أبلاي إيدج ابدأ البحث عن عمل

Chief Information Security Officer

Grayson Search Partners · Raleigh-Durham-Chapel Hill Area

قدّم وتابع مع أبلاي إيدج
Chief Information Security Officer Location: Raleigh-Durham, NC (Hybrid)About the OpportunityOur client is a rapidly growing, private equity-backed vertical SaaS company that provides mission-critical software solutions to a large and highly engaged user base across North America. The organization has experienced significant growth through both organic expansion and strategic acquisitions and is now consolidating multiple platforms into a modern cloud-native architecture.As the business continues to scale, leadership has made the strategic decision to hire its first dedicated Chief Information Security Officer (CISO). This executive will be responsible for establishing and leading a company-wide cybersecurity program that protects the business, enables innovation, strengthens customer trust, and supports future growth initiatives.This is a unique opportunity for a highly technical security leader who enjoys building rather than inheriting. The ideal candidate will bring deep experience from modern SaaS environments and possess a strong track record of scaling security capabilities in cloud-native organizations.Position SummaryThe Chief Information Security Officer will define and execute the company's cybersecurity strategy while partnering closely with Engineering, Product, Infrastructure, IT, Compliance, and Executive Leadership.This individual will serve as both a strategic advisor and hands-on leader, helping the organization mature its security capabilities without introducing unnecessary complexity or bureaucracy. The successful candidate will be a collaborative partner who views security as a business enabler rather than a control function.The environment is highly modern and cloud-native, leveraging Google Cloud Platform (GCP) as the primary infrastructure platform and operating within a fast-paced software development culture.Key ResponsibilitiesSecurity Leadership & StrategyDevelop and execute a comprehensive cybersecurity strategy aligned with business objectives.Establish security governance, risk management, and reporting frameworks for executive leadership and investors.Build a scalable security organization capable of supporting continued growth and future acquisitions.Serve as the primary executive responsible for cybersecurity strategy, risk management, and security operations.Cloud SecurityOwn the security architecture and security posture of a large-scale Google Cloud Platform (GCP) environment.Develop security standards and controls for cloud infrastructure, networking, identity management, and operational processes.Implement and mature cloud security monitoring, logging, detection, and response capabilities.Partner with Infrastructure and Platform Engineering teams to continuously improve security automation.Application Security & DevSecOpsBuild and mature an enterprise application security program.Establish secure software development practices across engineering teams.Implement security controls throughout the software development lifecycle.Drive initiatives related to secure coding practices, threat modeling, vulnerability management, penetration testing, security automation, CI/CD pipeline security, and developer security enablement.Governance, Risk & ComplianceLead compliance and risk management efforts across the organization.Maintain and enhance programs supporting, PCI-DSS, privacy, and customer trust requirements.Partner with Sales and Customer Success teams on security reviews, customer assessments, and RFP responses.Oversee third-party risk management and vendor security programs.Security Operations & Incident ResponseLead enterprise incident response planning and execution.Build processes to identify, prioritize, and remediate security risks.Establish security monitoring and threat detection capabilities.Develop business continuity and disaster recovery strategies.Coordinate security assessments, audits, and remediation efforts.Team DevelopmentEvaluate current security capabilities and identify organizational gaps.Build a high-performing security function over time through a combination of internal hires and strategic partners.Mentor technical teams and cultivate a strong security-first culture across the organization.Establish effective partnerships with leaders throughout the business.Ideal Candidate ProfileRequired Experience10+ years of progressive cybersecurity experience.Experience leading security programs within modern B2B SaaS organizations.Proven success building or significantly transforming security programs.Deep expertise securing cloud-native environments on Google Cloud Platform (GCP).Strong background in cloud security, application security, security architecture, DevSecOps, cyber risk management, security operations, and incident response.Experience communicating cybersecurity concepts to executive stakeholders, customers, and investors.Preferred ExperiencePrevious experience as a CISO, VP of Security, Head of Security, or equivalent executive leadership role.Background supporting private equity-backed or high-growth software businesses.Experience integrating security programs following acquisitions.Experience within multi-tenant SaaS environments.Familiarity with Google Workspace and cloud-first operating environments.Industry certifications such as CISSP, CCSP, CISM, GIAC, or similar credentials.Leadership CharacteristicsA builder who enjoys creating programs from the ground up.Highly technical and respected by engineering organizations.Pragmatic and business-oriented.Collaborative and low ego.Comfortable operating in fast-moving growth environments.An influential communicator who can align stakeholders around security priorities.Capable of balancing risk management with business velocity.A player-coach leader who remains engaged in technical discussions while operating at the executive level.First-Year PrioritiesEstablish a company-wide cybersecurity strategy and operating model.Create visibility into enterprise and product security risks.Mature cloud security capabilities within the GCP environment.Strengthen application security and DevSecOps practices.Enhance compliance, governance, and customer trust programs.Build scalable incident response and security operations processes.Develop a long-term roadmap for growing the security organization.