Head of Information Security & IT

Chronograph

$215K — $250K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 7+ years of information security experience with hands-on technical expertise
  • Broad knowledge of cloud and application security, identity, vulnerability management, and detection and response
  • Experience leading information security programs and security assurance certifications like SOC 1, SOC 2, ISO 27001
  • Strong executive communication skills to convey technical risks to non-technical stakeholders
  • Curiosity about emerging threats, particularly in the AI landscape
  • Proficiency with risk management frameworks such as NIST or CIS

Responsibilities

  • Own the information security program, strategy, and architecture for Chronograph
  • Lead a small team of senior security professionals while mentoring and providing guidance
  • Communicate security risks and strategies clearly to executive leadership
  • Develop and implement security initiatives and controls directly
  • Oversee application security requirements and vulnerability management
  • Lead efforts on AI security strategy and address emerging threats
  • Manage corporate IT and ensure alignment with security protocols

Benefits

  • Equity participation
  • 401k plan
  • Unlimited and flexible vacation days
  • Generous health benefits
  • Fully-paid parental leave
  • Team events at HQ in Brooklyn, NY three times a year
Full Job Description
The Opportunity

Bring your expertise to a highly collaborative, creative, and innovative team with a market-leading technology product suite. We hire technologists with a broad set of technical skills who are eager to solve a wide range of challenges. The thread that unites us at Chronograph is a focus on delivering great, secure products that drive value for our clients.

We are looking for a Head of Information Security & IT to own Chronograph's security strategy, architecture, and execution as we continue to scale.

This is a hands-on leadership role spanning security strategy, governance, technical execution, and external assurance. We expect you to continuously strengthen our information security program and certifications while remaining technically close enough to investigate issues, prototype solutions, and implement controls where appropriate.

The security landscape is changing rapidly, particularly as AI expands both attacker capabilities and the attack surface of modern software. We want someone who follows emerging threats closely, continuously reassesses whether our security posture remains appropriate, and responds to credible new threats with urgency.

Our ideal candidate has a strong sense of ownership, excellent judgment, and a bias toward action. You are equally comfortable defining security strategy, representing it with sophisticated clients and external stakeholders, and getting technically involved when that is the best way to move an issue forward.

As Head of Information Security & IT at Chronograph, you will:

Leadership & Strategy
  • Own Chronograph's information security program, strategy, architecture, and roadmap
  • Serve as Chronograph's senior security leader in strategic client, partner, and external engagements
  • Lead and mentor a small team of senior security, compliance, and IT practitioners
  • Continuously assess our security posture and prioritize pragmatic, high-impact improvements
  • Communicate material security risks, priorities, and tradeoffs clearly to executive leadership
  • Develop a deep understanding of the business, product, and infrastructure to make sound security decisions

Technical Leadership
  • Develop technical approaches for security initiatives, validate assumptions, and build proofs of concept where useful
  • Implement security controls directly where appropriate, while partnering with engineering and infrastructure teams on more complex efforts
  • Maintain sufficient technical depth across cloud, application architecture, identity, logging, and security tooling to investigate issues and guide implementation
  • Evaluate and configure security tooling and automation

Application & Cloud Security
  • Own the security posture and requirements for our cloud and application environments, partnering with infrastructure and engineering teams on implementation
  • Lead vulnerability management and threat modeling programs, hands-on where needed
  • Partner with engineering on secure development practices and application security architecture
  • Own and improve application security tooling, including SAST, SCA, DAST, SOAR, secrets detection, and infrastructure-as-code scanning
  • Prioritize vulnerabilities based on exploitability and business risk

AI Security & Emerging Threats
  • Own security strategy for Chronograph's use of AI internally and within our products
  • Secure employee use of AI tools, agents, models, and integrations, including controls around sensitive data, third-party services, and agent permissions
  • Threat-model AI-enabled functionality, including prompt injection, data exfiltration, insecure tool use, excessive agency, and supply-chain risks
  • Track developments in offensive and defensive AI security and quickly assess their relevance to Chronograph
  • Evaluate AI-enabled security tooling and automation where it can improve our defensive capabilities

Corporate Security
  • Own our detection and response stack, including SIEM, EDR, WAF, and DLP, as well as the automation routing alerts between them
  • Lead threat detection and incident response strategy, including security partner relationships
  • Set direction for corporate IT, identity, endpoint management, and employee technology, with the IT team owning day-to-day operations

GRC & Compliance
  • Own Chronograph's SOC 1, SOC 2, ISO 27001, and broader security assurance strategy, with the GRC team managing day-to-day audit and evidence processes
  • Ensure our certifications, policies, risk management processes, and technical controls operate as a coherent information security program
  • Set direction for our annual risk assessment, risk register, policy lifecycle, and third-party risk program
  • Partner closely with compliance, sales, and customer teams on security due diligence, customer requirements, and strategic client engagements
  • Represent Chronograph's controls, certifications, and approach to risk with authority and credibility to customers, prospects, and auditors

You will be successful in this role if you have:
  • 7+ years of information security experience, including meaningful hands-on technical experience and increasing ownership of security programs
  • Strong technical judgment and the ability to investigate problems, develop solutions, build proofs of concept, and implement controls when appropriate
  • Broad experience across cloud and application security, identity, vulnerability management, and detection and response
  • Experience owning or materially leading an information security program, including risk management, policies, controls, and security roadmap, leveraging frameworks such as NIST, CIS, or GDPR.
  • Experience leading SOC1, SOC 2, ISO 27001, or comparable security assurance and certification programs
  • Experience representing an organization's security controls, certifications, and risk posture with sophisticated enterprise customers and auditors
  • Strong security instincts and curiosity about emerging threats, including the rapidly evolving implications of AI
  • Strong executive communication skills and the ability to translate technical controls, risks, and security strategy into clear business language

Even if you do not meet all criteria, we would still encourage you to apply or get in touch! Chronograph offers an entrepreneurial environment where you will be able to proactively identify opportunities to develop and strengthen our team.

We offer:
  • Competitive salary
  • Equity Participation
  • 401k
  • Unlimited and flexible vacation
  • Generous health benefits
  • Team week events in HQ (Brooklyn, NY) three times annually for all employees
  • Fully-paid parental leave
  • ...and more!

Salary Range (dependent on experience)

$215,000-$250,000 USD

Similar Jobs

More Jobs at Chronograph

More Information Technology Jobs

Find similar Head of Information Security & IT jobs: