> Markdown version of [/jobs/ext/1394367-svp-chief-information-security-officer](https://www.wearedevelopers.com/jobs/ext/1394367-svp-chief-information-security-officer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # SVP, Chief Information Security Officer - **Company:** Attain - **Location:** United States - **Experience:** Expert - **Salary:** $250,000.0 - $325,000.0 - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Software System Penetration Testing, Microsoft Azure, Cloud Engineering, Cyber Security, Identity and Access Management, Red Team (Cyber Security), Software Engineering, Software Vulnerability Management, Google Cloud, Information Technology, CIS Benchmarks - **Published:** July 23, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=a3d5af2ee452500a ## About the Role * 15+ years of progressive experience in information security, with at least 5 years in a senior leadership role, ideally within financial services, asset management, or private credit * Deep knowledge of cybersecurity frameworks and standards, including NIST CSF, ISO 27001, SOC 2, and CIS Controls * Demonstrated experience managing security in cloud-native or hybrid environments, with familiarity with AWS, Azure, or GCP security architectures * Strong understanding of the regulatory landscape relevant to financial services, private credit and/or investment management, including SEC, FINRA, and applicable data privacy laws * Proven ability to communicate complex security risks to non-technical stakeholders, including boards and investors * Experience building and scaling security programs in growth-stage or mid-market financial firms is strongly preferred * Relevant certifications such as CISSP, CISM, or CRISC are preferred. * Bachelor's degree in Computer Science, Information Security, or a related field; advanced degree preferred ## Description Are you ready to make a difference in the world of consumer finance? At Attain Finance, we bring over 50 years of expertise in providing credit solutions across the U.S. and Canada. Our deep roots in the financial industry have empowered us to develop convenient, easily accessible financial services that meet our customers' growing needs. Join a leading consumer credit lender that thrives on innovation and collaboration, where your contributions are truly valued. Our portfolio includes distinguished brands like Cash Money®, LendDirect® and Heights Finance. Each brand is constantly evolving to better serve our customers. Be part of a dynamic team that is shaping the future of consumer finance. Apply today and take the next step in your career with Attain Finance! The SVP, Chief Information Security Officer (CISO) will serve as Attain Finance's senior-most authority on information security, owning the strategy, execution, and governance of all security functions across the organization. Partnering closely with the Chief Technology Officer and reporting to the Chief Legal and Administrative Officer, the SVP, CISO will align security capabilities with the firm's growth objectives while managing risk in a highly regulated financial services environment. Responsibilities: * Optimize, implement, and continuously mature an enterprise-wide information security strategy, framework, and roadmap aligned with Attain Finance's business objectives and risk appetite * Partner with the CTO to integrate security into technology architecture, infrastructure decisions, software development practices, and vendor selection * Lead and develop a high-performing security team spanning domains such as security operations, vulnerability management, identity and access management, and data protection * Own the firm's security risk management program, including risk assessments, control gap analysis, and remediation planning across all business lines and technology environments * Improve and maintain a robust incident response capability, including detection, containment, recovery, and post-incident review processes * Partner with the Chief Compliance Officer to ensure compliance with applicable regulatory requirements and industry frameworks, including the FTC Safeguards Rule * Serve as the security liaison to the Board of Directors, executive leadership, investors, and external auditors, providing clear and actionable reporting on the firm's security posture * Manage third-party and vendor risk, ensuring that security requirements are embedded in procurement, contracting, and ongoing oversight processes * Champion a firm-wide security awareness and training program that builds a proactive security culture across all employees and business functions * Evaluate and manage the security technology stack, ensuring investments are effective, scalable, and aligned with the threat landscape * Stand up and lead a proactive threat hunting program - build the team, tooling, and playbooks to actively search for threats across our environment rather than waiting on alerts, and mature it from ad-hoc hunts to a repeatable, intel-driven capability. Build out an internal offensive security (red team) function - establish in-house ethical hacking, penetration testing, and adversary emulation to continuously probe our own systems, applications, and controls for weaknesses before attackers do. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [A practical guide to writing secure Dockerfiles](https://www.wearedevelopers.com/videos/109-a-practical-guide-to-writing-secure-dockerfiles) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [The Cloud is Calling: Answer with In-Demand Skills](https://www.wearedevelopers.com/videos/945-the-cloud-is-calling-answer-with-in-demand-skills) - [OPA for the cloud natives](https://www.wearedevelopers.com/videos/713-opa-for-the-cloud-natives) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology)