersecurity consulting firms (Wavestone, EY), IT service companies, and security software vendors (TEHTRIS). They are also highly sought after by large corporations and public institutions to directly join their Information Systems Department (IT Department) to protect strategic data.

Interested in a career as a Chief Information Security Officer (CISO)?

Discover the MSc Cyber Security and Risk Management at Rennes School of Business, a programme designed to combine governance, cybersecurity, and risk management to prepare students for leading information systems security.

Discover the programme