Chief Security Officer Jobs

12 open positions found · Salary range: $201 - $228,000

View Chief Information Security Officer
B

Chief Information Security Officer

From $201/yr

Powering the next generation of global finance About Us Founded in 2018, Bakkt, Inc. is a regulated financial technology company building infrastructure for the future of finance. Bakkt's platform serves financial institutions, fintechs, and consumer finance products — providing the compliance, security, and scale required to deliver trusted financial services at a global level. Through its core business pillars, Bakkt powers institutional-grade trading capabilities, AI-enabled programmable finance, and cross-border payment infrastructure. Role Summary Bakkt is seeking a strategic, Chief Information Security Officer (CISO) to lead our global information security posture and serve as our designated officer for regulatory cybersecurity compliance. This role is designed for an innovative leader who thrives at the intersection of modern engineering velocity and institutional-grade risk management. As we scale our Agentic AI and Stablecoin settlement infrastructure, you will lead a progressive security function that moves far beyond "check-the-box" compliance. Reporting directly to executive leadership with a dotted line to the Board of Directors, you will have the authority to build a defensible, automated security program that serves as a core enabler for our business growth. Key Responsibilities Regulatory Ownership \& Executive Governance * Designated Regulatory Authority: Serve as the designated CISO responsible for Bakkt's cybersecurity program in accordance with NYDFS Part 500 requirements. Oversee comprehensive annual risk assessments and manage our annual certification of compliance process. * SEC \& Public Market Readiness: Lead our organizational process for determining the materiality of cybersecurity incidents. Oversee the timely preparation of all required disclosures and filings in accordance with public market regulations and governance standards. * Board Stewardship: Provide quarterly Material Security Risk briefings to the Audit Committee of the Board, translating complex infrastructure threats into actionable business risk metrics. * Global Expansion Support: Maintain and evolve our security controls to support international settlement expansion, aligning with global mandates as required (e.g., EU DORA, UK FCA, GDPR). * AI Governance \& Stablecoin Infrastructure * Agentic AI Security: Establish the governance and security framework for autonomous AI agents, ensuring programmable money movement is resilient against prompt injection, model poisoning, and unauthorized agentic transactions. * Stablecoin Settlement Defense: Oversee the security of our end-to-end stablecoin lifecycle, ensuring the cryptographic integrity of minting/burning protocols and the security of reserve management interfaces. * Identity-First (Zero Trust) Architecture: Architect a comprehensive security model that applies consistent rigor to both human and non-human identities, implementing modern phishing-resistant authentication and zero-trust principles across the enterprise. * Continuous Compliance: Transition our operations from manual GRC to Continuous Controls Monitoring (CCM), ensuring audit evidence is generated in real-time through Policy-as-Code. * Security Engineering \& DevSecOps * Seamless Security (Shift Left): Foster an internal culture where security is built-in from the start. Replace manual gatekeeping with automated guardrails integrated into our development pipeline, allowing engineers to ship securely without losing speed. * Smart Risk Management: Move beyond unprioritized vulnerability lists. Implement a threat-modeling process that prioritizes fixes based on real-world business impact, ensuring engineering teams focus on the risks that actually threaten our environment. Operational Leadership \& Resilience * Incident Response \& Tabletops: Own the global Incident Response and Business Continuity plans. Lead high-stakes tabletop exercises simulating systemic financial failures and AI-driven fraud. * Third-Party Risk Management (TPRM): Manage the security lifecycle of critical banking and ICT partners, moving beyond point-in-time assessments to continuous, data-driven vendor monitoring. * Talent Development: Lead, develop, and motivate a high-performing team of security subject matter experts in our distributed, remote-first environment.Ideal Candidate Profile Qualifications and Skills * The Standard: CISSP required, or a demonstrably equivalent executive credential (CISM, CCISO, or CISA). * Financial \& Public Co. Pedigree: 12+ years in Information Security, with significant experience operating within a NYDFS-regulated or SEC-reporting public company environment. * Infrastructure Depth: Proven success leading security in distributed, cloud-driven (AWS/GCP) environments. Direct experience with stablecoin protocols or AI-driven financial tools is a strong advantage. * Preferred Education: Master’s degree (Cybersecurity, MIS, or MBA) and/or senior-level professional designations like GSLC or equivalent executive cybersecurity leadership training. * Leadership \& Soft Skills * Strategic \& Lateral Thinker: Ability to look at complex regulatory frameworks not as obstacles, but as tools for building robust, continuous process improvement. * Operational Resolve: Capable of leading difficult, high-stakes conversations where business velocity and regulatory safety intersect. * Agile Leadership: Proven ability to lead through ambiguity and rapid change. You are a decisive leader who can pivot strategies in real-time based on shifting market conditions while maintaining team focus on high-priority outcomes. * Collaborative Culture Builder: A sophisticated, modern approach to managing and motivating technical subject matter experts in a remote-first, high-growth environment. Bakkt is devoted to having diversity in its workforce and is proud to be an equal opportunity employer. Bakkt does not make any employment decisions based on race, color, religion, sex, national origin, veteran status, disability, age, sexual orientation, gender identity or any other characteristic protected by law. Must successfully pass a post-offer background check and drug screen. California Candidate Privacy Notice Before submitting your application, please review Bakkt's California Candidate Privacy Notice and Notice at Collection, which explains how Bakkt collects, uses, retains, and discloses applicant and candidate personal information during the recruiting process. The notice is available here: https://bakkt.com/candidate-privacy/

3 months agovia universal intelligenceApply ›
View Deputy Chief Information Officer for Cybersecurity and Chief Information Security Officer (CISO)
U

Deputy Chief Information Officer for Cybersecurity and Chief Information Security Officer (CISO)

$199,172 - $228,000/yr

Summary The Department of Energy's (DOE) Office of the Chief Information Officer is looking for a dynamic, innovative, seasoned executive to serve as the Deputy Chief Information Officer for Cybersecurity and CISO within the Office of the Chief Information Officer (OCIO). This job is open to The public U.S. Citizens, Nationals or those who owe allegiance to the U.S. Federal employees - Competitive service Current federal employees whose agencies follow the U.S. Office of Personnel Management's hiring rules and pay scales. Federal employees - Excepted service Current federal employees whose agencies have their own hiring rules, pay scales and evaluation criteria. Senior executives Individuals looking for an executive-level job and who meet the five Executive Core Qualifications (ECQs). Clarification from the agency Open to All U.S. Citizens Duties The Department of Energy's (DOE) Office of the Chief Information Officer is looking for a dynamic, innovative, seasoned executive to lead the Office Deputy Chief Information Officer for Cybersecurity and Chief Information Security Officer (CISO). The Deputy Chief Information Officer for Cybersecurity \& CISO provides leadership for the strategic direction and management of Department-wide enterprise cybersecurity threat and vulnerability information to enable the agency to identify, protect, detect, respond and recover from cyber-attacks. As the Deputy Chief Information Officer for Cybersecurity and CISO you will: * Provide leadership for the strategic direction and management of Department-wide enterprise cybersecurity threat and vulnerability information to enable the agency to identify, protect, detect, respond, and recover from cyber-attacks. * Provide guidance and expert advice in developing, promoting, and maintaining cybersecurity controls and performance measures to adequately and cost effectively protect all cyber critical infrastructure, including classified and unclassified information systems and national security systems. * Provide leadership, maintain governance and operational oversight of the DOE Joint Cybersecurity Coordination Center, central point for the collection, analysis, handling, and sharing of enterprise cybersecurity information and serve as the Department's incident response coordination and reporting element. * Provide Department-wide leadership in information security policy and guidance to promote efficient, effective cyber, telecommunications, and information security practices while assuring consistency with national policy. * Provide expert advice, recommendations, and representation in areas of Departmental cybersecurity policies, guidelines, and implementation of enhanced Departmental information security practices. * Serve as a representative to appropriate Federal cyber security committees and forums, including the Federal Computer Security Program Manager's Forum and the Committee for National Security Systems Security Committee. * Develop and mentor staff through on-boarding, open communication, training and development opportunities and performance management processes. This is a dual-hatted position that includes serving as the "Chief Information Security Officer" (CISO), duties include: * Develop and maintain the Department's cybersecurity architecture to ensure Departmental information and information systems are protected in accordance with the risk and magnitude of harm that would occur from the loss or compromise of the Department's information assets. * On behalf of the CIO, prepare DOE's annual agency report on the effectiveness of DOE's Cybersecurity Management Program, including progress of remedial actions. * Serve as the senior advisor to departmental officials to ensure that DOE's program office compliance with the Cybersecurity Management Program. * Establish Departmental cybersecurity policy, standards, and guidelines in accordance with federal law and regulations, Presidential directives, the national standards and industry best practices. Develop and coordinate Departmental policy for communications security, emissions security, secure voice, and cybersecurity. * Responsible for the Enterprise Risk Management-Cybersecurity (ERM-CS) strategy plan, and management. * Serve as the agency's cybersecurity liaison to the private sector and federal community including the Executive Office of Management and Budget (OMB), the Committee on National Security Systems, and the National Institute for Standards and Technology. * Serve as the DOE's senior Authorizing Official (AO) and provide training, guidance, and coordination with other agency AOs. Requirements Conditions of employment * Complete a Declaration for Federal Employment to determine your suitability for Federal employment, at the time requested by the agency * If you are a male applicant born after December 31, 1959, certify that you have registered with the Selective Service System or are exempt from having to do so. * May be subject to pre-employment and random drug tests * File a Confidential Financial Disclosure Report OGE-278e within 30 days of appointment and annually from then on. * You will be required to obtain and maintain an interim and/or final security clearance prior to entrance on duty. Failure to obtain and maintain the required level of clearance may result in the withdrawal of a job offer or removal. There are three key documents that contain important information about your rights and obligations. Please read and retain these documents: * Noncriminal Justice Applicant's Privacy Rights, for those who undergo an FBI fingerprint-based criminal history record check for personnel vetting, which includes Rap Back, * FD-258 Privacy Act Statement - FBI (this is the same statement used when your fingerprints are submitted as part of your background investigation), and * SEAD-3-Reporting-U.pdf (dni.gov), (applicable to those who hold a sensitive position or have eligibility for access to classified information)" Qualifications Candidates should be committed to improving the efficiency of the Federal government, passionate about the ideals of our American republic, and committed to upholding the rule of law and the United States Constitution. Candidates will not be hired based on their race, sex, color, religion, or national origin. To meet the minimum qualification requirements for this position, you must show that you possess the Executive Core Qualifications (ECQ) and Technical Qualifications (TQ) related to this position within your resume - NOT TO EXCEED 2 PAGES. Resumes over the 2-page limit, will not be reviewed beyond page 2 or may be disqualified. Your resume should include examples of experience, education, and accomplishments applicable to the qualification(s). If your resume does not reflect demonstrated evidence of these qualifications, you may not receive consideration for the position. TECHNICAL QUALIFICATIONS (TQs): Your resume should demonstrate accomplishments that would satisfy the technical qualifications. TQ 1: Demonstrated comprehensive executive leadership in establishing and directing advanced cybersecurity programs that underpin digital transformation initiatives. TQ 2: Exhibited exceptional leadership in managing complex cybersecurity operations, including, but not limited to, incident response and recovery, at an enterprise level. EXECUTIVE CORE QUALIFICATIONS (ECQs): In addition to the Technical Qualification Requirements listed above, all new entrants into the Senior Executive Service (SES) under a career appointment will be assessed for executive competency against the following five mandatory ECQs. If your 2-page resume does not reflect demonstrated evidence of the ECQs and TQs, you may not receive further consideration for the position. There are five ECQs: * ECQ 1: Commitment to the Rule of Law and the Principles of the American Founding - This core qualification requires a demonstrated knowledge of the American system of government, commitment to uphold the Constitution and the rule of law, and commitment to serve the American people. * ECQ 2: Driving Efficiency - This core qualification involves the demonstrated ability to strategically and efficiently manage resources, budget effectively, cut wasteful spending, and pursue efficiency through process and technological upgrades. * ECQ 3: Merit and Competence - This core qualification involves the demonstrated knowledge, ability and technical competence to effectively and reliably produce work that is of exceptional quality. * ECQ 4: Leading People - This core qualification involves the demonstrated ability to lead and inspire a group toward meeting the organization's vision, mission, and goals, and to drive a high-performance, high-accountability culture. This includes, when necessary, the ability to lead people through change and to hold individuals accountable. * ECQ 5: Achieving Results - This core qualification involves the demonstrated ability to achieve both individual and organizational results, and to align results to stated goals from superiors. Note: If you are a member of the SES or have been certified through successful participation in an OPM approved SES Candidate Development Program (SESCDP), or have SES reinstatement eligibility, you do not need to respond to the ECQs. Instead, you should attach proof (e.g., SF-50, Certification by OPM's SES Qualifications Review Board (QRB)) of your eligibility for noncompetitive appointment to the SES. Education No education requirements for this position. Additional information Veterans Preference: Veterans' preference is not applicable to the SES. Mobility: Organizational and geographical mobility is essential in developing and managing SES leaders. Individuals selected for SES positions members may be subject to reassignment across geographical, organizational, and functional lines, and may be required to sign a Reassignment Rights and Obligation Agreement. Equal Employment Opportunity (EEO) Policy Statement: http://www.eeoc.gov/federal/index.cfm Employment Information Resources - Resource Center: https://help.usajobs.gov/how-to Males born after 12-31-1959 must be registered or exempt from Selective Service (see https://www.sss.gov/RegVer/wfRegistration.aspx) Hiring incentives may be authorized in accordance with agency policy and if funding is available. This is a non-bargaining unit position. Candidates should be committed to improving the efficiency of the Federal government, passionate about the ideals of our American republic, and committed to upholding the rule of law and the United States Constitution. Benefits ======== A career with the U.S. government provides employees with a comprehensive benefits package. As a federal employee, you and your family will have access to a range of benefits that are designed to make your federal career very rewarding. Opens in a new windowLearn more about federal benefits. Eligibility for benefits depends on the type of position you hold and whether your position is full-time, part-time or intermittent. Contact the hiring agency for more information on the specific benefits offered. How you will be evaluated You will be evaluated for this job based on how well you meet the qualifications above. Once the application process is complete, a review of your resume and supporting documentation will be conducted. If you meet minimum qualifications, your Application Package will be further reviewed to determine if you possess the Executive Core Qualifications (ECQ) and Technical Qualifications (TQ) listed above. ECQs and TQs must be thoroughly addressed within your two (2) page resume. Separate narratives will not be accepted or reviewed. Highly Qualified applicants may undergo one or more interviews and may be referred to the selecting official for further consideration. Upon selection, if not already a member of the SES serving under a career appointment, the individual selected must have his/her executive qualifications certified by the U.S. Office of Personnel Management's SES Qualifications Review Board (QRB) before appointment to this position. The selected individual's application will be forwarded to the OPM for review and certification by the QRB, unless the selectee provides evidence of their noncompetitive status (i.e., a current SES, OPM QRB certified SESCDP graduate, or SES reinstatement eligible). Upon QRB certification, the selected individual will be required to serve a one-year probationary period. For more information regarding the SES, go to https://www.opm.gov/policy-data-oversight/senior-executive-service/. Required Documents A complete application includes items described below. Please note that if you do not provide all required information, as specified in this announcement, you may not be considered for this position (or may not receive the special consideration for which you may be eligible). Please carefully review the following list to determine what documentation you need to submit. Some documents may not apply to all applicants. 1. RESUME: All applicants are required to submit a resume limited to two (2) pages (i.e., 1 page that is double-sided or 2 pages that are one-sided each) showing all relevant experience. A minimum of 10-point font is required. Applicants seeking initial career appointment to the Senior Executive Service (SES) must include evidence of the ECQs and TQs. PLEASE DO NOT USE USAJOBS RESUME BUILDER. 2. VACANCY QUESTION/ASSESSMENT QUESTIONNAIRE RESPONSES: Responses are automatically submitted through USA Jobs when you apply to this vacancy. 3. ADDITIONAL REQUIRED DOCUMENTS: Applicants are required to submit the following supporting documentation if applicable: * CURRENT OR FORMER SES MEMBERS: Must provide your SES appointment SF-50 (Notification of Personnel Action), and an SF-50 showing current career SES status or career SES reinstatement eligibility. * SES CANDIDATE DEVELOPMENT PROGRAM (SESCDP) GRADUATES: Verification of successful completion of an OPM-approved SESCDP and OPM SES QRB certification. * CURRENT OR FORMER FEDERAL CIVIL SERVICE EMPLOYEE: Must provide a copy of your Notification of Personnel Action, Standard Form 50 (SF-50) or equivalent personnel action form reflecting you are a current Federal Civil Service employee. STRONGLY RECOMMENDED: Most recent performance evaluation If you are relying on your education to meet qualification requirements: Education must be accredited by an accrediting institution recognized by the U.S. Department of Education in order for it to be credited towards qualifications. Therefore, provide only the attendance and/or degrees from schools accredited by accrediting institutions recognized by the U.S. Department of Education. Failure to provide all of the required information as stated in this vacancy announcement may result in an ineligible rating or may affect the overall rating. How to Apply To apply for this position, you must complete this application and submit any required documents specified in the Required Documents section and submit by 11:59 PM (EST) on the closing date of the announcement to receive consideration. To begin, click Apply to access the online application. You will need to be logged into your USAJOBS account to apply. If you do not have a USAJOBS account, you will need to create one before beginning the application. Follow the prompts to select and upload your résumé and/or other required documents to be included with your application package. You will have the opportunity to upload additional documents to include in your application before it is submitted. Your uploaded documents may take several hours to clear the virus scan process. After acknowledging you have reviewed your application package, complete the "Include Personal Information" section as you deem appropriate and click to continue with the application process. You will be taken to the online application which you must complete in order to apply for the position. Complete the online application, verify the required documentation is included with your application package, and submit the application.It is applicant's responsibility to verify that information entered and uploaded, (i.e., resume and other required documents) is complete, accurate, and submitted by the closing date. Human Resources will not modify or change any part of your application. Application packages will NOT be accepted via mail. Due to security processes, mail delivery takes approximately 2-3 weeks to process at which time the vacancy announcement will be closed, and no further consideration will be given to additional application packages. Agency contact information Rashida Smith Email rashida.smith@hq.doe.gov Address Office of the Chief Information Officer Department of Energy Human Capital Shared Service Center 1000 Independence Ave, SW Washington, DC 20585 US### Next steps To verify the status of your application, sign in to your USAJOBS account (https://www.usajobs.gov/), all of your applications will appear on the Welcome screen. The Application Status will appear along with the date your application was last updated. For information on what each Application Status means, visit: https://help.usajobs.gov/how-to. Once your online application is submitted you will receive a confirmation notification by email. Your application will be evaluated by the Human Resources Office to determine your eligibility for the position. After the evaluation is complete, you will receive another notification regarding the status of your application. Overview Accepting applications Open \& closing dates 02/06/2026 to 02/19/2026 Salary $199,172 to - $228,000 per year Pay scale \& grade ES 00 Location 1 vacancy in the following location: Washington, DC Remote job No Telework eligible Yes—as determined by the agency policy. Travel Required Occasional travel - You may be expected to travel for this position. Relocation expenses reimbursed No Appointment type Permanent Work schedule Full-time Service Senior Executive Promotion potential None Job family (Series) * 2210 Information Technology Management Supervisory status Yes Security clearance Sensitive Compartmented Information Drug test Yes Position sensitivity and risk Critical-Sensitive (CS)/High Risk Trust determination process * National security Financial disclosure Yes Bargaining unit status No Announcement number 26-IM-00167-12878795-ES Control number 856782800

7 months agovia universal intelligenceApply ›
View CHIEF SAFETY & SECURITY OFFICER (PLANNER VIII) (SR-30) [1 vacancy]
C

CHIEF SAFETY & SECURITY OFFICER (PLANNER VIII) (SR-30) [1 vacancy]

City and County of HonoluluHonolulu, HI, USonsite

JOB Current Vacancy Information: There is one (1) vacancy with the Department of Transportation Services, Administration Division. The Chief Safety \& Security Officer position plans, organizes, directs and oversees safety, emergency, and security design criteria, policies, plans, procedures, work instructions, practices, for the department and activities for multimodal transportation. The position has overall responsibility for the department including the Safety and Security Office including health, safety, environmental, quality, system safety and compliance, emergency, cyber security, and security functions.Examples of duties of a Chief Safety \& Security Officer, includes but are not limited to the following: Serves as the safety, emergency, and security subject matter expert;The primary liaison with the State Safety Oversight Agency and is responsible for safety and security certifications;Manages and directs the complex development, implementation, monitoring, evaluation, and enhancement of safety, emergency, and security programs for the department and multimodal transportation; Responsible for the reduction and mitigation of hazards, injuries, accidents, as well as threats; Communicates with line staff, supervisors, managers, senior leadership, the Director and may represent the department at public meetings with regard to safety, emergency, and security information;Implements and updates compliance manuals, Job Hazard Analysis, Position Physical Effort Analysis and Health \& Safety Plans, which is part of a a comprehensive program that establishes systems, responsibilities, and processes for contract management and compliance obligations;Responsible for the ongoing review, inspection, and acceptance of contractor submittals such as invoices, performance reports, change requests, plans, procedures, work instructions and training materials to include competency tracking and assurance;Engages in surveillance, inspection, investigation, audit, and reporting activities to ensure programs satisfy the requirements of any relevant contracts, plans, procedures, and work instructions as well as any applicable federal, state, and local laws and regulations;Establishes and maintains a strong relationship within the Department, with HART and Lead Operations and Maintenance Contractors, and other City departments in order to fulfill requests, support special projects, and resolve issues;Demonstrates a commitment to safety that guides all aspects of work through consistent and professional behaviors in performance of the essential duties. Special Work Requirements: Must be able to handle highly confidential information. Incumbent of this position is designated as a Disaster Response Worker whose responsibilities may require night and weekend work during natural disasters, and other emergencies (e.g., when 24-hour staffing of the City's Emergency Operating Center is activated). Regular office hour and work schedule changes and may include weekdays, weekends, and hours outside of 7:45 a.m. to 4:30 p.m.If you qualify for the position, your name will be placed on an eligible list for further consideration. This list may be used to fill current and future vacancies in this department. EXAMPLE OF DUTIES Applications must be submitted online at https://www.governmentjobs.com/careers/honolulu to be accepted.\\Actual salary will be commensurate with applicable experience, pending approval.\\ Some notifications will be sent via e-mail. You are responsible for monitoring instructions and correspondence from this office by checking your email account in a timely manner. To ensure proper delivery, please make sure you: - are subscribed to email notices; - use a valid e-mail account; - verify your e-mail address is entered correctly on your GovernmentJobs account; - check your spam folders; and - add infoneogov@honolulu.gov and info@governmentjobs.com to your contact list.Notifications may also be sent via text message if opted into the service. Data and text messaging fees apply. SUPPLEMENTAL INFORMATION EDUCATION AND EXPERIENCE EVALUATION: In addition to meeting the above minimum qualifications, your application will be further evaluated. Your score will be based on the quality and quantity of your education, experience and/or other related job requirements and competencies applicable to the position. Failure to provide sufficient information may result in your application being rejected or your receiving a lower score.EXAMINATION WEIGHT: Education and Experience Evaluation . . . . . . . . . . . . . . . . 100%

Apr 12, 2024via universal intelligenceApply ›
View Chief Information Security Officer
B

Chief Information Security Officer

ButterflyMXNew York remote

Our Mission:ButterflyMX is on a mission to empower people to open and manage doors & gates from a smartphone. Our products are installed in more than 20,000+ multifamily, commercial, gated communities, and student-housing properties worldwide, including properties developed, owned, and managed by the most trusted names in real estate. Our features are designed for developers, owners, property managers, and tenants and our products lower operating costs and improve tenant satisfaction.Our Solution:Developers and owners no longer need to run building wiring or install in-unit hardware. Property managers can grant building access, revoke permissions, and review entry logs from an online dashboard. Residents can open doors from their smartphones, issue visitor access, and see who is trying to enter the building.Our Culture & Values:Fantastic people are the key to our success. As a distributed, primarily remote workforce, we’re looking for more intelligent, passionate, collaborative, ai-forward, and down-to-earth individuals to join our growing team. We’re driven by a shared commitment to excellence and innovation, grounded in our core values: We delight our customers, We take ownership, We are a community of collaborators, We speak up, We think big and do small, and We are tenacious. Role Overview: As our CISO, you’ll lead and scale a small, talented security team into a world-class organization that protects our customers, employees, and partners across cloud, IoT, and enterprise systems. You’ll be responsible for shaping our security strategy, implementing practical controls that balance risk and innovation, and ensuring that security enables our growth without slowing us down.You’ll partner closely with Engineering, Product, and Infrastructure leaders to ensure our platforms and connected devices are secure by design. You’ll partner closely with our People team to ensure that our business systems and processes are meeting high security standards. You’ll partner closely with Sales and Support leaders to build confidence in our security posture with our customers. You’ll report to the CTO and engage regularly with the executive team to ensure our strategy aligns with the company’s goals, risk appetite, and compliance obligations.This is both a strategic and hands-on role. You’ll set direction, manage budgets, lead audits and certifications, but also dive into architecture reviews, incident response, and vendor risk assessments when needed. We’re looking for someone who can move fluidly between the boardroom and the command line. Most importantly, to be successful in this role you’ll need to be passionate about building strong, productive relationships across the organization, and about helping people to understand the real world impact of security-related work: the ‘why’ behind the ‘what’.About YouYou’re a security leader who’s earned your credibility through both technical depth and sound judgment. You thrive in an environment where security must scale without slowing innovation, and you know how to rally people around doing the right thing for the business.ResponsibilitiesOwn and evolve the company’s security and privacy strategyScale and mentor the Security team, developing great security team members as the company grows.Build and mature the company’s security framework, balancing pragmatism and rigor across system security, application security, infrastructure security, and device security.Lead security operations and incident response, ensuring the company can rapidly detect, respond to, and recover from threats.Oversee compliance programs (e.g., SOC 2, GDPR, CPRA) and maintain a continuous improvement mindset beyond checkbox compliance.Partner with Engineering and Product to embed security into the SDLC, CI/CD pipelines, and IoT device lifecycle.Establish and maintain relationships with key stakeholders, such as executive leadership, providing actionable metrics and insights into security posture, risk trends, and emerging threats.Oversee vendor risk management and ensure robust controls across third-party services and integrations.Conduct regular security awareness training and education programs for employees.Evaluate and select security technologies and tools to enhance the organization's security posture.Build a strong security culture, from awareness and education to clear policies and positive engagement across all teams.Optimize the security budget and make pragmatic tradeoffs that balance protection, velocity, and business impact.Requirements10+ years of progressive experience in information security, including 3+ in a leadership role at a SaaS or technology company.Experience securing cloud-native systems (AWS/GCP) and managing organizational security at a remote-first company.Deep understanding of security frameworks and standards (e.g., NIST CSF, CIS, ISO 27001, SOC 2, OWASP).Strong background in incident response, threat modeling, and risk management.Proven ability to partner with product and engineering teams to design secure, scalable architectures.Experience building and mentoring high-performing security teams.Excellent communication skills enabling you to distill complex security topics for executives, engineers, and customers alike.A balanced, business-first mindset: you make practical, risk-informed decisions rather than striving for theoretical perfection.Certifications such as CISSP, CISM, or CRISC (preferred but not required).BenefitsComprehensive Medical (ButterflyMX covers 90% of the cost), Dental, and Vision plans (ButterflyMX covers 100% of the cost) starting day 1401(k) plan with a match13 paid holidays and 25 days PTOPaid Family LeaveEmployee Assistance ProgramQuarterly self-care stipendsHealthAdvocacy ProgramAccess to optional benefits including pre-tax flexible healthcare spending accounts (FSA and HSA), Dependent Care FSA, and Commuter Benefits, as well as optional Supplemental Life, AD&D, Hospital Indemnity, Disability, Legal, Accident, Critical Illness, Pet, and Personal Liability InsuranceCollaborative, dynamic work environment filled with kind, smart people, who are working hard on an industry-defining productButterflyMX is an equal opportunity employer and we value diversity at our company. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status. You must have the authorization to work in the US to become an employee. We strive to create an accessible and inclusive experience for all candidates and employees. If you need reasonable accommodations during the application or the recruiting process, please let our recruiting team know.Please mention the word FAITHFUL and tag RMTg1LjIwMy4xMjIuMjIy when applying to show you read the job post completely (#RMTg1LjIwMy4xMjIuMjIy). This is a beta feature to avoid spam applicants. Companies can search these words to find applicants that read this and see they're human.

securitydesignsaassystemtraining+16 more
7 months agovia remoteokApply ›

Companies hiring for Chief Security Officer

Track these jobs with Jobfu

Get AI-powered resume tailoring, application tracking, and job alerts for Chief Security Officer roles. Sign up free.

Sign up free