> Markdown version of [/jobs/ext/2727961-chief-information-security-officer-ciso](https://www.wearedevelopers.com/jobs/ext/2727961-chief-information-security-officer-ciso). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Chief Information Security Officer (CISO) - **Company:** Obsidian Security, Inc. - **Location:** Palo Alto, United States - **Experience:** Expert - **Salary:** $300,000.0 - **Contract:** Permanent contract - **Skills:** Training Data, Artificial Intelligence, Software System Penetration Testing, Software as a Service, Cloud Engineering, Cyber Security, Continuous Integration, Information Leak Prevention, IT Management, Intrusion Detection and Prevention, Open Web Application Security, Systems Development Life Cycle, Secure Coding, Software Vulnerability Management, Large Language Models, Software Security, Cyber Threat Analysis, AI Platforms, Information Technology, Cybercrime, Machine Learning Operations - **Published:** September 5, 2026 - **Apply:** https://startup.jobs/chief-information-security-officer-ciso-obsidian-security-9924996 ## About the Role * 15+ years in information security, with 5+ years in a senior leadership role (CISO, VP/Deputy CISO, Sr. Director of Security, or equivalent). * Deep experience building and scaling security teams across product security, security architecture, infrastructure protection, and enterprise risk management. * Strong track record securing cloud-native SaaS environments, including container-based workloads and next-generation security tooling (endpoint protection, CI/CD-integrated code scanning, identity-as-a-service, automated monitoring/remediation). * Experience developing AI governance frameworks and familiarity with AI/ML attack surfaces (model poisoning, prompt injection, training data extraction, adversarial inputs, ML supply chain risks). * Experience operating as a customer-facing security executive, including direct participation in sales cycles, regulated entity security reviews, and audits. * Demonstrated success improving security program maturity using NIST CSF, ISO 27001, or similar frameworks, with measurable results. * Proven ability to present to boards, advise executive leadership, and communicate security posture to customers in support of revenue goals. * Effective cross-functional partner with legal, compliance, and IT leadership in a matrixed environment. * Experience managing siginificant security budgets. * Master's degree in Information Security, Computer Science, or a related field preferred. Executive leadership education is a plus., * Experience at a cybersecurity vendor, where the CISO role carries both internal and external credibility demands. * Background in critical infrastructure security (energy, utilities, telecommunications) in addition to SaaS/technology. * Hands-on experience deploying AI/ML within security operations (SOAR, AI-assisted threat hunting, automated triage) and familiarity with AI security frameworks (OWASP Top 10 for LLMs, NIST AI RMF, MITRE ATLAS). * Experience securing AI features within a commercial SaaS product, including red-teaming or adversarial testing of AI/ML systems. * Track record conducting security due diligence for M&A transactions. * Experience engaging government stakeholders or congressional committees on security matters. ## Description The CISO will own Obsidian's internal security program end-to-end while serving as a visible security leader to our customers, partners, and the broader market. This role reports to the Chief Legal and Trust Officer., * Security Strategy & Executive Communication: Design and execute a global security strategy aligned with business growth objectives. Advise the board and executive leadership on critical cyber risk domains with clear, actionable mitigation plans. * Cyber Risk Management: Own the cyber risk management program, including security risk assessments, third-party vendor reviews, and executive-backed mitigation initiatives targeting measurable risk reduction. * Security Architecture, Engineering & Operations: Build and lead teams spanning product/application security, infrastructure protection, and security engineering. Oversee threat detection, vulnerability management (with SLA-based performance tracking), and incident response. Establish a guardrail-based controls model for cloud and container workloads. * Product Security: Embed secure-by-design principles across engineering workflows, integrating security early and consistently throughout the SDLC, including secure coding standards, penetration testing, bug bounty programs, and security requirements for AI/ML components (model integrity, training data protection, prompt injection prevention, output validation). * AI Security & Governance: Establish enterprise AI governance (acceptable use, data loss prevention for AI inputs, vendor risk assessments for third-party AI services). Build detection and response capabilities for AI-powered attack vectors. Drive adoption of AI and automation across the security function, including AI-assisted threat detection, automated incident response, and intelligent vulnerability prioritization. * Cross-Functional Partnerships: Partner with Engineering and Product to embed security throughout the development lifecycle, AI/ML feature delivery, and infrastructure architecture decisions. Support Sales and TAM teams by participating in customer security reviews, responding to questionnaires, and enabling the team to speak confidently about Obsidian's security posture. Collaborate with Marketing to develop security-focused content, support thought leadership positioning and inform messaging around trust and security. * Customer Trust & External Presence: Serve as the executive-level security contact for prospects and customers during sales cycles, audits, and security reviews. Represent Obsidian in industry forums and public engagements to build market credibility. * Team Leadership & Budget: Recruit, mentor, and retain a high-performing security organization. Own the security budget with precise, on-target forecasts. * M&A Due Diligence: Assess the security posture, risk exposure, and integration readiness of prospective acquisition targets. ## Related Videos - [Fighting the Next Wave of Cybercrime](https://www.wearedevelopers.com/videos/100331-fighting-the-next-wave-of-cybercrime) - [The New AI Security Stack: Observe, Detect, Protect](https://www.wearedevelopers.com/videos/100302-the-new-ai-security-stack-observe-detect-protect) - [Fireside Chat: Deep Learning, Deep Impact: Harnessing AI for Language Innovation](https://www.wearedevelopers.com/videos/612-fireside-chat-deep-learning-deep-impact-harnessing-ai-for-language-innovation) - [This App Reached 10,000 Users in One Week. Here's How.](https://www.wearedevelopers.com/videos/100329-this-app-reached-10-000-users-in-one-week-here-s-how) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Exploring 5 Key Applications of AI Abundance with Blockchain Assurance](https://www.wearedevelopers.com/videos/971-exploring-5-key-applications-of-ai-abundance-with-blockchain-assurance) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Best US AI Conferences for CTOs in 2026: Build vs. Buy, Vendor Evaluation, and Peer Intelligence](https://www.wearedevelopers.com/magazine/736-best-us-ai-conferences-for-ctos-in-2026-build-vs-buy-vendor-evaluation-and-peer-intelligence) - [Stephan Gillich - Bringing AI Everywhere](https://www.wearedevelopers.com/magazine/489-stephan-gillich-bringing-ai-everywhere) - [Trustworthy AI Starts at Deployment: 5 Checks Before You Ship](https://www.wearedevelopers.com/magazine/753-trustworthy-ai-starts-at-deployment-5-checks-before-you-ship) - [Navigating the AI Shift](https://www.wearedevelopers.com/magazine/629-navigating-the-ai-shift)