Drata logo
DrataPosted 1 month ago

Field CISO

$210,000–$350,000 year

RemoteUnited States

Full TimeMedium

Job Summary

Partner with Sales, Customer Success, and Marketing teams on strategic enterprise and F500/G2000 opportunities, leading executive briefings and CISO-to-CISO conversations to build trust. Represent Drata at industry conferences, CISO dinners, and regional roundtables across the Americas, EMEA, and APAC, while sharing field insights through webinars, panels, and press. Advise executive leadership on emerging regulatory shifts and systemic industry risks, providing strategy for company-wide responses to major regulatory regimes and certification changes. Equip sales teams with security and GRC context to navigate technical conversations and shape product roadmap decisions based on hands-on customer feedback. Work alongside internal security and GRC teams to support critical initiatives, drawing on a network of 15+ years in the field to open doors and raise the security bar. This senior individual contributor role involves 50-75% travel and reporting directly to the SVP, Security & CISO.

Required Qualifications

  • 15+ years of progressive experience in security and GRC
  • 10+ years leading and managing teams
  • 5+ years in the CISO seat (as a CISO, Deputy CISO, or equivalent senior security and GRC leader)
  • Strong grasp of the compliance frameworks our customers care about — including ISO 27001, SOC 2, HIPAA, FedRAMP, GDPR, NIST CSF, PCI DSS, and CCPA
  • Excellent communication skills, with the ability to move comfortably between boardroom conversations and technical deep-dives
  • Genuine reputation and network within the security and GRC community
  • Track record of operating at the most senior individual contributor level of a security or GRC organization
  • Comfort working with ambiguity — turning undefined, fast-moving problems like regulatory direction, market shifts, or systemic risk into clear strategy
  • Experience partnering with go-to-market teams in customer-facing conversations
  • Track record of thought leadership—speaking, writing, or other public and social engagement
  • Familiarity with SaaS and cloud-native environments
  • Thoughtful perspective on how AI is shaping both security and GRC risk and practice
  • Openness to travel regularly and represent Drata's security and GRC program in a public-facing capacity
  • Ideally either based on the East Coast of the U.S. or willing to work EST hours to support coverage across the Americas and EMEA time zones
  • Willingness to travel regularly - 50-75% (including international travel) for customer meetings, conferences, and field events

Desired Qualifications

  • Professional certifications such as CISSP, CISM, CRISC, or CCSP

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce