Head of Information Security & IT
Leads Chronograph’s information security and IT strategy, combining executive leadership with hands-on oversight of cloud, application, AI, corporate, and compliance security. Requires at least seven years of security experience, broad technical depth, assurance-program leadership, and strong executive communication.
About the job
Responsibilities
- Own Chronograph’s information security program, strategy, architecture, and roadmap.
- Serve as the senior security leader in strategic client, partner, and external engagements.
- Lead and mentor a team of security, compliance, and IT practitioners.
- Assess security posture and prioritize pragmatic, high-impact improvements.
- Communicate security risks, priorities, and tradeoffs to executive leadership.
- Develop technical approaches, validate assumptions, build proofs of concept, and implement controls where appropriate.
- Partner with engineering and infrastructure teams on cloud, application, identity, logging, and security initiatives.
- Lead vulnerability management, threat modeling, secure development, application security architecture, detection, and incident response programs.
- Own application security tooling, including SAST, SCA, DAST, SOAR, secrets detection, and infrastructure-as-code scanning.
- Set AI security strategy, including controls for AI tools, agents, models, integrations, sensitive data, and permissions.
- Threat-model AI-enabled functionality and assess emerging offensive and defensive AI security developments.
- Own the detection and response stack, including SIEM, EDR, WAF, DLP, and alert-routing automation.
- Set direction for corporate IT, identity, endpoint management, and employee technology.
- Own SOC 1, SOC 2, ISO 27001, and broader security assurance strategy.
- Set direction for risk assessments, risk registers, policy lifecycle management, and third-party risk programs.
- Partner with compliance, sales, and customer teams on security due diligence and customer requirements.
Requirements
- 7+ years of information security experience, including meaningful hands-on technical experience and increasing ownership of security programs.
- Strong technical judgment and ability to investigate problems, develop solutions, build proofs of concept, and implement controls.
- Broad experience across cloud and application security, identity, vulnerability management, and detection and response.
- Experience owning or materially leading an information security program covering risk management, policies, controls, and security roadmaps.
- Experience with security frameworks such as NIST, CIS, or GDPR.
- Experience leading SOC 1, SOC 2, ISO 27001, or comparable assurance and certification programs.
- Experience representing security controls, certifications, and risk posture to enterprise customers and auditors.
- Strong understanding of emerging threats and the security implications of AI.
- Strong executive communication skills and ability to translate technical risks and controls into clear business language.
Compensation and Benefits
- Salary: $215,000–$250,000 annually.
- Equity participation.
- 401(k).
- Unlimited and flexible vacation.
- Health benefits.
- Team week events at the Brooklyn, NY headquarters three times annually.
- Fully paid parental leave.
Skills
Information Security, Cloud Security, Application Security, Identity Management, Vulnerability Management, Incident Response, SIEM, Edr, Waf, Dlp, SAST, Sca, DAST, Soar, ISO 27001
Similar jobs
Security Engineering jobsLeads GameChanger’s Information Security and Technology strategy, teams, roadmap, and risk decisions, with primary focus on product and application security. Requires 10+ years of security experience, broad security-program leadership, and experience managing technical leaders and partnering with Engineering and executives.
Leads LogicGate’s internal security organization, compliance posture, risk management, and customer trust program while serving as Deputy CISO. Requires 7–10 years of information security experience, substantial people leadership, SaaS compliance expertise, and strong technical knowledge of modern security architectures.
Leads ID.me’s Product Security program and security engineering team, partnering with Product and Engineering to reduce risk through practical, developer-aligned controls. Requires strong technical depth across application and cloud security, outcome-based leadership, and experience building security programs in fast-moving cloud-native environments.
Leads technical security, compliance (SOC 2, GDPR, ISO 42001), vulnerability management, and infrastructure hardening for a fast-growing fintech. Requires 3-7 years in security engineering with hands-on AWS, vuln tooling, and audit experience.
Leads Exa’s company-wide security strategy, architecture, engineering, governance, incident response, and team development across AI infrastructure, cloud, products, and corporate systems. Requires executive-level security accountability and deep technical credibility in a rapidly scaling technology company.