Deputy Chief Information Security Officer
Leads company-wide information security, data governance, compliance, and risk programs while driving AI security strategy and executive-level governance. The role requires board presentation experience, enterprise customer engagement, vendor and supply chain risk expertise, and multiple security certifications.
About the job
Responsibilities
Company-Wide Security & Compliance Leadership
- Drive, scale, and execute enterprise-wide information security, risk management, and compliance programs aligned with organizational goals and regulatory standards.
AI & Data Security Strategy
- Drive AI and data security initiatives across the company.
- Embed data protection, governance, and threat modeling into product development lifecycles.
Executive & Board Governance
- Prepare materials and present security posture, cyber risk metrics, and strategic roadmaps to executive staff, the Audit Committee, and the Board of Directors.
Legal, Privacy & AI Partnership
- Collaborate with Legal and Risk teams on privacy requirements, AI/ML governance frameworks, regulatory compliance, and technological risk management.
Customer Assurance & External Audits
- Act as an executive security ambassador with enterprise customers, prospects, and auditors.
- Address security architecture, compliance requirements, and audit reviews.
Vendor & Supply Chain Risk Management
- Architect and oversee vendor risk management and software supply chain security programs.
Enterprise Security Operations
- Provide leadership oversight for detection and response, identity and access governance, and cloud-native enterprise security posture.
Requirements
- Hold the following certifications:
- Certified Information Systems Security Professional (CISSP)
- Certified Information Privacy Technologist (CIPT)
- Factor Analysis of Information Risk (FAIR) Certification
- Certified in Risk and Information Systems Control (CRISC)
- Proven experience presenting complex risk concepts, security strategies, and incident reports to Audit Committees and Board members.
- Hands-on experience architecting, evaluating, or deploying AI security solutions and AI safety or governance frameworks.
- Extensive experience managing enterprise vendor risk management, third-party compliance, and software supply chain risk.
- High degree of comfort representing security in high-stakes enterprise customer meetings, sales cycles, and compliance audits.
Nice-to-Haves
- Experience overseeing detection and response operations in modern, cloud-native SaaS environments.
- Deep experience with enterprise security platforms, especially Okta and CrowdStrike.
- Background in high-growth technology companies, AI/ML products, or B2B technology sectors.
Compensation
- Annual salary range: $200,000–$250,000.
Skills
Information Security, Risk Management, Compliance, Ai Security, Data Governance, Threat Modeling, Ai/Ml Governance, Vendor Risk Management, Software Supply Chain Security, Cloud Security, Identity And Access Management, Okta, Crowdstrike, Incident Response, Cissp
Similar jobs
Security Engineering jobsExecutive leader responsible for setting strategy and leading Huntress’s global Threat Detection & Response organization across SOC, incident response, detection engineering, threat hunting, and adversary tactics. Requires 10+ years in security leadership and 5+ years managing managers and directors.
Leads Chronograph’s information security and IT strategy, combining executive leadership with hands-on oversight of cloud, application, AI, corporate, and compliance security. Requires at least seven years of security experience, broad technical depth, assurance-program leadership, and strong executive communication.
Leads technical security, compliance (SOC 2, GDPR, ISO 42001), vulnerability management, and infrastructure hardening for a fast-growing fintech. Requires 3-7 years in security engineering with hands-on AWS, vuln tooling, and audit experience.
Leads GameChanger’s Information Security and Technology strategy, teams, roadmap, and risk decisions, with primary focus on product and application security. Requires 10+ years of security experience, broad security-program leadership, and experience managing technical leaders and partnering with Engineering and executives.
Leads ID.me’s Product Security program and security engineering team, partnering with Product and Engineering to reduce risk through practical, developer-aligned controls. Requires strong technical depth across application and cloud security, outcome-based leadership, and experience building security programs in fast-moving cloud-native environments.