Deputy Chief Information Security Officer
Job description
About the role
Sardine is seeking a Deputy Chief Information Security Officer to provide strategic partnership to the CISO and drive the maturation of the enterprise security program across a high-growth environment. This role owns the end-to-end security strategy and execution, translating business objectives into a resilient and scalable security foundation. The hire will act as a cross-functional leader responsible for application security, governance risk and compliance, security operations, cloud and SaaS security, and corporate IT oversight. You will prioritize the highest risks to the business and ensure that security controls are implemented efficiently without impeding innovation. This position requires frequent interaction with executive stakeholders, customers, auditors, and vendors to communicate security posture and decision-making. The Deputy Chief Information Security Officer will champion a pragmatic security culture that balances risk management with speed and business enablement.
Key facts
What you'll do
Partner with the CISO to define, execute, and scale Sardine's multi-year security strategy, roadmap, and priorities.
Identify, prioritize, and address the highest-risk areas across the business by evaluating emerging threats and regulatory changes.
Support executive-level security reporting, budgeting, vendor evaluation, and strategic planning initiatives.
Partner on key compliance and assurance programs including PCI, SOC 2, ISO 27001, DORA, and prepare for future FedRAMP readiness.
Support incident response activities and be prepared to act as deputy incident lead during major security events.
Collaborate with Engineering to advance application security, secure SDLC, vulnerability management, threat modeling, and remediation tracking.
Assess and improve security controls across cloud infrastructure, SaaS tools, identity and access management, endpoint management, and corporate IT environments.
Demonstrate strong application security fluency across the full lifecycle of software delivery, including design, CI/CD, testing, SAST/DAST, dependency scanning, and secrets management.
Partner with Product and Engineering teams to embed security for AI/ML systems, bot mitigation, and abuse prevention strategies.
Engage in customer-facing security activities such as RFPs, security reviews, due diligence, and executive briefings.
Translate complex technical security concepts into clear business language to build trust with enterprise customers and stakeholders.
Partner cross-functionally with Legal, Sales, Engineering, Product, People, and IT to align security initiatives with business needs.
Champion a pragmatic security culture that enables the business while effectively managing risk and maintaining strong governance.
Represent Sardine's security program in internal and external forums, including industry discussions and analyst interactions.
Requirements
Must possess 10-15+ years of cybersecurity experience, including at least 3 years in a senior leadership role managing security programs.
Bring a broad security background across multiple domains and avoid positioning as a single-specialty profile only.
Show strong application security experience and the ability to assess technical risk without needing to write code on a daily basis.
Have operated in startup, scale-up, or similarly resource-constrained environments where prioritization, trade-offs, and pragmatism are essential.
Demonstrate the ability to evaluate risk, stack-rank priorities, and focus on the highest-impact security work under uncertainty.
Possess strong working knowledge of compliance frameworks such as SOC 2, PCI DSS, ISO 27001, GDPR, CCPA, DORA, and have readiness for FedRAMP.
Have direct experience participating in or leading security incidents including detection, response, and post-incident activities.
Show strong fundamentals in cloud security, SaaS security, identity and access management, endpoint security, and zero-trust principles.
Demonstrate familiarity with AI-assisted workflows and emerging AI/ML security risks, including data privacy and model integrity concerns.
Have customer-facing communication skills to support sales engagements, security reviews, and executive-level conversations with customers and partners.
Approach security as a business enabler, collaborating with teams to find safe paths forward rather than defaulting to restrictive "no" decisions.
Exhibit strong leadership presence and the ability to build trust with security, engineering, executive, and go-to-market organizations.
Have prior experience in fintech, payments, security, bot mitigation, or regulated industries considered a plus but is not mandatory.
Must be legally authorized to work in the United States without sponsorship for this role.
Nice to have
Preferred candidates will have experience influencing executive leadership and board-level security discussions.
Familiarity with financial crime prevention, fraud detection, and transaction monitoring technologies is a plus.
Experience supporting procurement, third-party risk management, and vendor security questionnaires is encouraged.
Background in data privacy regulations and privacy program operations is a strong advantage.
Practical notes
Travel: Approximately once every 1-2 months, primarily in North America, with some potential international travel.
Location: Remote, United States.
Work hours: This is a full-time role aligned with U.S. time zones.
</output>