Chief Information Security Officer (CISO)
The job description
Tech stack. Enterprise risk management, security governance frameworks (NIST CSF, ISO 27001), board reporting, security budgeting and vendor management, incident command, regulatory compliance (SOC 2, GDPR, PCI DSS), security organization design
About the role
You will own cybersecurity for a technology company as its most senior security leader, personally accountable to the executive team and the board for how cyber risk is managed. The role spans security strategy, organization building, major incident command, and regulatory compliance across every business unit and geography. You will set multi-year direction, build the leadership bench, manage the budget, and represent the company to regulators and customers. This matters because security at this scale is fundamentally a business discipline: you translate technical risk into business decisions, build an organization capable of executing on them, and answer directly for the outcomes when serious incidents occur.
What you will achieve
- Define the three-year security strategy, funded and formally adopted by the executive team, with measurable risk reduction targets reviewed annually.
- Build and lead a security organization of 30+ professionals spanning engineering, operations, governance, and offensive security functions.
- Present to the board of directors quarterly with risk metrics directors genuinely understand and act upon.
- Achieve and maintain the certifications the business requires to sell and operate: SOC 2 Type II, ISO 27001, and regional equivalents.
- Command major incident response end to end, from technical containment through regulatory notification and customer communication.
What you will bring
Must-haves
- 15+ years in cybersecurity with 5+ years leading security organizations or large, complex security functions.
- Proven ability to set security strategy and secure genuine executive and board-level sponsorship and funding.
- Deep understanding of risk management as a discipline: quantifying, accepting, mitigating, and transferring cyber risk.
- Experience building and scaling security teams, including hiring, developing, and retaining senior leaders.
- Track record leading enterprise incident response with legal, regulatory, and reputational dimensions simultaneously.
- Strong grasp of compliance frameworks: SOC 2, ISO 27001, GDPR, PCI DSS, or equivalents across jurisdictions.
- Executive presence: you brief boards confidently, negotiate with vendors firmly, and represent the company to regulators credibly.
Nice-to-haves
- Prior CISO, deputy CISO, or VP of security experience at a comparable-scale company.
- CISSP, CISM, or an equivalent senior leadership credential.
- Experience with M&A security diligence and post-acquisition integration programs.
- Background in a regulated industry such as financial services or healthcare.
Google
Microsoft
CrowdStrike
Palo Alto Networks
Cisco
Okta