Chief Information Security Officer leading global information security strategy and protecting systems at Cloudinary. Overseeing security governance, compliance, and incident readiness while collaborating with various teams.
Responsibilities
Develop and maintain the company’s information security strategy, policies, and long-term roadmap. Both for production environments and for internal business by overseeing security of enterprise systems.
Lead security risk assessments, mitigation planning, and ongoing security monitoring.
Lead incident response planning, preparedness, and execution.
Manage security governance, including controls, documentation, and audit readiness.
Ensure compliance with relevant standards and regulations such as SOC 2, ISO 27001, GDPR, and emerging AI frameworks.
Direct security architecture reviews and support secure development practices across product and engineering teams.
Ensure security is integrated into engineering culture and delivery without hindering velocity, while aligning platform security with engineering practices and production resiliency requirements.
Oversee vendor security, penetration testing, and third-party risk management.
Serve as the primary security contact for customers, partners, auditors, and regulators, and own the security aspects of the company’s products, in alignment with business and customers’ needs.
Provide regular updates to executive leadership on security posture, risks, and priorities.
Requirements
Extensive experience in information security leadership, including prior ownership of a security program at scale at SaaS companies.
Strong understanding of security frameworks, cloud security, risk management, and secure software development.
Expertise in security governance, threat modeling, and compliance frameworks (SOC 2, ISO 27001, GDPR, and emerging AI regulations).
Proven ability to manage incidents, lead cross-functional teams, and implement organisation-wide security practices.
Effective communicator with experience supporting enterprise customers and executive stakeholders.
Proven ability to represent the company’s security posture to enterprise customers, partners, auditors, and regulators.
Relevant certifications (CISSP, CISM, or equivalent) preferred.
Experience as CISO in a publicly traded company or IPO planning is preferred.
SAP Security GRC Consultant involved in designing and implementing security architectures for Swiss clients. Collaborating with project teams on compliance and security solutions.
Senior Consultant with Wavestone providing SAP Security and IAM solutions in Switzerland. Collaborating on security architectures and supporting clients on SAP security transformations.
Network Security Engineer ensuring secure, highly available enterprise network systems with a focus on collaboration and technical excellence. Involves designing and implementing networking solutions.
Security Manager at Leonardo focusing on cyber compliance and risk management across OT and IT frameworks. Supporting clients in strategic initiatives and infrastructure assessments.
Senior Analyst leading cybersecurity governance initiatives at Elsevier. Developing and maturing governance programs for data protection and risk management across the organization.
Commercial Security Service Sales Executive promoting and selling security services at Johnson Controls. Building relationships and delivering solutions to protect people and property within assigned territories.
Security Incident Responder in a leading IT service company in Germany, responsible for analyzing and responding to IT security incidents while developing technological solutions.
Deputy ISSO leading compliance and security activities for NOAA systems at RCG. Requires active Secret clearance and CISSP certification with 8+ years of experience.
Technical Recruiter hiring for Snap Inc.'s security and machine learning teams. Full life cycle recruiting support for technical talent across Snap's innovations.