Chief Product & Information Security Officer
InvestCloud, Inc.USA3d ago
SecurityExecutiveremotecurated-jd
Job description
Chief Product & Information Security Officer at InvestCloud, Inc.
About the role
InvestCloud is hiring a Chief Product & Information Security Officer to manage global security strategy, risk management, and incident response. This position holds direct responsibility for the security of all software products, ensuring protection is integrated from initial architecture through final delivery to clients.
Key facts
What you'll do
- Establish and direct enterprise security policies, standards, and controls for both corporate infrastructure and software products.
- Manage product security throughout the software development lifecycle, including secure design, vulnerability management, and testing.
- Collaborate with engineering and product leads to integrate security requirements into release cycles and architectural reviews.
- Direct security operations and the Computer Security Incident Response Team.
- Present security metrics, risk assessments, and product posture updates to executive leadership.
- Maintain audit readiness and ensure compliance with financial services and data protection regulations.
- Manage cyber risk and evaluate threats across cloud, data, and third-party environments.
- Build and mentor a high-performing team focused on both information and product security.
Requirements
- Significant leadership experience in cybersecurity or information security, including a senior role involving executive-level influence.
- Proven expertise in application security, DevSecOps, and secure software development practices.
- Deep knowledge of risk management, identity and access management, security operations, and regulatory compliance.
- Ability to manage security programs within complex, regulated environments such as financial services or enterprise software.
- Bachelor degree.
Nice to have
- Advanced degree.
- Relevant certifications such as CISSP, CISM, or CSSLP.
Skills & tools
- SAST (Static Application Security Testing)
- DAST (Dynamic Application Security Testing)
- SCA (Software Composition Analysis)
- DevSecOps
Practical notes
Compensation is determined by experience, education, skills, internal equity, and geographic location. Benefits include medical, dental, vision, disability, and life insurance, FSA, HSA, EAP, health advocacy, and voluntary plans for legal, identity theft, and pet insurance. The package also includes a 401(k) plan with company match and paid time off.