Chief Information Security Officer

Own the company's information security, governance, risk, and compliance programs, focusing on ISO 27001 readiness, certification, ongoing maintenance, SOC 2, vendor risk, customer security reviews, audits, policies, controls, risk management, metrics, and incident response governance.

Responsibilities

  • Own and drive information security and compliance strategy focused on ISO 27001 readiness and maintenance
  • Serve as executive owner for security compliance programs including ISO 27001, SOC 2, vendor risk, and customer security reviews
  • Design, implement, and improve security governance frameworks, policies, standards, and risk management processes
  • Partner with Engineering, Infrastructure, Product, Legal, and Operations to embed security and compliance requirements
  • Lead and manage external audits, certifications, and assessments and act as primary contact for auditors
  • Translate regulatory and customer security requirements into practical, scalable controls
  • Manage the risk lifecycle including identification, assessment, prioritization, and executive reporting
  • Establish and report security and compliance metrics to executive leadership and the board
  • Oversee incident response governance, policies, playbooks, and escalation paths

Requirements

  • 8–12+ years of experience in information security, GRC, or security leadership roles with ownership of compliance programs
  • Hands-on experience leading ISO 27001 certification efforts
  • Experience as a security leader in high-growth technology companies, ideally in fintech, payments, or regulated environments
  • Strong understanding of security governance, risk management, and control frameworks including ISO 27001/27002, SOC 2, and NIST
  • Experience partnering with engineering and technical teams to implement controls in cloud-native and application-driven environments
  • Experience managing third-party risk, customer security questionnaires, and enterprise security reviews
  • Ability to communicate risk, tradeoffs, and priorities to executives and non-technical stakeholders
  • Nice to have: SOC 2 Type II, PCI DSS, ISO 22301, global regulatory requirements, security certifications, or board presentation experience

Benefits

  • Unlimited time off with a minimum of 10 days required
  • Flexible working and home workspace stipend
  • Comprehensive health, dental, and vision plans for US employees and dependents
  • Company-subsidized life insurance for US employees
  • 401(k) with 4% company match
  • Equity option plan
  • Company-issued Rain Cards for product testing
  • Health and wellness spending
  • Domestic and international team and company summits

See also

要針對這個職缺調整履歷嗎?

目前無法檢查您與這個職缺的符合程度;請先將履歷加入個人檔案,下次即可查看。

A new version of freehire is available