CISO
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+11 more
Job description
Be an Early Applicant Remote Hiring Remotely in USA Entry level Remote Hiring Remotely in USA Entry level Lead Ent’s internal security program across people, systems, infrastructure, product development, and company data. Set security strategy, manage risk, establish cloud and endpoint controls, lead incident response, embed security into software development, and oversee SOC 2, ISO 27001, FedRAMP, audits, and customer diligence. Build the security team and operating model while advising executives, the board, customers, and partners on security risks and priorities., We are seeking a hands-on Chief Information Security Officer to build and lead Ent’s internal security program as we scale. You will own the security of our people, systems, infrastructure, product development environment, and company data. You will work closely with our founders and leaders across Engineering, Product, Legal, People Operations, IT, and Go-to-Market to make clear, risk-based decisions and earn the trust of large enterprise and government customers.
This is an internal security leadership role with meaningful customer-facing responsibility. Because Ent is building AI-native endpoint security, you will need deep technical credibility, strong operating judgment, and the ability to turn high security standards into practical controls that protect the company without slowing the team down. You will set the strategy, personally drive the highest-priority work, and build the team and operating model Ent needs for its next stage.
What You’ll Achieve
- Set Ent’s company-wide security strategy and roadmap, with priorities, ownership, and measurable outcomes that reflect our stage, risk profile, and customer commitments.
- Serve as a hands-on security leader. Personally drive critical assessments, control design, remediation, and incident work while building a focused internal team and using outside partners where they add leverage.
- Own security risk across identities, employee endpoints, SaaS applications, cloud infrastructure, company data, the software supply chain, and third-party vendors.
- Partner with Engineering and Product to embed security into architecture and the software development lifecycle, including threat modeling, secure design reviews, vulnerability management, secrets and dependency management, logging, monitoring, and remediation.
- Establish and continuously improve core controls for identity and access management, device security, privileged access, data protection, configuration management, and employee onboarding and offboarding across Ent’s cloud-first environment.
- Build and lead incident response, including detection and escalation processes, investigation, containment, communications, tabletop exercises, post-incident reviews, and improvements to business continuity and disaster recovery.
- Lead Ent’s security assurance and compliance program. Translate requirements from frameworks and programs such as SOC 2, ISO 27001, FedRAMP, and customer-specific standards into durable controls, with clear judgment about what Ent needs now and what can come later.
- Own customer and partner security diligence, including questionnaires, audits, penetration tests, security reviews, and security commitments in contracts. Partner with Legal and Go-to-Market to respond accurately and efficiently.
- Create clear, usable policies and security education that help employees make good decisions, including guidance for sensitive data, approved AI tools, and emerging risks from AI agents and automation.
- Use Ent’s product internally as part of the company’s security program and provide structured feedback to Product, Engineering, and Research based on real operating experience.
- Give the executive team and board a clear view of Ent’s risk, readiness, incidents, and investment priorities, and represent Ent credibly in strategic customer security conversations when needed., Serves as an outsourced CISO for multiple clients while leading SGP’s internal cybersecurity and compliance program. Responsibilities include NIST, CMMC, and ISO 27001 alignment; security assessments; risk reviews; SSPs, POA&Ms, audits, incident response, vulnerability management, executive reporting, security training, and compliance monitoring. The role also manages assessment partners, subcontracted vCISOs, client proposals, scalable GRC methodologies, and security reviews for business initiatives. Top Skills: Business IntelligenceC3PaoCisaCmmcErpFbiIso/Iec 27001Nist Sp 800-171Nist Sp 800-53NocPlans Of Action And Milestones (Poa&Ms)RpoSocSystem Security Plans (Ssps) Eon.io
CISO
One Month Ago Remote US Expert/Leader Expert/Leader Big Data * Cloud * Big Data Analytics Own Eon’s enterprise security strategy, governance, risk, compliance, engineering, operations, and customer trust programs. Build and lead the security organization, manage SOC 2, ISO 27001, NIST, and FedRAMP readiness, oversee detection and incident response, partner with Engineering and Product on secure design, and represent security to executives, the board, regulators, enterprise customers, and industry stakeholders. Top Skills: CloudCloud InfrastructureData ProtectionFedrampInfrastructure SecurityIso 27001NistSaaSSecure Software Development LifecycleSoc 2StaterampVulnerability Management Afterpay
Requirements
- Experience operating at CISO, Deputy CISO, Head of Security, or equivalent scope in a high-growth technology company. Experience building a security program during an early stage of growth is strongly preferred.
- Deep technical understanding of cloud, identity, endpoint, application, product, and infrastructure security. You can engage directly with engineers on architecture, threat models, control implementation, and remediation.
- Experience securing cloud-first environments and modern identity and device ecosystems, including platforms such as AWS, Azure, or GCP; Google Workspace or Microsoft Entra ID; and macOS and Windows device management.
- Strong command of incident response, vulnerability management, security monitoring, third-party risk, data protection, and secure software development practices.
- Experience building and maintaining security assurance or compliance programs such as SOC 2, ISO 27001, or FedRAMP, and supporting the diligence requirements of sophisticated enterprise or government customers.
- A current understanding of security risks created by AI systems, employee use of generative AI, autonomous agents, sensitive data flows, and rapidly changing development tools.
- Sound risk judgment and a practical operating style. You know when to insist on a control, when to accept or escalate risk, and how to design a solution the organization can sustain.
- The ability to move comfortably between strategy and execution. You are willing to investigate an issue, review a design, write or refine a policy, answer a customer question, and establish a longer-term program.
- Strong communication skills with technical teams, executives, board members, customers, auditors, and partners. You explain risk clearly, without relying on fear or unnecessary complexity.
- A low-ego, highly collaborative approach and the ability to build trust across functions while holding a high bar for security and accountability.
Benefits & conditions
Our Benefits
- Distributed workplace. While we have positions we hire for in our SF office, we also hire remotely across North America.
- Own a piece of the journey. Every teammate gets meaningful equity on top of their salary.
- We’ve got you covered. 90% of your medical, dental, and vision is paid by Ent. We also cover 75% for your dependents.
- Take the time you need. Our flexible PTO lets you recharge, travel, or just take a breather.
- Family matters. 12 weeks of fully paid maternity leave (birth, adoption, or foster) and 8 weeks fully paid paternity leave.
- Live well. A $100 monthly lifestyle account to spend on what keeps you healthy and happy - fitness, wellness, learning, and more.
- Set up your space. A $500 home office stipend when you join as a remote employee.
Diversity & Accommodations
We’re committed to building a diverse, inclusive, and equitable workplace where people of all backgrounds, identities, experiences, and abilities are welcomed, valued, and supported. We recognize there is no single path to success and value nontraditional career journeys and diverse perspectives as key to building stronger, more innovative teams.
We strive to ensure an inclusive experience at every stage of hiring and are happy to provide reasonable accommodations. If you require accommodations or accessible formats at any point during our process, please let your recruiter know. As an equal opportunity employer, our hiring process is designed to put you at ease and help you do your best work. If there’s anything we can do to improve your experience, we’re always open to feedback., 59 Minutes Ago Remote or Hybrid 173K-312K Annually Senior level 173K-312K Annually Senior level Fintech * Payments * Software * Financial Services Lead Sales Development across North America and the UK, owning top-of-funnel pipeline, regional alignment, performance reporting, upmarket expansion, cross-functional partnerships, talent development, and technology-enabled productivity. The role manages teams and managers, establishes scalable inbound and outbound motions, partners with Marketing, Sales, Finance, and Strategy, and drives revenue-focused planning, qualification, and conversion. Top Skills: AIAnalyticsAutomationReporting Tools
What you need to know about the Colorado Tech Scene
With a business-friendly climate and research universities like CU Boulder and Colorado State, Colorado has made a name for itself as a startup ecosystem. The state boasts a skilled workforce and high quality of life thanks to its affordable housing, vibrant cultural scene and unparalleled opportunities for outdoor recreation. Colorado is also home to the National Renewable Energy Laboratory, helping cement its status as a hub for renewable energy innovation.
Key Facts About Colorado Tech
- Number of Tech Workers: 260,000; 8.5% of overall workforce (2024 CompTIA survey)
- Major Tech Employers: Lockheed Martin, Century Link, Comcast, BAE Systems, Level 3
- Key Industries: Software, artificial intelligence, aerospace, e-commerce, fintech, healthtech
- Funding Landscape: $4.9 billion in VC funding in 2024 (Pitchbook)
- Notable Investors: Access Venture Partners, Ridgeline Ventures, Techstars, Blackhorn Ventures
- Research Centers and Universities: Colorado School of Mines, University of Colorado Boulder, University of Denver, Colorado State University, Mesa Laboratory, Space Science Institute, National Center for Atmospheric Research, National Renewable Energy Laboratory, Gottlieb Institute
About the company
Ent is the intent-aware workspace security platform for securing human and AI-driven work. Built to protect productivity, the new attack surface, Ent understands not just what users and agents do but why, and intervenes at the moment of risk before incidents occur. Where existing tools see events, Ent sees intent, so security teams can step in at the moment of risk instead of investigating days later. Founded by Lou Manousos and Brandon Dixon, co-founders of RiskIQ (acquired by Microsoft) and the team behind Microsoft Security Copilot, Ent is in production with Global 2000 customers across hospitality, financial services, and defense, and backed by Decibel, Sequoia, Crosspoint Capital, Craft Ventures, Shield Capital, Felicis, and In-Q-Tel. We’re now hiring the team that will define this category.
How We Work
Customer first. The product and the business are built around problems we’ve watched real security teams struggle with - not the other way around. Every roadmap conversation starts with what a CISO told us last week.
Humble. No drama. We hire people who share the mission and trust each other to deliver. Teamwork over showmanship. Accountability over politics. The work speaks louder than the person doing it.
Urgency. The window to build a durable security company in the AI era is open right now and it will not stay open. The shot clock has started. We move at the speed of the people we want to protect.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
9 Ways to Make Money Hacking
What Are The Top Skills Required For Azure Developers?
Understanding and Mitigating Common Web Vulnerabilities
Navigating the AI Shift