OverviewThe SVP, Chief Information Security Officer (CISO)will serve as Attain Finance's senior-most authority on information security, owning the strategy, execution, and governance of allsecurity functions across the organization. Partnering closely with the Chief Technology Officerand reporting to the Chief Legal and Administrative Officer, the SVP, CISO will align security capabilities with the firm's growth objectiveswhile managing risk in a highly regulated financial services environment.
Responsibilities
- Optimize, implement, and continuously mature an enterprise-wide informationsecurity strategy, framework, and roadmap aligned with Attain Finance's businessobjectivesand risk appetite
- Partner with the CTO to integrate security into technology architecture, infrastructure decisions, software development practices, and vendor selection
- Lead and develop a high-performingsecurity teamspanning domains such as security operations, vulnerability management, identity and access management, and data protection
- Own the firm'ssecurity risk management program, including risk assessments, control gap analysis, and remediation planning across all business lines and technology environments
- Improveandmaintaina robustincident responsecapability, including detection, containment, recovery, and post-incident review processes
- Partner with the Chief Compliance Officer toensure compliancewith applicable regulatory requirements and industry frameworks, including the FTC Safeguards Rule
- Serve as thesecurity liaisonto the Board of Directors, executive leadership, investors, and external auditors, providing clear and actionable reporting on the firm's security posture
- Manage third-party and vendor risk, ensuring that security requirements are embedded in procurement, contracting, and ongoing oversight processes
- Champion afirm-wide security awarenessand training program that builds a proactive security culture across all employees and business functions
- Evaluate and manage the security technology stack, ensuring investments are effective, scalable, and aligned with the threat landscape
- Stand up and lead a proactive threat hunting programuild the team, tooling, and playbooks to actively search for threats across our environment rather than waiting onalerts, andmature it from ad-hoc hunts to a repeatable, intel-driven capability. Build outan internal offensive security (red team) functionstablishin-house ethical hacking, penetration testing, and adversary emulation to continuously probe our own systems, applications, and controls for weaknesses before attackers do.
Base Salary: $250,000 - $325,000 USD
The base salary range represents the low and high end of the anticipated salary range for this position based on the U.S. average. The actual base salary offered for this full-time position will be determined by various factors, including but not limited to, location, skills, knowledge, competencies, and experience.All full-time salaried employees are eligible for the following benefits, starting on day one: Flexible Paid Time Off Program, Medical, Dental, Vision, Life Insurance, Disability, and other voluntary coverages. You will also be eligible to participate in our 401k program, starting on the first of the month following 30 days of employment with a company match.This employer participates in E-Verify for US-based hires.#AttainFinance
Qualifications
- 15+ yearsof progressiveexperience in information security, with at least 5 years in a senior leadership role, ideally within financial services, asset management, or private credit
- Deep knowledge of cybersecurity frameworks and standards, including NIST CSF, ISO 27001, SOC 2, and CIS Controls
- Demonstrated experience managing security in cloud-native or hybrid environments, with familiarity with AWS, Azure, or GCP security architectures
- Strong understanding of theregulatory landscape relevanttofinancial services,privatecreditand/orinvestment management, including SEC, FINRA, and applicable data privacy laws
- Proven ability to communicate complex security risks to non-technical stakeholders, including boards and investors
- Experience building and scaling security programs in growth-stage or mid-market financial firms is strongly preferred
- Relevant certifications such asCISSP, CISM, or CRISC are preferred.
- Bachelor's degreein Computer Science, Information Security, or a related field; advanced degree preferred