> Markdown version of [/jobs/ext/41031-chief-information-security-officer](https://www.wearedevelopers.com/jobs/ext/41031-chief-information-security-officer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Chief Information Security Officer - **Company:** EP Wealth Advisors - **Location:** United States (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, User Authentication, Software as a Service, Cloud Computing, Cloud Computing Security, Cyber Security, Information Leak Prevention, Identity and Access Management, Network Segmentation, Systems Development Life Cycle, Cloud Services, Phishing, Zero Trust Network Access, Salesforce.Com, Secure Coding, Software Vulnerability Management, Data Processing, Snowflake, Information Technology, Data Management, Machine Learning Operations, Virtual Agents - **Published:** May 19, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=80a8f71260667a0b ## About the Role * Bachelor's degree in Information Security, Computer Science, Engineering, or related field (or equivalent experience) * 10+ years of progressive experience in cybersecurity, including leadership of enterprise security programs * Demonstrated experience leading incident response and managing stakeholders through high-pressure events * Strong understanding of security controls and frameworks relevant to a regulated environment * Proven ability to influence at the executive level and communicate technical risk in clear business terms Preferred * Experience in wealth management, RIA, financial services, or similarly regulated industries * Experience with cloud security (Microsoft ecosystems and modern SaaS environments), identity security, and endpoint security at scale * Relevant certifications (one or more): CISSP, CISM, CCSP, GIAC (GSEC/GCIH/GCIA), or similar * Track record of building and maturing security programs in growth environments (M&A integration, platform standardization, and modernization) ## Description The Chief Information Security Officer (CISO) is the senior leader accountable for EP Wealth's enterprise Information Security program, responsible for setting strategy, building and operating a risk-based security function, and ensuring protection of EP's clients, advisors, and associates. We are seeking a hands-on, cloud-native Chief Information Security Officer to lead EP's enterprise information security program as the firm scales. This player-coach will both set security strategy and risk appetite at the Executive/Board level and roll up their sleeves to design and deliver technical controls, processes and measurable outcomes - strengthening identity and access management, endpoint and cloud security, detection & response, data protection, third-party/custodial risk management, and security governance. With a relentless focus on client trust and operational resilience, the CISO will partner closely with Technology, Legal, Compliance, Risk and Business leadership to enable growth while protecting clients and staff, meeting regulatory obligations, modernizing controls and tooling, and ensuring production readiness for cloud, SaaS and data platforms (e.g., Snowflake, Salesforce, Agentforce) and AI initiatives., Strategy, Governance, and Risk Leadership * Define and execute a multi-year Information Security strategy and roadmap aligned with EP's business priorities, regulatory requirements, and risk appetite. * Mature security governance: policies, standards, exception management, risk decision frameworks and formal production gates. * Lead enterprise risk assessments, threat modeling, remediation prioritization, and executive/Board reporting on security posture and program progress. * Translate security risk into business terms and recommend prioritized investments. Cloud-Native Security & Architecture * Lead security architecture and engineering decisions across our cloud environment, with a strong emphasis on: + Zero Trust principles + Strong Authentication / MFA, privileged access management (PAM) + Device trust and conditional access * Partner with Product & Technology leadership to embed security into architecture reviews, platform selection, and modernization initiatives * Implement CSPM, runtime protection, IaC scanning, network segmentation, and automated compliance checks for cloud workloads. Security Operations, Monitoring, and Incident Response * Oversee security operations including threat intelligence, monitoring, detection, investigation, and response (internal team and/or managed partners) * Maintain and regularly exercise an Incident Response (IR) program, including playbooks, tabletop exercises, executive communications, and coordination with Legal and external counsel * Ensure high-confidence processes for evidence handling, third-party coordination, and post-incident lessons learned Securing Agentic AI & Data * Lead the security aspects of data protection: classification, encryption, DLP, secure sharing, retention, and data loss prevention controls. * Define security guardrails for agentic workers and production AI: data minimization, secure feature stores, model access controls, inference governance, model explainability and drift detection. * Partner with Data & Engineering to secure MLOps pipelines, model registries, and production inference. Ensure safe prompt/data handling and auditability for agents. Security Culture, Awareness, and Training * Drive an enterprise security awareness program tailored to EP's environment (advisor-facing, client-facing, corporate staff). * Promote a culture of "secure by default," emphasizing practical behaviors that reduce social engineering risk. Third-Party and Vendor Risk Management * Transform and direct program to evaluate and monitor third parties (SaaS, vendors, custodians, and key partners) including: + Security questionnaires, attestations (SOC 2/ISO), and contract security requirements + Ongoing monitoring and periodic reassessments Secure Development and Technology Enablement * Partner with Engineering/IT to mature secure engineering practices, such as: + Security requirements in the SDLC + Vulnerability management and remediation SLAs + Configuration baselines, hardening standards, and security testing Team Leadership and Program Operations * Build, lead, and mentor a high-performing security team and partner ecosystem * Establish KPIs and program metrics that drive measurable improvement (e.g., phishing resilience, MFA coverage, patch SLAs, EDR coverage) * Manage budget and vendor relationships to ensure efficient, effective security coverage ## Related Videos - [How to Cause (or Prevent) a Massive Data Breach- Secure Coding and IDOR](https://www.wearedevelopers.com/videos/39-how-to-cause-or-prevent-a-massive-data-breach-secure-coding-and-idor) - [How Cisco embraced a DevOps culture within its network engineering team](https://www.wearedevelopers.com/videos/99-how-cisco-embraced-a-devops-culture-within-its-network-engineering-team) - [Passkeys: Truly Phishing-Resistant? Implementation and Pitfalls](https://www.wearedevelopers.com/videos/100156-passkeys-truly-phishing-resistant-implementation-and-pitfalls) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [Don't Be A Naive Developer: How To Avoid Basic Cybersecurity Mistakes](https://www.wearedevelopers.com/videos/498-don-t-be-a-naive-developer-how-to-avoid-basic-cybersecurity-mistakes) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Coffee with Developers - Maria Apazoglou - Making AI understandable for all in production](https://www.wearedevelopers.com/magazine/475-coffee-with-developers-maria-apazoglou-making-ai-understandable-for-all-in-production) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)