Hippo Insurance logo
Hippo InsurancePosted 2 months ago

Chief Information Security Officer (CISO)

$237,500–$390,000 year

HybridAustin, Texas, United States

Full TimeSenior LevelMediumInsurance

Job Summary

Develop and execute enterprise cybersecurity strategy aligned with business risk appetite and regulatory requirements for a publicly traded, multi-state insurance carrier. Build and lead security operations, including threat detection, incident response, vulnerability management, and threat intelligence, while owning the SOC 2 program end-to-end. Drive compliance with state and federal cybersecurity regulations, SEC disclosure obligations, and SOX audit cycles. Lead identity governance, privacy strategy, and third-party risk management, reporting directly to the Board of Directors and Audit and Risk Committee. Manage the security engineering function, disaster recovery, and business continuity planning, mentoring a team to embed security into engineering culture.

Required Qualifications

  • 10+ years of progressive experience in cybersecurity or information security
  • at least 5 years in a senior security leadership role (CISO, VP of Security, or Head of Information Security)
  • Experience at a regulated, publicly traded company
  • direct involvement in SOX audit cycles
  • Track record of building and managing security operations capabilities
  • End-to-end ownership of a SOC 2 program, including control design, audit preparation, and remediation
  • experience with cybersecurity regulations in a regulated industry (financial services, insurance, or healthcare)
  • Strong GRC background with experience maintaining risk registers, policy frameworks, and control libraries
  • Proven ability to present cybersecurity risk and incident information to boards of directors, audit committees, and regulators
  • Experience managing third-party and vendor cybersecurity risk programs
  • Excellent cross-functional leadership skills with a track record of partnering effectively with Legal, Finance, Internal Audit, and Engineering

Desired Qualifications

  • Experience in the insurance, Insurtech, or fintech industry
  • Familiarity with privacy frameworks and data protection requirements (CCPA/CPRA, state breach notification laws)
  • Relevant certifications such as CISSP, CISM, CRISC, or CISA
  • Background in security engineering or application security in addition to GRC and security operations
  • Experience managing cybersecurity programs across multi-entity corporate structures

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce