About the Role
We are seeking an experienced Chief Information Security Officer (CISO) to lead the company’s information security, cybersecurity, cloud security, governance, risk, compliance, and audit readiness functions. The company develops software products for financial services organisations, so the role requires a strong understanding of security expectations in regulated, audit-driven, enterprise customer environments.
The CISO will report to the Chief Information Officer (CIO) and will work closely with executive leadership, product engineering, cloud operations, customer-facing teams, legal, procurement, and external auditors to ensure security is embedded in how the organisation builds, operates, sells, and supports its products.
The ideal candidate is a commercially aware security leader who combines technical credibility, audit discipline, cloud expertise, and strong communication skills. They should be comfortable engaging with customers and auditors, challenging engineering teams constructively, and helping the organisation scale a security programme that supports growth in demanding financial services markets.
Responsibilities
- Define, maintain, and continuously improve the enterprise information security strategy, roadmap, policies, standards, and operating model.
- Own the security governance, risk, and compliance programme, including risk assessment, control design, issue tracking, executive reporting, and continuous improvement.
- Lead the company’s security certification and audit readiness agenda, including frameworks and customer expectations such as ISO/IEC 27001, SOC 2, where applicable, NIST-based controls, cloud security benchmarks, privacy and data protection requirements, and financial services customer due diligence.
- Manage external and internal security audits, including planning, evidence collection, control testing, remediation tracking, auditor engagement, and executive communication.
- Partner with sales, product, legal, and customer success teams to respond to security sections of RFPs, due diligence questionnaires, customer audits, security addenda, and contractual security commitments.
- Define and audit secure software development standards for cloud-based product delivery across OCI and AWS environments, including identity and access management, encryption, network security, logging and monitoring, vulnerability management, secrets management, change control, incident response, and secure configuration baselines.
- Establish and mature secure software development lifecycle practices, including threat modelling, secure coding standards, dependency and open-source risk management, application security testing, infrastructure-as-code review, CI/CD security controls, and release governance.
- Develop security as a culture across the organisation by building awareness, role-based training, security champions, practical guidance for engineering teams, and clear accountability for security outcomes.
- Lead incident response planning and readiness, including playbooks, tabletop exercises, breach response coordination, lessons learned, and communication with senior stakeholders.
- Provide clear, business-focused reporting to the CIO and executive leadership on security posture, key risks, audit status, customer security commitments, regulatory exposure, and investment priorities.
Experiences and Skills
- Significant senior-level information security, cybersecurity, governance, risk, compliance, or security leadership experience, ideally in a software product, SaaS, cloud, fintech, financial services technology, or enterprise B2B environment.
- Demonstrated experience leading audit and certification programmes, including preparation, execution, remediation, and ongoing operational control monitoring.
- Strong working knowledge of security frameworks and standards commonly required by financial services customers, including ISO/IEC 27001, SOC 2, NIST Cybersecurity Framework, CIS Controls, secure SDLC practices, and cloud security control frameworks.
- Experience governing cloud security principles in AWS, Azure, OCI or similar environments, including shared responsibility models, landing zones, IAM, network segmentation, encryption, logging, monitoring, vulnerability management, backup, resilience, and incident response.
- Experience supporting enterprise sales cycles by completing RFP responses, security questionnaires, customer due diligence, customer audit requests, and security contract reviews.
- Proven ability to translate technical security risk into practical business language for executives, customers, auditors, product leaders, and engineering teams.
- Experience developing policies, standards, procedures, metrics, dashboards, and evidence processes that are practical, auditable, and adopted by delivery teams.
- Track record of influencing engineering and operational teams without creating unnecessary friction, helping teams build secure products at pace.
Qualifications and Certifications
- Relevant degree or equivalent professional experience in information security, computer science, software engineering, cloud computing, risk management, or a related discipline.
- Professional certifications are strongly preferred, such as CISSP, CISM, CISA, CCSP, ISO/IEC 27001 Lead Implementer or Lead Auditor, AWS Security Specialty, OCI security-related certifications, or equivalent industry credentials.
- Evidence of continuing professional development and current knowledge of security, privacy, cloud, regulatory, and audit trends affecting software suppliers to financial services organisations.
Core Competencies
- Security strategy and executive risk management
- Audit, certification, and compliance programme leadership
- Cloud security architecture and control assurance across AWS and OCI
- Secure software development lifecycle governance
- Customer-facing security communication and RFP response leadership
- Policy, standards, control design, and evidence management
- Security culture, awareness, and engineering enablement
- Incident response, crisis management, and operational resilience
- Stakeholder management across executive, technical, customer, legal, and audit audiences
- Data protection regulation, such as GDPR, encryption and privacy engineering
Success Measures
- Security certifications, audits, and customer due diligence activities are delivered on time with clear ownership, reliable evidence, and effective remediation tracking.
- Cloud security standards for AWS and OCI are defined, adopted, measured, and regularly audited across product and platform teams.
- RFP and customer security responses are accurate, timely, consistent, and aligned with the company’s actual control posture.
- Security policies and standards are practical, understood, and embedded into engineering and operational workflows.
- The organisation demonstrates measurable improvement in security culture, risk visibility, incident readiness, vulnerability management, and audit confidence.
About MCO (MyComplianceOffice)
MCO is a global leader dedicated to empowering Financial Services firms to manage compliance programs with ease and efficiency.
Our mission is to foster a fair, transparent, and trusted financial environment worldwide by helping Organizations meet their regulatory obligations to society.
At the heart of MCO’s offering is our unique, unified platform, which seamlessly integrates compliance monitoring and data into a single, comprehensive view. This holistic approach enables firms to maintain compliance across all internal systems, structures, and processes ensuring peace of mind in an ever-evolving regulatory landscape.
Headquartered in Dublin, MCO has an international footprint, with offices in London, Singapore, Hyderabad, New York, Chicago, Fort Worth, Switzerland, South Africa, Slovenia, and the UAE.
Since our founding in 2008, we have evolved from a specialist provider of “best of breed” employee compliance solutions to a pioneer in integrated compliance technology.
Today, our team of over 400 professionals supports more than 1.5 million users in 128 countries. Our diverse customer base includes small businesses, large enterprises, four of the world’s top ten asset managers, twenty of the top seventy-five global banks, and three of the top five investment banks for global M&A transactions.