> Markdown version of [/jobs/ext/506129-chief-information-security-officer](https://www.wearedevelopers.com/jobs/ext/506129-chief-information-security-officer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Chief Information Security Officer - **Company:** The Baker - **Location:** Carmel, IN, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Software as a Service, Control Objectives for Information and Related Technology (COBIT), Cyber Security, Continuous Integration, PCI Data Security Standards, Systems Development Life Cycle, Phishing, Systems Architecture, Information Security Management System, Information Technology - **Published:** June 11, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=a56347d0bcce1b3c ## About the Role Do you have experience in Team leadership?, Do you have a Bachelor's degree?, * Strong knowledge of compliance regimes including ISO 27001, SOC 2 Type II, and PCI-DSS. * Experience with privacy regimes including GDPR and state laws like CCPA. * Familiarity with state security regulations such as NYDFS. * Ability to navigate and monitor governance published by OCC, Treasury Department, FFIEC, FDIC, and NCUA. * Understanding of SDLC and CI/CD, with the ability to integrate security processes within them * Strong knowledge of SaaS and Fintech industry security requirements. * Proven experience in developing and implementing security policies and procedures. * Excellent understanding of current legislation and regulations relevant to information security and data privacy., * Bachelor's degree in computer science, Information Technology, or a related field required; master's degree preferred. * Minimum of 10 years of experience in information security, with at least 5 years in a leadership role. * At least 5 years of experience leading a security business function. * Strong knowledge of SaaS and Fintech industry security requirements. * Proven experience in developing and implementing security policies and procedures. * Excellent understanding of current legislation and regulations relevant to information security and data privacy. * Certifications such as CISSP, CISM, or CISA are highly desirable. * Strong leadership, communication, and interpersonal skills. * Ability to work effectively in a fast-paced, rapidly changing environment. * Leading SAFe Agilist (SA) certification required to understand SAFe principles, building an agile mindset, and leading Agile transformation; or the ability to obtain within the first 90 days of employment STANDARD REQUIREMENTS Use AI responsibly and in alignment with policy, including ongoing learning, and incorporate AI into routine tasks such as drafting communications, summarizing meetings, and organizing information. This position requires regular onsite work at our Carmel, Indiana office. Candidates must be able to commute to and work from this location as part of their role. ## Description Job Summary: The Chief Information Security Officer (CISO) will be responsible for establishing and maintaining the enterprise vision, strategy, and program to ensure information assets and technologies are adequately protected. The CISO will work closely with the COO / CTO and other members of the IT and Product Development leadership to align security initiatives with business objectives and ensure compliance with regulatory requirements., * Develop, implement, and monitor a strategic, comprehensive enterprise information security and IT risk management program. * Lead the development and implementation of a robust cybersecurity strategy to protect the company's information assets. * Manage the Information Security Management System (ISMS) and Artificial Intelligence Management System (AIMS). * Lead monthly Information Security and AI Governance meetings. * Assess and manage security risks from vendors, partners and sub processors. * Conduct annual business continuity and disaster recovery exercises/simulations. * Orchestrate phishing simulations and education. * Author, maintain and prepare policy documents for external auditors and client due diligence. * Ensure compliance with relevant regulations and standards, including SOC 2 Type II control objectives and PCI-DSS. * Conduct regular security assessments and audits to identify vulnerabilities and mitigate risks. * Lead audits and assessments to ensure ongoing compliance and security improvements. * Oversee incident response planning and the investigation of security and operational incidents. * Collaborate with the IT department to ensure security is integrated into all system architecture and processes. * Provide leadership and guidance to employees, fostering a culture of security awareness across the organization. * Develop and deliver security training programs for employees. * Stay current with the latest cybersecurity trends, threats, and technology solutions. * Responding to client and prospect inquiries regarding assurance and security programs. ## Related Videos - [Passkeys: Truly Phishing-Resistant? Implementation and Pitfalls](https://www.wearedevelopers.com/videos/100156-passkeys-truly-phishing-resistant-implementation-and-pitfalls) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [The QUEST for Better Software](https://www.wearedevelopers.com/videos/721-the-quest-for-better-software) - [How to govern Vibe Coding for the Enterprise](https://www.wearedevelopers.com/videos/100290-how-to-govern-vibe-coding-for-the-enterprise) - [Skynet wants your Passwords! The Role of AI in Automating Social Engineering](https://www.wearedevelopers.com/videos/770-skynet-wants-your-passwords-the-role-of-ai-in-automating-social-engineering) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) ## Related Articles - [Navigating the AI Shift](https://www.wearedevelopers.com/magazine/629-navigating-the-ai-shift) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Now is the time for industrialized software development](https://www.wearedevelopers.com/magazine/601-now-is-the-time-for-industrialized-software-development) - [Stephan Gillich - Bringing AI Everywhere](https://www.wearedevelopers.com/magazine/489-stephan-gillich-bringing-ai-everywhere) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing)