Field CISO
Drata · San Francisco Bay Area · 6 days ago
HybridInformation Technology$210k–$350k/yrFull-time
About the role
The Field Chief Information Security Officer (CISO) will partner with our Sales, Customer Success, and Marketing teams to bring tried-and-true security and GRC expertise into strategic enterprise and F500/G2000 opportunities. They will represent Drata at industry conferences, CISO dinners, and regional roundtables, building genuine relationships across the security and GRC community.
Responsibilities
- Partner with our amazing Sales, Customer Success, and Marketing teams on our most strategic enterprise and F500/G2000 opportunities—bringing tried-and-true security and GRC expertise into the conversation when customers need it most.
- Lead executive briefings and CISO-to-CISO conversations that build trust and help prospective customers feel confident in their decision.
- Represent Drata at industry conferences, CISO dinners, and regional roundtables across the Americas, EMEA, and APAC regions, building genuine relationships across the security and GRC community.
- Share what you’re hearing in the field through webinars, panels, bylines, and press opportunities that build Drata’s voice and credibility in the security and GRC market.
- Advise our CISO, CMO, CRO, and executive leadership team members directly on emerging regulatory shifts, systemic industry risk, and where Drata's security and GRC strategy needs to head next.
- Provide strategy and direction to company-wide responses to major shifts in our industry, such as new regulatory regimes, major certifications, systemic risk events surfaced by our customers, reaffirming the direction set has a lasting effect on Drata's market position.
- Raise the overall security and GRC bar across Drata and industry-wide through knowledge sharing, internal and external forums, and pattern-setting.
- Equip our sales teams with the security and GRC context and talking points they need to navigate technical conversations with confidence.
- Partner with Marketing and GTM leadership to help plan executive events, speaking engagements, dinners, and roundtables throughout the year.
- As a real, ongoing influence on our product roadmap and go-to-market growth strategy — not just relaying field feedback, but helping shape the decisions themselves based on hands on experience corroborated with customer needs.
- Approach every external conversation as an extension of Drata’s security and GRC program, with the same care and integrity you’d bring internally.
- Work alongside our own internal security and GRC team members to support any critical company initiatives as deemed necessary.
Requirements
- 15+ years in security and GRC, including 10+ years leading and managing security and GRC teams and 5+ years in the CISO seat (as a CISO, Deputy CISO, or equivalent senior security and GRC leader).
- A strong grasp of the compliance frameworks our customers care about — including ISO 27001, SOC 2, HIPAA, FedRAMP, GDPR, NIST CSF, PCI DSS, and CCPA — and the practical experience to speak to them with real depth.
- Excellent communication skills, with the ability to move comfortably between boardroom conversations and technical deep-dives.
- A genuine reputation and network within the security and GRC community, built through your own experience leading programs and engaging with peers.
- Comfort working with ambiguity — turning undefined, fast-moving problems like regulatory direction, market shifts, or systemic risk into clear strategy, not just talking points.
- Experience partnering with go-to-market teams in customer-facing conversations, and comfort with the pace and cadence of enterprise sales cycles.
- A track record of thought leadership—speaking, writing, or other public and social engagement that reflects your experience and perspective.
- Familiarity with SaaS and cloud-native environments, along with a thoughtful perspective on how AI is shaping both security and GRC risk and practice.
- Familiarity with compliance automation platforms like Drata, so you can speak to our own product with the same credibility you bring to security and GRC itself.
- Openness to travel regularly and represent Drata’s security and GRC program in a public-facing capacity.
- A curious, thoughtful approach to using AI in your own work, with the judgment to apply it responsibly.
Qualifications
- 15+ years in security and GRC, including 10+ years leading and managing security and GRC teams and 5+ years in the CISO seat (as a CISO, Deputy CISO, or equivalent senior security and GRC leader).
- Willingness to travel regularly - 50-75% (including international travel) for customer meetings, conferences, and field events.
- Professional certifications such as CISSP, CISM, CRISC, or CCSP are a plus (though real, tenured experience carries more weight).