> Markdown version of [/jobs/ext/2196203-chief-information-security-officer](https://www.wearedevelopers.com/jobs/ext/2196203-chief-information-security-officer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Chief Information Security Officer - **Company:** Swan, L.L.C. - **Location:** United States (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Cyber Security, Digital Asset Management, Digital Assets, Identity and Access Management, IT Management, Intrusion Detection and Prevention, Open Web Application Security, Software Maintenance, IT General Controls (ITGC), Large Language Models, Multi-Agent Systems, Software Security, Patch Management, Virtual Agents, Data Pipelines, Dynamic Application Security Testing - **Published:** August 23, 2026 - **Apply:** https://www.workingnomads.com/job/go/1809065/ ## About the Role * Professional Experience: A minimum of 10 years in a leadership role related to information security and IT, with a demonstrated track record of managing and guiding teams to success. * Financial & Regulatory Experience: Prior experience in financial technology, public companies, or regulated environments a plus. * Experience with digital asset management systems and cold storage systems, also a plus. * Educational Background: Advanced certifications such as CISSP, CISM, or CISA are highly desirable, but not required. * Proactive leadership: Set goals and report on them to leadership. Ensure your team is moving in the right direction with active guidance and engagement. * Balanced ability to multitask in a rapid growth environment: manage long term goals with short term disruptions. * Must be located in and have work authorization in the United States. * Compensation for this role will be based on location and experience, and may include base salary, equity, and benefits ## Description Swan is seeking a hands-on, technically-minded CISO to lead our security team and help scale a robust, risk-informed security program across a rapidly growing fintech platform. You'll be responsible for protecting our clients, partners, and infrastructure, while supporting a culture of trust, transparency, and operational excellence. This role reports directly to the CTO for day to day management and to the Board Audit Committee quarterly. The role involves close collaboration across engineering, product, operations, and legal/compliance., * Security Leadership and Strategy: Define and execute the company's cybersecurity strategy in alignment with business goals and regulatory expectations. Maintain an actionable roadmap that evolves with Swan's growth and risk profile. * Security Team Leadership: Lead the Security group ****responsible for Enterprise IT Security, AppSec, TDR, GRC, and other security functions. Lead the broader Security Guild process which also includes platform and product security teams. Build a high-performance culture focused on proactive risk management and technical depth. Help organize projects and set priorities. * Governance, Risk, and Compliance: Oversee risk management processes, policies, and controls aligned with frameworks such as SOC 2, SOX ITGC, and ISO 27001. Partner with executive team to create a culture of risk ownership and SOPs across the organization. * Security Architecture: Drive secure-by-design principles across infrastructure, applications, and custodial integrations. Review and influence technical designs to ensure security is embedded at every layer. Oversee IAM/PAM efforts. * Threat Detection and Response: Own the incident response program from detection through post-mortem. Ensure continuous improvement through tabletop exercises, simulations, and cross-team coordination. Help select and engage MDR vendors if appropriate to expand coverage. * Vulnerability and Patch Management: Oversee continuous scanning of enterprise systems, manage and prioritize remediations based on risks. * Data Security and Privacy: Advise on data projects across the company to ensure data pipelines are built with Security and Privacy in mind. * Vendor and Custodian Risk Management: Develop and enforce third-party risk management policies for vendors, custodians, and infrastructure providers. Lead due diligence and security review processes. * Training and Awareness: Build and sustain a security-aware culture. Design practical training programs for developers, operators, and executives tailored to real risks in fintech and digital asset environments. * Executive and Board Reporting: Translate technical risk into business impact for leadership and the board. Provide ongoing insight into emerging threats, regulatory developments, and control effectiveness., Swan is an AI powered organization with significant amounts of automation throughout the entire organization, including Security. We expect our entire team, including senior management, to be hands on with these tools. * Build: Author and maintain agentic skills and pipelines for SOC 2 internal controls, ITGC evidence collection, GRC reporting, vendor assessment, security program maintenance, etc. * Operate: Contribute to autonomous DAST, multi-agent PR review, risk-policy merge gates, and agentic red-team validation of the security pipeline itself. * Govern: Apply NIST AI RMF, ISO/IEC 42001, and OWASP LLM/Agentic-AI Top 10. Reason about prompt injection, excessive agency, model/tool supply chain, and non-human identity sprawl. ## Related Videos - [Automated Security for the Entire SDLC](https://www.wearedevelopers.com/videos/100323-automated-security-for-the-entire-sdlc) - [Your Manager Doesn’t Come with a User Manual (But You Can Totally Write One)](https://www.wearedevelopers.com/videos/1495-your-manager-doesn-t-come-with-a-user-manual-but-you-can-totally-write-one) - [Why and when should we consider Stream Processing frameworks in our solutions](https://www.wearedevelopers.com/videos/1085-why-and-when-should-we-consider-stream-processing-frameworks-in-our-solutions) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Navigating the AI Shift](https://www.wearedevelopers.com/magazine/629-navigating-the-ai-shift) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking)