Chief Information Security Officer (CISO)

Obsidian Security
Palo Alto
Workplace: OnsiteFull timeUSD 300,000 - 380,000 annuallyFunction: CybersecurityExperience: 15+ yearsEducation: mastersSkills: ["Executive communication","Board-level communication","Cross-functional leadership","Risk management","Security governance"]

Own the company’s internal security program end-to-end and serve as a visible security executive for customers, partners, and the market. Set and execute global security strategy, manage cyber risk and third-party assessments, and lead security architecture, engineering, detection, vulnerability management, and incident response. Embed secure-by-design across the SDLC, establish AI governance for AI/ML risks, lead cross-functional security partnerships, and represent Obsidian during sales cycles and audits.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Obsidian Security
Obsidian Security
1 day ago

Chief Information Security Officer (CISO)

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 1 hour agoStatus: Live

Job Summary

Own the company’s internal security program end-to-end and serve as a visible security executive for customers, partners, and the market. Set and execute global security strategy, manage cyber risk and third-party assessments, and lead security architecture, engineering, detection, vulnerability management, and incident response. Embed secure-by-design across the SDLC, establish AI governance for AI/ML risks, lead cross-functional security partnerships, and represent Obsidian during sales cycles and audits.
Location: Palo Alto
Workplace: Onsite
Employment Type: Full time
Job Function: Cybersecurity
Seniority: CXO level

Key Responsibilities

  • •Design and execute a global security strategy aligned with business growth; advise the board and executives on cyber risk with actionable mitigation plans.
  • •Own cyber risk management, including security risk assessments, third-party vendor reviews, and executive-backed initiatives targeting measurable risk reduction.
  • •Build and lead product/application security, infrastructure protection, and security engineering teams; oversee threat detection, vulnerability management with SLA performance tracking, and incident response.
  • •Embed secure-by-design principles across the SDLC, including secure coding standards, penetration testing, bug bounty programs, and AI/ML security requirements.
  • •Establish AI governance (acceptable use, AI data loss prevention, third-party AI vendor risk assessments), build AI threat detection/response, and lead adoption of AI and automation; also recruit, mentor, and retain the security org and own the security budget.

Pay and Benefits

Salary: USD 300,000 - 380,000 annually
Equity and Bonus:Equity
Perks:Health InsuranceDentalVision401kEquityPaid LeaveLearning BudgetParental Leave

Key Requirements

  • •15+ years in information security with 5+ years in senior leadership (CISO/VP/Deputy CISO/Sr. Director of Security or equivalent).
  • •Deep experience building and scaling security teams across product security, security architecture, infrastructure protection, and enterprise risk management.
  • •Strong track record securing cloud-native SaaS, including container-based workloads and next-generation security tooling.
  • •Experience developing AI governance frameworks and understanding AI/ML attack surfaces (model poisoning, prompt injection, training data extraction, adversarial inputs, ML supply chain risks).
  • •Demonstrated security program maturity improvements using NIST CSF, ISO 27001, or similar frameworks, with measurable results.
Experience:15+ yearsSaaSCloud-nativeAI governanceAI/ML securityCybersecurityProduct/application security
Education:Master's in Information Security, Computer Science, or related field
Skills:Executive communicationBoard-level communicationCross-functional leadershipRisk managementSecurity governance
Tech Stack:NIST CSFISO 27001OAuth tokensContainer workloadsCI/CD code scanningIdentity-as-a-serviceSOAROWASP Top 10 for LLMsNIST AI RMFMITRE ATLASAI/ML red teamingBug bounty programsPenetration testingAI-assisted threat detectionAutomated triage

Company Brief

Obsidian Security
Provides cloud-native security solutions that detect and respond to identity- and configuration-based threats across SaaS, IaaS, and cloud identity platforms. Focuses on discovering risky exposures, prioritizing alerts, and enabling remediation for enterprise cloud environments.
Industry: Cybersecurity
Headquarters: San Mateo, United States
WebsiteLinkedIn