CISO
Owns security governance, risk, and compliance strategy with focus on ISO 27001 certification and regulatory readiness in a fintech environment. Partners with engineering and leadership to implement controls, manage audits, and report risks; requires 8-12+ years in security leadership.
About the job
Responsibilities
- Own and drive Rain’s information security and compliance strategy, with a primary focus on ISO 27001 (and related standards) readiness, certification, and ongoing maintenance.
- Serve as the executive owner for security compliance programs (e.g., ISO 27001, SOC 2, vendor risk, customer security reviews).
- Design, implement, and continuously improve Rain’s security governance framework, including policies, standards, and risk management processes.
- Partner closely with Engineering, Infrastructure, Product, Legal, and Operations to embed compliance and security requirements into technical and business workflows.
- Lead and manage external audits, certifications, and assessments, acting as the primary point of contact for auditors and assessors.
- Translate regulatory, customer, and partner security requirements into practical, scalable controls that align with Rain’s architecture and operating model.
- Own the risk management lifecycle, including risk identification, assessment, prioritization, and executive reporting.
- Establish and track security and compliance metrics, reporting posture, progress, and risk to executive leadership and the board as needed.
- Oversee incident response governance, ensuring policies, playbooks, and escalation paths meet compliance and regulatory expectations.
Requirements
- 8–12+ years of experience in information security, GRC, or security leadership roles, with demonstrated ownership of compliance programs.
- Hands-on experience leading ISO 27001 certification efforts (initial certification and/or ongoing surveillance audits).
- Experience operating as a security leader in a high-growth, technology-driven company, ideally in fintech, payments, or regulated environments.
- Strong understanding of security governance, risk management, and control frameworks (ISO 27001/27002, SOC 2, NIST, etc.).
- Proven ability to partner effectively with engineering and technical teams to implement controls in cloud-native and application-driven environments.
- Experience managing third-party risk, customer security questionnaires, and enterprise security reviews.
- Ability to clearly communicate risk, tradeoffs, and priorities to executives and non-technical stakeholders.
Nice to Haves
- Experience with additional frameworks such as SOC 2 Type II, PCI DSS, ISO 22301, or regional regulatory requirements.
- Prior experience acting as a first or early security leader at a scaling company.
- Familiarity with cloud security and modern application architectures, even if not hands-on day-to-day.
- Experience supporting global customers or international compliance requirements.
- Security or compliance certifications (e.g., CISSP, CISM, ISO 27001 Lead Implementer / Auditor).
- Experience presenting security posture or risk assessments to boards or executive committees.
Skills
ISO 27001, Iso 27002, SOC 2, Nist, GRC, Cloud Security, Risk Management, Incident Response, Pci Dss, Cissp, Cism
Similar jobs
Security Engineering jobsLeads company-wide information security, data governance, compliance, and risk programs while driving AI security strategy and executive-level governance. The role requires board presentation experience, enterprise customer engagement, vendor and supply chain risk expertise, and multiple security certifications.
Executive leader responsible for setting strategy and leading Huntress’s global Threat Detection & Response organization across SOC, incident response, detection engineering, threat hunting, and adversary tactics. Requires 10+ years in security leadership and 5+ years managing managers and directors.
Leads LogicGate’s internal security organization, compliance posture, risk management, and customer trust program while serving as Deputy CISO. Requires 7–10 years of information security experience, substantial people leadership, SaaS compliance expertise, and strong technical knowledge of modern security architectures.
Leads GameChanger’s Information Security and Technology strategy, teams, roadmap, and risk decisions, with primary focus on product and application security. Requires 10+ years of security experience, broad security-program leadership, and experience managing technical leaders and partnering with Engineering and executives.
Leads Exa’s company-wide security strategy, architecture, engineering, governance, incident response, and team development across AI infrastructure, cloud, products, and corporate systems. Requires executive-level security accountability and deep technical credibility in a rapidly scaling technology company.