Chief Information Security Officer (CISO)
$237,500–$390,000 year
HybridAustin, Texas, United States
Job Summary
Develop and execute enterprise cybersecurity strategy aligned with business risk appetite and regulatory requirements for a publicly traded, multi-state insurance carrier. Build and lead security operations, including threat detection, incident response, vulnerability management, and threat intelligence, while owning the SOC 2 program end-to-end. Drive compliance with state and federal cybersecurity regulations, SEC disclosure obligations, and SOX audit cycles. Lead identity governance, privacy strategy, and third-party risk management, reporting directly to the Board of Directors and Audit and Risk Committee. Manage the security engineering function, disaster recovery, and business continuity planning, mentoring a team to embed security into engineering culture.
Required Qualifications
- 10+ years of progressive experience in cybersecurity or information security
- at least 5 years in a senior security leadership role (CISO, VP of Security, or Head of Information Security)
- Experience at a regulated, publicly traded company
- direct involvement in SOX audit cycles
- Track record of building and managing security operations capabilities
- End-to-end ownership of a SOC 2 program, including control design, audit preparation, and remediation
- experience with cybersecurity regulations in a regulated industry (financial services, insurance, or healthcare)
- Strong GRC background with experience maintaining risk registers, policy frameworks, and control libraries
- Proven ability to present cybersecurity risk and incident information to boards of directors, audit committees, and regulators
- Experience managing third-party and vendor cybersecurity risk programs
- Excellent cross-functional leadership skills with a track record of partnering effectively with Legal, Finance, Internal Audit, and Engineering
Desired Qualifications
- Experience in the insurance, Insurtech, or fintech industry
- Familiarity with privacy frameworks and data protection requirements (CCPA/CPRA, state breach notification laws)
- Relevant certifications such as CISSP, CISM, CRISC, or CISA
- Background in security engineering or application security in addition to GRC and security operations
- Experience managing cybersecurity programs across multi-entity corporate structures
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.