Chief Information Security Officer leading global information security strategy and protecting systems at Cloudinary. Overseeing security governance, compliance, and incident readiness while collaborating with various teams.
Responsibilities
Develop and maintain the company’s information security strategy, policies, and long-term roadmap. Both for production environments and for internal business by overseeing security of enterprise systems.
Lead security risk assessments, mitigation planning, and ongoing security monitoring.
Lead incident response planning, preparedness, and execution.
Manage security governance, including controls, documentation, and audit readiness.
Ensure compliance with relevant standards and regulations such as SOC 2, ISO 27001, GDPR, and emerging AI frameworks.
Direct security architecture reviews and support secure development practices across product and engineering teams.
Ensure security is integrated into engineering culture and delivery without hindering velocity, while aligning platform security with engineering practices and production resiliency requirements.
Oversee vendor security, penetration testing, and third-party risk management.
Serve as the primary security contact for customers, partners, auditors, and regulators, and own the security aspects of the company’s products, in alignment with business and customers’ needs.
Provide regular updates to executive leadership on security posture, risks, and priorities.
Requirements
Extensive experience in information security leadership, including prior ownership of a security program at scale at SaaS companies.
Strong understanding of security frameworks, cloud security, risk management, and secure software development.
Expertise in security governance, threat modeling, and compliance frameworks (SOC 2, ISO 27001, GDPR, and emerging AI regulations).
Proven ability to manage incidents, lead cross-functional teams, and implement organisation-wide security practices.
Effective communicator with experience supporting enterprise customers and executive stakeholders.
Proven ability to represent the company’s security posture to enterprise customers, partners, auditors, and regulators.
Relevant certifications (CISSP, CISM, or equivalent) preferred.
Experience as CISO in a publicly traded company or IPO planning is preferred.
Senior Infrastructure Security Engineer handling cloud security and infrastructure lifecycle for Zocks, a fintech startup. Responsible for security initiatives and compliance readiness in a rapidly growing team.
Data Center Security Officer ensuring safety and security for data center clients through patrols and monitoring. Conducting reports and maintaining client security requirements.
Cybersecurity Specialist overseeing the protection of clients' technology systems and networks. Implementing cybersecurity policies and conducting evaluations against cyber threats in a supportive working environment.
Providing security incident management for industrial environments at Telefónica Tech. Utilizing various monitoring platforms to enhance security posture.
Senior Cybersecurity Incident Responder at ZEISS handling technical incident response activities. Collaborating with cyber defense teams to ensure effective incident management and resolution.
Information Security Manager responsible for steering InfoSec programs globally at ZEISS. Leading cross - functional initiatives and risk management strategies in a high - tech environment.
Endpoint Security Engineer at Booz Allen designing and operationalizing data protection controls. Safeguarding sensitive data across enterprise systems and leading technical operations.
Senior Security Adviser handling governance and US integration tasks at Boeing. Liaising with US - based partners and coordinating crisis management for international security operations.
Lead Industrial Security Specialist at Boeing assessing compliance with security programs and implementing corrective actions. Involves extensive travel and oversight of security protocols across multiple locations.