Jobs · Utah

Chief Information Security Officer (CISO)

MasterControl · Salt Lake City, UT · Today
HybridFull-time

About the role

MasterControl Inc. is a leading cloud-based quality and compliance software provider for life sciences and other regulated industries. Our mission is to enable our customers to bring life-changing products to market faster while ensuring compliance and quality throughout the product lifecycle. We are committed to innovation, customer success, and making a positive impact on the world.

Responsibilities

  • Define and execute the company's enterprise security strategy, aligned with business objectives and compliance obligations (including FedRAMP).

  • Own security governance, policies, standards, and risk management practices across the organization.

  • Embed security-by-design principles across systems, applications, cloud infrastructure, and engineering workflows.

  • Set policy for access control, data protection, and secure development practices, partnering with Engineering to embed requirements into the SDLC without becoming a bottleneck.

  • Own data privacy and residency requirements across the regions where we operate infrastructure, including GDPR and other applicable cross-regional obligations.

  • Own the security and governance model for how AI and LLM tooling are used across engineering — controlling what data can reach which models and keeping regulated data inside trusted boundaries.

  • Implement guardrails for AI and agentic workflows to catch data leakage, prompt injection, and unsafe outputs before they reach production or customers.

  • Partner with Engineering leadership to make security a built-in part of our AI-driven SDLC tooling, not a gate bolted on afterward.

  • Evaluate and, where appropriate, pursue recognized AI governance frameworks (e.g., ISO 42001) to give customers confidence in how we govern AI use.

  • Help turn our AI security posture into a competitive advantage in customer conversations, in partnership with Sales and Compliance.

  • Own the enterprise risk assessment program: identify, quantify, and track risk across infrastructure, applications, vendors, and third parties.

  • Run and continuously improve a formal risk register with clear ownership, remediation timelines, and executive reporting.

  • Lead risk assessments for cloud infrastructure and key third-party dependencies (e.g., AWS, Azure), and for new products, features, or architecture changes before launch.

  • Translate technical risk into business terms for executive reporting.

  • Support Sales and Customer Success in customer security conversations, questionnaires, and due diligence reviews — working closely with the Compliance team, who own the customer relationship.

  • Maintain and mature our compliance posture (e.g., FedRAMP, SOC 2, ISO 27001 as applicable) in partnership with Compliance/Validation.

  • Contribute to customer-facing security collateral (architecture summaries, trust documentation) that scales beyond 1:1 conversations.

  • Be available for direct customer engagement when a deal or renewal requires executive-level security assurance.

  • Own the cybersecurity incident response program: detection, escalation, communication, and remediation.

  • Lead cross-functional incident response involving Legal, Engineering, and executive leadership as needed.

  • Ensure continuous monitoring, threat intelligence integration, penetration testing, and vulnerability management.

  • Mature our detection and response capability (SIEM, monitoring, managed detection/response) to steadily reduce mean-time-to-detect.

  • Drive post-incident reviews and continuous improvement.

  • Build, lead, and develop the security team (or oversee the security function, depending on current staffing).

  • Represent security at the executive/leadership table; advise the CEO/CTO on risk posture and security investment priorities.

  • Set and manage the security budget and tooling stack.

Qualifications

  • 8-10 years in security leadership, with direct experience owning risk assessment programs (enterprise, product, and/or third-party risk).

  • Hands-on experience securing cloud environments on AWS and/or Azure.

  • Experience governing the security of AI/LLM usage — data boundaries, guardrails against prompt injection and data leakage, and secure use of AI in engineering workflows.

  • Deep working knowledge of at least one major compliance framework (FedRAMP, SOC 2, ISO 27001, or similar).

  • Experience with data privacy and cross-regional compliance requirements (e.g., GDPR) for organizations operating infrastructure in multiple regions.

  • Experience building or maturing a formal risk register and executive risk reporting.

  • Strong written and verbal communication — able to translate technical security concepts for customers and executives, and to work cross-functionally with Sales, Compliance, and Engineering.

  • Track record of leading incident response for a SaaS or cloud-based product.

Preferred Qualifications

  • Prior experience at a company servicing regulated or security-conscious enterprise/government customers.

  • Experience in life sciences or another regulated vertical with GxP, FDA, or similar quality/regulatory.

  • FedRAMP compliance or authorization experience.

  • Experience pursuing or maintaining ISO 42001 or similar AI governance certification.

  • Experience partnering with Sales/Customer Success/Compliance as a named security resource in customer due diligence.

  • Relevant certifications (CISSP, CISM, CRISC, or equivalent).

Similar jobs