Chief Information Security Officer (CISO)

Obsidian Security

Palo Alto (CA)

On-site

USD 300,000 - 380,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Equity & 401k
Healthcare benefits
PTO & holidays
Parental leave

Job summary

Obsidian Security is seeking a Chief Information Security Officer (CISO) to own the internal security program end-to-end and lead a world-class security organization.

You will report to the Chief Legal and Trust Officer and partner with Engineering, Product, and Sales to embed security across the SDLC, drive AI security governance, and protect customer trust while guiding security strategy and budget decisions.

Qualifications

  • 15+ years in information security
  • 5+ years in a senior leadership role (CISO, VP/Deputy CISO, Sr. Director of Security, or equivalent)
  • Deep experience building and scaling security teams across product security, security architecture, infrastructure protection, and enterprise risk management
  • Experience developing AI governance frameworks and familiarity with AI/ML attack surfaces
  • Experience operating as a customer-facing security executive
  • Demonstrated success improving security program maturity using NIST CSF, ISO 27001, or similar frameworks
  • Proven ability to present to boards, advise executive leadership, and communicate security posture to customers in support of revenue goals
  • Effective cross-functional partner with legal, compliance, and IT leadership in a matrixed environment
  • Experience managing significant security budgets
  • Master's degree in Information Security, Computer Science, or a related field preferred
  • Executive leadership education is a plus

Responsibilities

  • Own Obsidian's internal security program end-to-end and serve as a visible security leader to customers, partners, and the broader market
  • Design and execute a global security strategy aligned with business growth objectives
  • Oversee security architecture, engineering, operations, and threat detection with SLA-based performance tracking
  • Embed secure-by-design principles across the SDLC, including secure coding standards and AI/ML security requirements
  • Establish enterprise AI governance and detect/respond to AI-powered attack vectors
  • Partner with Engineering, Product, Sales, and Marketing to embed security throughout development and go-to-market
  • Represent Obsidian in industry forums to build market credibility and trust
  • Recruit, mentor, and retain a high-performing security organization and manage the security budget
  • Assess security posture for potential acquisitions during M&A due diligence

Skills

15+ years in information security
5+ years in senior leadership
Security leadership
Cloud-native SaaS security
AI governance
Executive communication
Board-level advisory
Cross-functional partnering
Security budgeting
M&A due diligence
Security program maturity
Security architecture

Education

Master's degree in Information Security or related field

Job description

Chief Information Security Officer (CISO)

Obsidian Security is the leading SaaS security platform, trusted by global enterprises like Snowflake, T-Mobile, and Algolia. We protect 200+ organizations across North America, Europe, the Middle East, Southeast Asia, Australia, and New Zealand, including many of the world's largest Fortune 1000 and Global 2000 companies.

Founded in 2017 and backed by top investors like Greylock, Obsidian was built to close a critical gap: securing SaaS apps where business happens—Microsoft 365, Salesforce, and hundreds more. The company does this by offering a complete SaaS security platform to reduce risk, detect and respond to threats, and prevent breaches at the source. Obsidian was built by leaders who redefined endpoint and identity security at CrowdStrike, Okta, Cylance, and Carbon Black. Now, they're transforming how SaaS is secured.

With global momentum, a growing partner ecosystem including SentinelOne, Databricks, and Google Cloud, and a major fundraise ahead, Obsidian is scaling rapidly toward long-term growth and IPO readiness.

The Role

The CISO will own Obsidian's internal security program end-to-end while serving as a visible security leader to our customers, partners, and the broader market. This role reports to the Chief Legal and Trust Officer.

Responsibilities
  • Security Strategy & Executive Communication: Design and execute a global security strategy aligned with business growth objectives. Advise the board and executive leadership on critical cyber risk domains with clear, actionable mitigation plans.
  • Cyber Risk Management: Own the cyber risk management program, including security risk assessments, third-party vendor reviews, and executive-backed mitigation initiatives targeting measurable risk reduction.
  • Security Architecture, Engineering & Operations: Build and lead teams spanning product/application security, infrastructure protection, and security engineering. Oversee threat detection, vulnerability management (with SLA-based performance tracking), and incident response. Establish a guardrail-based controls model for cloud and container workloads.
  • Product Security: Embed secure-by-design principles across engineering workflows, integrating security early and consistently throughout the SDLC, including secure coding standards, penetration testing, bug bounty programs, and security requirements for AI/ML components (model integrity, training data protection, prompt injection prevention, output validation).
  • AI Security & Governance: Establish enterprise AI governance (acceptable use, data loss prevention for AI inputs, vendor risk assessments for third-party AI services). Build detection and response capabilities for AI-powered attack vectors. Drive adoption of AI and automation across the security function, including AI-assisted threat detection, automated incident response, and intelligent vulnerability prioritization.
  • Cross-Functional Partnerships: Partner with Engineering and Product to embed security throughout the development lifecycle, AI/ML feature delivery, and infrastructure architecture decisions. Support Sales and TAM teams by participating in customer security reviews, responding to questionnaires, and enabling the team to speak confidently about Obsidian's security posture. Collaborate with Marketing to develop security-focused content, support thought leadership positioning and inform messaging around trust and security.
  • Customer Trust & External Presence: Serve as the executive-level security contact for prospects and customers during sales cycles, audits, and security reviews. Represent Obsidian in industry forums and public engagements to build market credibility.
  • Team Leadership & Budget: Recruit, mentor, and retain a high-performing security organization. Own the security budget with precise, on-target forecasts.
  • M&A Due Diligence: Assess the security posture, risk exposure, and integration readiness of prospective acquisition targets.
Qualifications
  • 15+ years in information security, with 5+ years in a senior leadership role (CISO, VP/Deputy CISO, Sr. Director of Security, or equivalent).
  • Deep experience building and scaling security teams across product security, security architecture, infrastructure protection, and enterprise risk management.
  • Strong track record securing cloud-native SaaS environments, including container-based workloads and next-generation security tooling (endpoint protection, CI/CD-integrated code scanning, identity-as-a-service, automated monitoring/remediation).
  • Experience developing AI governance frameworks and familiarity with AI/ML attack surfaces (model poisoning, prompt injection, training data extraction, adversarial inputs, ML supply chain risks).
  • Experience operating as a customer-facing security executive, including direct participation in sales cycles, regulated entity security reviews, and audits.
  • Demonstrated success improving security program maturity using NIST CSF, ISO 27001, or similar frameworks, with measurable results.
  • Proven ability to present to boards, advise executive leadership, and communicate security posture to customers in support of revenue goals.
  • Effective cross-functional partner with legal, compliance, and IT leadership in a matrixed environment.
  • Experience managing significant security budgets.
  • Master's degree in Information Security, Computer Science, or a related field preferred. Executive leadership education is a plus.
Preferred
  • Experience at a cybersecurity vendor, where the CISO role carries both internal and external credibility demands.
  • Background in critical infrastructure security (energy, utilities, telecommunications) in addition to SaaS/technology.
  • Hands-on experience deploying AI/ML within security operations (SOAR, AI-assisted threat hunting, automated triage) and familiarity with AI security frameworks (OWASP Top 10 for LLMs, NIST AI RMF, MITRE ATLAS).
  • Experience securing AI features within a commercial SaaS product, including red-teaming or adversarial testing of AI/ML systems.
  • Track record conducting security due diligence for M&A transactions.
  • Experience engaging government stakeholders or congressional committees on security matters.

Employee Benefits

Our competitive benefits packages are designed to support our employees' well-being, both at work and at home. Our US based employees enjoy:

  • Competitive compensation with equity and 401k
  • Comprehensive healthcare with dental and vision coverage
  • Flexible paid time off and paid holiday time off
  • 12 weeks of new parent or family leave
  • Personal and professional development resources

For more details on our US benefits, or for information on our international benefits, please see here .

Pay Transparancy

Please note that the base pay range is a guideline and for candidates who receive an offer, the base pay will vary based on factors such as work location, as well as the knowledge, skills and experience of the candidate. In addition to a competitive base salary, this position is eligible for equity awards and may be eligible for sales commission or incentive compensation based on the role or function within the company.

At Obsidian, we are proud to be an equal-opportunity employer. We value diversity and hire for talent, passion, and compassion. In compliance with federal law, all persons hired will be required to submit satisfactory proof of identity and legal authorization. If you have a need that requires accommodation, please contact accommodations@obsidiansecurity.com

Information collected and processed as part of any job applications you choose to submit is subject to Obsidian's Applicant Privacy Policy .

Base Salary Range

$300,000 - $380,000 USD

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Chief Information Security Officer (CISO)
Chief Information Security Officer (CISO)

Obsidian-Security • Palo Alto (CA)

On-site
USD 300,000 - 380,000
Equity & 401k
Healthcare (medical, dental, vision)
Paid time off
+2
Staff Software Engineer
Staff Software Engineer

Menlo Ventures • Philadelphia

On-site
USD 223,000 - 239,000
Equity awards
401k
Healthcare (medical, dental, vision)
+1
Tech Lead - Data Scientist
Tech Lead - Data Scientist

Menlo Ventures • Newport Beach (CA)

On-site
USD 220,000 - 250,000
Competitive compensation with equity
Comprehensive healthcare with dental and vision coverage
Flexible paid time off
+2
Tech Lead - Data Scientist
Tech Lead - Data Scientist

Obsidian Security • Newport Beach (CA)

On-site
USD 220,000 - 250,000
Competitive compensation with equity
Comprehensive healthcare
Flexible paid time off
+2
Head of Customer Support
Head of Customer Support

DaParrot Ltd • Northern (KY)

Hybrid
USD 165,000 - 199,000
Equity and 401k
Healthcare including dental/vision
Flexible PTO and holidays
+2
Senior Support Engineer
Senior Support Engineer

Menlo Ventures • United States

Hybrid
USD 100,000 - 130,000
Equity
401k
Healthcare
+3
Senior DevOps Engineer
Senior DevOps Engineer

Obsidian Security • Palo Alto (CA)

On-site
USD 150,000 - 209,000
Competitive compensation with equity
Comprehensive healthcare
Flexible paid time off
+2
Software Engineer - AI Security Product
Software Engineer - AI Security Product

Menlo Ventures • Palo Alto (CA)

On-site
USD 155,000 - 180,000
Competitive compensation with equity
Comprehensive healthcare with dental and vision coverage
Flexible paid time off
+2
Sr Technical Marketing Manager - Alliances & Competitive Strategy
Sr Technical Marketing Manager - Alliances & Competitive Strategy

DaParrot Ltd • Northern (KY)

Hybrid
USD 195,000 - 212,000
Equity + 401k
Healthcare + dental + vision
Flexible PTO
+1
Head of Customer Support
Head of Customer Support

Menlo Ventures • United States

On-site
USD 165,000 - 199,000
Competitive compensation
Comprehensive healthcare
Flexible paid time off
+2