Chief Information Security Officer
Own the company's information security, governance, risk, and compliance programs, focusing on ISO 27001 readiness, certification, ongoing maintenance, SOC 2, vendor risk, customer security reviews, audits, policies, controls, risk management, metrics, and incident response governance.
Responsibilities
- Own and drive information security and compliance strategy focused on ISO 27001 readiness and maintenance
- Serve as executive owner for security compliance programs including ISO 27001, SOC 2, vendor risk, and customer security reviews
- Design, implement, and improve security governance frameworks, policies, standards, and risk management processes
- Partner with Engineering, Infrastructure, Product, Legal, and Operations to embed security and compliance requirements
- Lead and manage external audits, certifications, and assessments and act as primary contact for auditors
- Translate regulatory and customer security requirements into practical, scalable controls
- Manage the risk lifecycle including identification, assessment, prioritization, and executive reporting
- Establish and report security and compliance metrics to executive leadership and the board
- Oversee incident response governance, policies, playbooks, and escalation paths
Requirements
- 8–12+ years of experience in information security, GRC, or security leadership roles with ownership of compliance programs
- Hands-on experience leading ISO 27001 certification efforts
- Experience as a security leader in high-growth technology companies, ideally in fintech, payments, or regulated environments
- Strong understanding of security governance, risk management, and control frameworks including ISO 27001/27002, SOC 2, and NIST
- Experience partnering with engineering and technical teams to implement controls in cloud-native and application-driven environments
- Experience managing third-party risk, customer security questionnaires, and enterprise security reviews
- Ability to communicate risk, tradeoffs, and priorities to executives and non-technical stakeholders
- Nice to have: SOC 2 Type II, PCI DSS, ISO 22301, global regulatory requirements, security certifications, or board presentation experience
Benefits
- Unlimited time off with a minimum of 10 days required
- Flexible working and home workspace stipend
- Comprehensive health, dental, and vision plans for US employees and dependents
- Company-subsidized life insurance for US employees
- 401(k) with 4% company match
- Equity option plan
- Company-issued Rain Cards for product testing
- Health and wellness spending
- Domestic and international team and company summits