About the RoleSocure is seeking an experienced, executive-level Deputy Chief Information Security Officer (Deputy CISO) to report directly to the CISO. In this role, you will lead company-wide security, data governance, compliance, and risk programs across our fast-scaling organization.
You will play a critical strategic role driving AI and data security initiatives both internally across the company and externally as a core component of product development. You will regularly engage with executive leadership, the Board of Directors, enterprise customers, and legal teams on emerging AI risks and privacy frameworks.
Key Responsibilities- Company-Wide Security & Compliance Leadership: Drive, scale, and execute enterprise-wide information security, risk management, and compliance programs aligned with organizational goals and regulatory standards.
- AI & Data Security Strategy: Drive AI and data security initiatives across the company, embedding robust data protection, governance, and threat modeling directly into product development lifecycles.
- Executive & Board Governance: Prepare materials and present security posture, cyber risk metrics, and strategic roadmaps directly to executive staff, the Audit Committee, and the Board of Directors.
- Legal, Privacy & AI Partnership: Collaborate closely with Legal and Risk teams on privacy requirements, AI/ML governance frameworks, regulatory compliance, and technological risk management.
- Customer Assurance & External Audits: Serve as an executive security ambassador, engaging directly with enterprise customers, prospects, and auditors on security architecture, compliance requirements, and audit reviews.
- Vendor & Supply Chain Risk Management: Architect and oversee enterprise Vendor Risk Management (VRM) and software supply chain security programs.
- Enterprise Security Operations: Provide leadership oversight for detection and response, identity and access governance, and cloud-native enterprise security posture.
Minimum Qualifications- Required Certifications:
- Certified Information Systems Security Professional (CISSP)
- Certified Information Privacy Technologist (CIPT)
- Factor Analysis of Information Risk (FAIR) Certification
- Certified in Risk and Information Systems Control (CRISC)
- Executive Presentation Experience: Proven track record of presenting complex risk concepts, security strategies, and incident reports to Audit Committees and Board members.
- AI & Security Deployment Track Record: Hands-on experience architecting, evaluating, or deploying AI security solutions and AI safety/governance frameworks.
- Vendor & Supply Chain Security: Extensive experience managing enterprise vendor risk management, third-party compliance, and software supply chain risk.
- Customer-Facing Engagement: High degree of comfort acting as a security representative in high-stakes enterprise customer meetings, sales cycles, and compliance audits.
Preferred Qualifications- Experience overseeing detection and response operations in modern, cloud-native SaaS environments.
- Deep experience with enterprise security platforms, specifically Okta (Identity & Access Management) and CrowdStrike (EDR/XDR).
- Background working in high-growth technology companies, AI/ML products, or B2B tech sectors.