SVP, Chief Information Security Officer
$250,000–$325,000 year
RemoteUnited States
Job Summary
Optimize the enterprise-wide information security strategy and roadmap aligned with business objectives and risk appetite. Partner with the CTO to integrate security into technology architecture, infrastructure decisions, software development practices, and vendor selection. Lead and develop a high-performing security team spanning security operations, vulnerability management, identity and access management, and data protection. Own the security risk management program, including assessments, gap analysis, and remediation planning across all business lines. Improve incident response capability and ensure compliance with regulatory requirements such as the FTC Safeguards Rule. Serve as the security liaison to the Board, executive leadership, investors, and external auditors. Manage third-party and vendor risk, embed security requirements in procurement and contracting, and champion a firm-wide security awareness program. Establish an internal offensive security function including ethical hacking and adversary emulation to proactively probe systems. Report to the Chief Legal and Administrative Officer while partnering closely with the CTO.
Required Qualifications
- 15+ years of progressive experience in information security
- at least 5 years in a senior leadership role
- Deep knowledge of cybersecurity frameworks and standards, including NIST CSF, ISO 27001, SOC 2, and CIS Controls
- Demonstrated experience managing security in cloud-native or hybrid environments
- familiarity with AWS, Azure, or GCP security architectures
- Strong understanding of the regulatory landscape relevant to financial services, private credit and/or investment management
- including SEC, FINRA, and applicable data privacy laws
- Proven ability to communicate complex security risks to non-technical stakeholders, including boards and investors
- Bachelor's degree in Computer Science, Information Security, or a related field
Desired Qualifications
- ideally within financial services, asset management, or private credit
- Experience building and scaling security programs in growth-stage or mid-market financial firms
- Relevant certifications such as CISSP, CISM, or CRISC
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.