Chief Information Security Officer

The Security Executive Council

Austin (TX)

On-site

USD 250,000 - 500,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Health benefits
Equity compensation
Training and career growth
Flexible time off
Parental leave
Onsite snacks/meals

Job summary

Hippo is seeking a seasoned Chief Information Security Officer to steer cybersecurity strategy, security operations, and governance, risk, and compliance across the enterprise. This leader will own Hippo’s SOC 2 program, drive regulatory compliance for a multi-state, publicly traded insurance carrier, and report to the Board on cybersecurity posture and risk trends.

The role requires expert security engineering, regulatory acumen, and executive communication across Legal, Finance, and

Qualifications

  • 10+ years in cybersecurity or information security with at least 5 in senior leadership (CISO/VP/Head of InfoSec)
  • Experience at a regulated, publicly traded company with SOX involvement
  • Track record building and managing security operations
  • End-to-end ownership of a SOC 2 program including design, audit prep, remediation
  • Experience with cybersecurity regulations in regulated industries (financial services, insurance, healthcare)
  • Strong GRC background with risk registers, policy frameworks, controls libraries
  • Proven ability to present cybersecurity risk/incident info to boards/audit committees/regulators
  • Experience managing third-party and vendor cybersecurity risk programs
  • Excellent cross-functional leadership with Legal, Finance, Internal Audit, and Engineering

Responsibilities

  • Develop and execute Hippo’s enterprise cybersecurity strategy aligned with business risk and regulatory requirements
  • Lead security operations including threat detection, incident response, vulnerability management, and threat intel
  • Own SOC 2 program end-to-end from design to auditor engagement
  • Steer governance, risk, and compliance including risk register, policy framework, standards, and control library
  • Drive compliance with state and federal cybersecurity and insurance regulations
  • Support SEC cybersecurity disclosures with Legal and Finance
  • Lead identity governance and separation of duties enforcement
  • Oversee privacy and data protection compliance with Legal on data handling and breach notification
  • Manage third-party and vendor cybersecurity risk program
  • Report to the Board and Audit & Risk Committee on posture, trends, and incidents
  • Provide second-line input to the SOX ITGC program
  • Build and lead security engineering with secure design standards and threat modeling
  • Mentor cybersecurity team and foster security-aware culture
  • Lead budgeting, roadmap planning, and technology rationalization
  • Own disaster recovery and business continuity planning with CIO/CTO
  • Oversee Enterprise Incident Response Plan and Security Incident Response Team
  • Drive continuous improvement with remediation tracking for Audit & Risk Committee
  • Lead supply chain risk management across open-source and third-party providers

Skills

CISO leadership
SOC 2
SOX audit
GRC
Board reporting
Vendor risk management
Security operations
Security engineering
Regulatory compliance
Incident response

Job description

About the Job

Hippo was built on a promise: make homeownership effortless. Nearly a decade later, that mission still drives us. We use technology and data to help our customers stay ahead of problems and protect what matters most. Today, that same tech‑native approach powers our work beyond homeowners. Hippo operates as a diversified carrier platform, partnering with MGAs to deliver tailored program solutions that help them grow and deliver better customer experiences. Behind that work is a team that values ownership, curiosity, collaboration, and continuous improvement. If you’re energized by building what’s next, we’d love to meet you.

About the Role

Hippo is hiring a Chief Information Security Officer to lead cybersecurity strategy, security operations, and governance, risk, and compliance across the enterprise. This role owns Hippo’s SOC 2 program, leads security operations, and drives compliance with applicable state and federal cybersecurity regulations. You will be responsible for protecting Hippo’s systems, data, and customers against an evolving threat landscape while ensuring the company meets its regulatory and compliance obligations as a publicly traded, multi‑state insurance carrier. The position requires fluency in security engineering, regulatory compliance, and executive communication.

About You

You are a seasoned cybersecurity leader who has built and run security programs at a publicly traded, regulated company. You have navigated regulatory examinations and SOX audit cycles, can move seamlessly between a technical incident response scenario and a board presentation, and think in terms of risk. You bring a builder’s mindset to security, understand that a great security program enables the business, and know how to embed security into engineering culture. Whether your background is in Insurtech, fintech, healthcare, or another heavily regulated sector, you understand multi‑regulator environments and lead with clarity.

What You’ll Do
  • Further develop and execute Hippo’s enterprise cybersecurity strategy, aligned with business risk appetite and regulatory requirements
  • Build and lead the security operations function, including threat detection, incident response, vulnerability management, and threat intelligence
  • Own Hippo’s SOC 2 program end‑to‑end, including control design, evidence collection, readiness assessments, and auditor engagement
  • Lead the governance, risk, and compliance function, maintaining the cybersecurity risk register, policy framework, standards, and control library
  • Drive compliance with applicable state and federal cybersecurity and insurance regulations
  • Support SEC cybersecurity disclosure obligations in coordination with Legal and Finance
  • Lead identity governance, including access certification, privileged access management policy, and separation of duties enforcement
  • Own privacy and data protection compliance strategy, partnering with Legal on data handling, breach notification, and policyholder data protection
  • Manage the third‑party and vendor cybersecurity risk management program
  • Report to the Board of Directors and Audit and Risk Committee on cybersecurity posture, risk trends, and incident activity
  • Provide second‑line oversight and security control design input to the SOX ITGC program
  • Build and lead the security engineering function, owning secure design standards and threat modeling practices that ensure security is embedded from architecture through to deployment
  • Build, mentor, and develop the cybersecurity team and drive a culture of security awareness across the organization
  • Lead cybersecurity budgeting, roadmap planning, and technology rationalization
  • Own disaster recovery and business continuity planning across the enterprise, working closely with the CIO and CTO to drive regular testing, validate recovery capabilities, and ensure organizational resilience
  • Own the enterprise Incident Response Plan; lead the Security Incident Response Team (SIRT) across the full incident lifecycle, define severity classifications and escalation paths, and ensure cross‑functional stakeholders are engaged appropriately during active incidents
  • Drive a continuous improvement program with outcomes tracked to remediation and reported to the Audit and Risk Committee
  • Lead the enterprise response to supply chain vulnerabilities across open‑source dependencies and third‑party service providers, owning risk assessment, mitigation, and remediation
Qualifications

Must Haves:

  • 10+ years of progressive experience in cybersecurity or information security, with at least 5 years in a senior security leadership role (CISO, VP of Security, or Head of Information Security)
  • Experience at a regulated, publicly traded company, including direct involvement in SOX audit cycles
  • Track record of building and managing security operations capabilities
  • End‑to‑end ownership of a SOC 2 program, including control design, audit preparation, and remediation
  • Experience with cybersecurity regulations in a regulated industry (financial services, insurance, or healthcare preferred)
  • Strong GRC background with experience maintaining risk registers, policy frameworks, and control libraries
  • Proven ability to present cybersecurity risk and incident information to boards of directors, audit committees, and regulators
  • Experience managing third‑party and vendor cybersecurity risk programs
  • Excellent cross‑functional leadership skills with a track record of partnering effectively with Legal, Finance, Internal Audit, and Engineering

Nice to Have:

  • Experience in the insurance, Insurtech, or fintech industry
  • Familiarity with privacy frameworks and data protection requirements (CCPA/CPRA, state breach notification laws)
  • Relevant certifications such as CISSP, CISM, CRISC, or CISA
  • Background in security engineering or application security in addition to GRC and security operations
  • Experience managing cybersecurity programs across multi‑entity corporate structures
Compensation

Hippo treats its team members with the same level of dedication and care as we do our customers, which is why we’re fortunate to provide all of our Hippos with:

  • Healthy Hippos Benefits – multiple medical plans to choose from and 100% employer‑covered dental and vision plans for team members and their families; 401(k) retirement plan; short and long‑term disability; employer‑paid life insurance; Flexible Spending Accounts for health and dependent care; and an Employee Assistance Program
  • Equity – this position is eligible for equity compensation
  • Training and career growth – training and internal career growth opportunities
  • Flexible time off – you know when and how you should recharge
  • Little Hippos Program – we offer 12 weeks of parental leave for primary and secondary caregivers
  • Hippo Habitat – snacks and drinks available and catered lunches for onsite employees
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Chief Information Security Officer (CISO)
Chief Information Security Officer (CISO)

Hippo Insurance • Austin (TX)

On-site
USD 150,000 - 200,000
Multiple medical plans
100% employer covered dental & vision plans
401(k)-retirement plan
+8
Chief Information Security Officer (CISO)
Chief Information Security Officer (CISO)

Hippo Enterprises Inc. • Austin (TX)

Hybrid
USD 237,000 - 390,000
Multiple medical plans
401(k) retirement plan
Equity compensation
+3
Chief Information Security Officer (CISO)
Chief Information Security Officer (CISO)

Hippo Insurance • Morristown (NJ)

On-site
USD 237,000 - 390,000
Multiple medical plans
100% employer covered dental & vision plans
401(k)-retirement plan
+2
Sr. Operational Compliance Analyst
Sr. Operational Compliance Analyst

Hippo Insurance • United States

Hybrid
USD 175,000 - 265,000
Healthy Hippos Benefits
Equity compensation
Training and Career Growth
+3
Senior Innovation Manager
Senior Innovation Manager

Hippo Enterprises Inc. • Austin (TX)

On-site
USD 147,000 - 220,000
Healthy benefits
Equity
Training and growth
+3
People Business Partner (HRBP)
People Business Partner (HRBP)

Socket.dev • Austin (TX)

Hybrid
USD 110,000 - 160,000
Equity
Training and Career Growth
Flexible Time Off
+2
People Business Partner (HRBP)
People Business Partner (HRBP)

Hippo • Austin (TX)

On-site
USD 110,000 - 150,000
Healthy benefits package
Equity compensation
Training and career growth
+3
Senior Communications Manager
Senior Communications Manager

Hippo Insurance • United States

On-site
USD 150,000 - 200,000
Health benefits
Equity
Career growth
+3
Software Engineer
Software Engineer

Hippo Insurance • Austin (TX)

Hybrid
USD 110,000 - 150,000
Health & dental
Equity
Career growth
+3
Senior Product Manager, Insurance Products
Senior Product Manager, Insurance Products

Hippo Insurance • New Jersey

On-site
USD 124,000 - 186,000
Healthy benefits packages
Equity compensation
401(k) retirement plan
+3