Deputy Chief Information Security Officer
$200,000–$250,000 year
HybridSan Francisco, California, United States or Carson City, Nevada, United States
Job Summary
Lead company-wide security, data governance, and compliance programs aligned with organizational goals and regulatory standards. Drive AI and data security initiatives across the organization, embedding robust data protection and threat modeling directly into product development lifecycles. Prepare materials and present security posture, cyber risk metrics, and strategic roadmaps to executive leadership, the Board of Directors, and the Audit Committee. Collaborate with Legal and Risk teams on privacy requirements, AI/ML governance frameworks, and technological risk management. Serve as an executive security ambassador engaging with enterprise customers, prospects, and auditors on security architecture and compliance requirements. Architect and oversee enterprise Vendor Risk Management and software supply chain security programs. Provide leadership oversight for detection and response, identity and access governance, and cloud-native enterprise security posture. Report directly to the CISO within a fast-scaling organization building identity trust infrastructure for the digital economy.
Required Qualifications
- Certified Information Systems Security Professional (CISSP)
- Certified Information Privacy Technologist (CIPT)
- Factor Analysis of Information Risk (FAIR) Certification
- Certified in Risk and Information Systems Control (CRISC)
- Proven track record of presenting complex risk concepts, security strategies, and incident reports to Audit Committees and Board members
- Hands-on experience architecting, evaluating, or deploying AI security solutions and AI safety/governance frameworks
- Extensive experience managing enterprise vendor risk management, third-party compliance, and software supply chain risk
- High degree of comfort acting as a security representative in high-stakes enterprise customer meetings, sales cycles, and compliance audits
Desired Qualifications
- Experience overseeing detection and response operations in modern, cloud-native SaaS environments
- Deep experience with enterprise security platforms, specifically Okta (Identity & Access Management) and CrowdStrike (EDR/XDR)
- Background working in high-growth technology companies, AI/ML products, or B2B tech sectors
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.