SVP, Chief Information Security Officer
Attain Finance · United States · Yesterday
RemoteRemoteInformation Technology$250k–$325k/yrFull-time
Responsibilities
- Optimize, implement, and continuously mature an enterprise-wide information security strategy, framework, and roadmap aligned with Attain Finance's business objectives and risk appetite
- Partner with the CTO to integrate security into technology architecture, infrastructure decisions, software development practices, and vendor selection
- Lead and develop a high-performing security team spanning domains such as security operations, vulnerability management, identity and access management, and data protection
- Own the firm's security risk management program, including risk assessments, control gap analysis, and remediation planning across all business lines and technology environments
- Improve and maintain a robust incident response capability, including detection, containment, recovery, and post-incident review processes
- Partner with the Chief Compliance Officer to ensure compliance with applicable regulatory requirements and industry frameworks, including the FTC Safeguards Rule
- Serve as the security liaison to the Board of Directors, executive leadership, investors, and external auditors, providing clear and actionable reporting on the firm's security posture
- Manage third-party and vendor risk, ensuring that security requirements are embedded in procurement, contracting, and ongoing oversight processes
- Champion a firm-wide security awareness and training program that builds a proactive security culture across all employees and business functions
- Evaluate and manage the security technology stack, ensuring investments are effective, scalable, and aligned with the threat landscape
- Build out an internal offensive security (red team) function—establish in-house ethical hacking, penetration testing, and adversary emulation to continuously probe our own systems, applications, and controls for weaknesses before attackers do.
Qualifications
- 15+ years of progressive experience in information security, with at least 5 years in a senior leadership role, ideally within financial services, asset management, or private credit
- Deep knowledge of cybersecurity frameworks and standards, including NIST CSF, ISO 27001, SOC 2, and CIS Controls
- Demonstrated experience managing security in cloud-native or hybrid environments, with familiarity with AWS, Azure, or GCP security architectures
- Strong understanding of the regulatory landscape relevant to financial services, private credit and/or investment management, including SEC, FINRA, and applicable data privacy laws
- Proven ability to communicate complex security risks to non-technical stakeholders, including boards and investors
- Experience building and scaling security programs in growth-stage or mid-market financial firms is strongly preferred
- Relevant certifications such as CISSP, CISM, or CRISC are preferred
- Bachelor's degree in Computer Science, Information Security, or a related field; advanced degree preferred
Pay
Base Salary: $250,000 - $325,000 USD
The actual base salary offered for this full-time position will be determined by various factors, including but not limited to, location, skills, knowledge, competencies, and experience.
Benefits
- Flexible Paid Time Off Program
- Medical, Dental, Vision, Life Insurance, Disability, and other voluntary coverages
- Eligible to participate in our 401k program, starting on the first of the month following 30 days of employment with a company match.