Chief Information Security Officer
Title: Chief Information Security Officer (CISO)
Location: San Francisco, CA (Hybrid)
Experience: 15+ years in cybersecurity, including 5+ years in a leadership role.
Compensation: $450,000 - $600,000 base salary + performance bonus + equity
We are seeking an experienced Chief Information Security Officer (CISO) to lead our cybersecurity strategy in a high-growth, cloud-native, and open-source-driven organization. This role is ideal for a security leader who understands how to balance risk management with innovation while securing complex, distributed environments.
Responsibilities
- Develop and implement a comprehensive cybersecurity strategy aligned with business objectives.
- Establish and enforce security policies, frameworks, and best practices to ensure compliance with SOC 2, ISO 27001, FedRAMP, HIPAA, and GDPR.
- Oversee risk management, threat modeling, and security audits across enterprise and cloud infrastructure.
- Lead security operations, including incident response, digital forensics, and threat intelligence programs.
- Secure cloud-native environments, including AWS, Azure, Google Cloud, Kubernetes, and containerized applications.
- Integrate DevSecOps principles into CI/CD pipelines, ensuring security is embedded within development workflows.
- Collaborate with engineering, IT, compliance, and executive teams to ensure security supports business goals.
- Communicate cybersecurity risks, strategies, and investments to the executive leadership team and board.
- Lead security awareness initiatives, fostering a security-first culture across the organization.
Experience & Qualifications
- Leadership Experience: Minimum 15 years in information security, with at least 5-7 years in senior leadership roles (e.g., Director, VP, or CISO) within SaaS, cloud infrastructure, open-source software, or similar technology-driven industries.
- Cloud & Security Expertise: Extensive experience securing cloud-native architectures, including containers (Docker, Kubernetes), infrastructure-as-code, and multi-cloud environments (AWS, Azure, GCP). Expertise in IAM, network security, endpoint protection, and securing cloud services is essential.
- Risk Management & Compliance: Proven track record in risk management, including hands-on experience with NIST, ISO 27001, SOC 2, and ensuring compliance with global data protection laws (e.g., GDPR, HIPAA). Skilled in leading security audits and implementing security controls to meet regulatory requirements.
- Incident Response Leadership: Demonstrated ability to lead incident response teams during security breaches and high-stress incidents. Experience with disaster recovery and business continuity planning.
- Security Program Development: Experience building and scaling information security programs, implementing DevSecOps, secure SDLC practices, and integrating security into CI/CD pipelines.
- Business & Strategic Acumen: Strong ability to align security objectives with broader business goals. Proven success in communicating security risks and strategies effectively to C-suite executives and boards of directors.
- Certifications & Education: CISSP, CISM, CISA, CCSP, or other relevant certifications. Cloud security certifications (AWS Certified Security Specialty, Azure Security Engineer, etc.) are a plus.
- Global Security Experience: Experience in managing international security risks and compliance with cross-border data protection and privacy laws.
- Innovation in Security: Ability to drive security innovation and stay ahead of emerging trends in cybersecurity, such as zero-trust architectures, AI/ML-driven security, and automated security practices.
This role is suited for a senior security leader with a strong technical background and a strategic mindset. If you are looking for an opportunity to shape security in a fast-scaling, cloud-first organization, we invite you to apply.
Title: Chief Information Security Officer (CISO)
Location: San Francisco, CA (Hybrid)
Experience: 15+ years in cybersecurity, including 5+ years in a leadership role.
Compensation: $450,000 - $600,000 base salary + performance bonus + equity
We are seeking an experienced Chief Information Security Officer (CISO) to lead our cybersecurity strategy in a high-growth, cloud-native, and open-source-driven organization. This role is ideal for a security leader who understands how to balance risk management with innovation while securing complex, distributed environments.
Responsibilities
- Develop and implement a comprehensive cybersecurity strategy aligned with business objectives.
- Establish and enforce security policies, frameworks, and best practices to ensure compliance with SOC 2, ISO 27001, FedRAMP, HIPAA, and GDPR.
- Oversee risk management, threat modeling, and security audits across enterprise and cloud infrastructure.
- Lead security operations, including incident response, digital forensics, and threat intelligence programs.
- Secure cloud-native environments, including AWS, Azure, Google Cloud, Kubernetes, and containerized applications.
- Integrate DevSecOps principles into CI/CD pipelines, ensuring security is embedded within development workflows.
- Collaborate with engineering, IT, compliance, and executive teams to ensure security supports business goals.
- Communicate cybersecurity risks, strategies, and investments to the executive leadership team and board.
- Lead security awareness initiatives, fostering a security-first culture across the organization.
Experience & Qualifications
- Leadership Experience: Minimum 15 years in information security, with at least 5-7 years in senior leadership roles (e.g., Director, VP, or CISO) within SaaS, cloud infrastructure, open-source software, or similar technology-driven industries.
- Cloud & Security Expertise: Extensive experience securing cloud-native architectures, including containers (Docker, Kubernetes), infrastructure-as-code, and multi-cloud environments (AWS, Azure, GCP). Expertise in IAM, network security, endpoint protection, and securing cloud services is essential.
- Risk Management & Compliance: Proven track record in risk management, including hands-on experience with NIST, ISO 27001, SOC 2, and ensuring compliance with global data protection laws (e.g., GDPR, HIPAA). Skilled in leading security audits and implementing security controls to meet regulatory requirements.
- Incident Response Leadership: Demonstrated ability to lead incident response teams during security breaches and high-stress incidents. Experience with disaster recovery and business continuity planning.
- Security Program Development: Experience building and scaling information security programs, implementing DevSecOps, secure SDLC practices, and integrating security into CI/CD pipelines.
- Business & Strategic Acumen: Strong ability to align security objectives with broader business goals. Proven success in communicating security risks and strategies effectively to C-suite executives and boards of directors.
- Certifications & Education: CISSP, CISM, CISA, CCSP, or other relevant certifications. Cloud security certifications (AWS Certified Security Specialty, Azure Security Engineer, etc.) are a plus.
- Global Security Experience: Experience in managing international security risks and compliance with cross-border data protection and privacy laws.
- Innovation in Security: Ability to drive security innovation and stay ahead of emerging trends in cybersecurity, such as zero-trust architectures, AI/ML-driven security, and automated security practices.
This role is suited for a senior security leader with a strong technical background and a strategic mindset. If you are looking for an opportunity to shape security in a fast-scaling, cloud-first organization, we invite you to apply.