> Markdown version of [/jobs/ext/3542015-chief-information-security-officer-ciso](https://www.wearedevelopers.com/jobs/ext/3542015-chief-information-security-officer-ciso). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Chief Information Security Officer (CISO) - **Company:** Slash Financial, Inc. - **Location:** San Francisco, CA, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Microsoft Access, Application Programming Interfaces (APIs), Amazon Web Services, Software System Penetration Testing, Cloud Computing Security, Key Management, PCI Data Security Standards, Data Logging, Rate Limiting, Cloudflare - **Published:** September 30, 2026 - **Apply:** https://startup.jobs/chief-information-security-officer-slash-com-10223391 ## About the Role * 10+ years in security, with meaningful time leading security at a fintech, payments company, bank, or crypto company, where the stakes were real money. * A builder's track record. You've stood up a security program from an early stage and scaled it through hypergrowth. * Deep technical credibility. You can go line by line through an auth flow with a senior engineer, and then explain the risk to our board in five minutes. * Hands-on experience with PCI DSS and SOC 2, and with the security expectations of sponsor banks and the FFIEC-style examinations they run. * Strong cloud security experience, ideally AWS, in a modern engineering environment that ships quickly. * Good judgment about tradeoffs. You make security the fast path for engineers, not the blocker. * Calm and decisive during incidents. * Bonus: experience securing crypto or stablecoin infrastructure, card issuing programs, or global and multi-entity payment operations. Also a plus: you've been a founder, or an early security leader at a company that went through a big growth arc. ## Description Our customers trust us with their operating cash, their cards, their payroll, and their cross-border payments. Keeping that money and data safe is one of the most important things we do. We're hiring our first CISO to own security across the whole company. You'll be responsible for the product, the infrastructure, our people, our vendors, and our relationships with bank partners and auditors. This is not a policy-and-slide-deck role. You'll write threat models, review architecture, and get hands-on when it matters. You'll also build the team and program that let Slash scale to many times its current size without slowing down. You'll report to CTO and work closely with engineering, compliance, legal, risk, and our partner banks. What you'll do * Own Slash's security strategy and program end-to-end. That includes deciding what matters most, what to build versus buy, and what we can safely leave for later. * Build and lead the security team, starting with our Security Engineering hire, and recruit a small group of exceptional engineers. * Secure a platform that moves real money. Scope includes card issuing and PCI DSS, ACH and wire flows, stablecoin payments, treasury, working capital, and our public API. * Lead account-security and anti-takeover work, including MFA and passkeys, session and device security, rate limiting, and admin and permission controls. Partner with fraud and risk teams on the threats that sit between security and fraud. * Set the approach for securing AI agents and automation that act on customer accounts. Define permissions, guardrails, auditability, and abuse prevention for autonomous financial actions. * Own cloud and infrastructure security posture across AWS and Cloudflare, including identity and access, secrets management, logging, detection, and response. * Build and run incident response. Own the playbooks, the on-call process, and customer, partner, and regulatory communication when something goes wrong. * Own our compliance frameworks and audits, including SOC 2 Type II and PCI. Support partner-bank oversight reviews, due diligence, and examinations, and answer enterprise customer security reviews. * Stand up third-party and vendor risk management across our banking, crypto, lending, and infrastructure partners. * Run pen testing, the bug bounty program, and red-team exercises, and make sure findings actually get fixed. * Brief leadership and the board on security risk in plain language. ## Related Videos - [Fireside Chat with Cloudflare's Chief Strategy Officer, Stephanie Cohen (with Mike Butcher MBE)](https://www.wearedevelopers.com/videos/1366-fireside-chat-with-cloudflare-s-chief-strategy-officer-stephanie-cohen-with-mike-butcher-mbe) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Rate-limiting using eBPF and Istio: How to protect your SaaS customers from themselves](https://www.wearedevelopers.com/videos/100220-rate-limiting-using-ebpf-and-istio-how-to-protect-your-saas-customers-from-themselves) - [Crypto-secure Data Management with In-Database Blockchain](https://www.wearedevelopers.com/videos/632-crypto-secure-data-management-with-in-database-blockchain) - [How we built an AI-powered code reviewer in 80 hours](https://www.wearedevelopers.com/videos/1511-how-we-built-an-ai-powered-code-reviewer-in-80-hours) - [Build Delightful Mobile Experiences with Kotlin, Realm, and Atlas Device Sync](https://www.wearedevelopers.com/videos/694-build-delightful-mobile-experiences-with-kotlin-realm-and-atlas-device-sync) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Security Basics for Vibe Coders](https://www.wearedevelopers.com/magazine/598-security-basics-for-vibe-coders) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing)