CISO: AI Security & Enterprise Risk Leader

Qualer, Now a MasterControl Company

Salt Lake City (UT)

On-site

USD 210,000 - 320,000

Full time

40 hours ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Competitive compensation
401(k) plan with company match
Generous PTO packages
Schedule flexibility
Dental/vision plans
Employer-paid life insurance policy

Job summary

MasterControl, Inc. is seeking a Chief Information Security Officer to own our enterprise security strategy, risk program, and AI governance across engineering. You will lead data privacy, security governance, and incident response, partnering with Sales, Compliance, and Legal as needed.

This senior role emphasizes risk assessment, governance, and secure development practices across cloud infrastructure and applications, with direct engagement in executive discussions about security investments.

Qualifications

  • 8-10 years in security leadership, with direct experience owning risk assessment programs (enterprise, product, and/or third‑party risk).
  • Hands‑on experience securing cloud environments on AWS and/or Azure.
  • Experience governing the security of AI/LLM usage — data boundaries, guardrails against prompt injection and data leakage, and secure use of AI in engineering workflows.
  • Deep working knowledge of at least one major compliance framework (FedRAMP, SOC 2, ISO 27001, or similar).
  • Experience with data privacy and cross‑regional compliance requirements (e.g., GDPR) for organizations operating infrastructure in multiple regions.

Responsibilities

  • Define and execute the company's enterprise security strategy, aligned with business objectives and compliance obligations (including FedRAMP).
  • Own security governance, policies, standards, and risk management practices across the organization.
  • Embed security‑by‑design principles across systems, applications, cloud infrastructure, and engineering workflows.
  • Set policy for access control, data protection, and secure development practices, partnering with Engineering to embed requirements into the SDLC without becoming a bottleneck.
  • Own data privacy and residency requirements across the regions where we operate infrastructure, including GDPR and other applicable cross‑regional obligations.
  • Own the security and governance model for how AI and LLM tooling are used across engineering — controlling what data can reach which models and keeping regulated data inside trusted boundaries.
  • Implement guardrails for AI and agentic workflows to catch data leakage, prompt injection, and unsafe outputs before they reach production or customers.
  • Partner with Engineering leadership to make security a built‑in part of our AI‑driven SDLC tooling, not a gate bolted on afterward.
  • Evaluate and, where appropriate, pursue recognized AI governance frameworks (e.g., ISO 42001) to give customers confidence in how we govern AI use.
  • Help turn our AI security posture into a competitive advantage in customer conversations, in partnership with Sales and Compliance.
  • Own the enterprise risk assessment program: identify, quantify, and track risk across infrastructure, applications, vendors, and third parties.
  • Run and continuously improve a formal risk register with clear ownership, remediation timelines, and executive reporting.
  • Lead risk assessments for cloud infrastructure and key third‑party dependencies (e.g., AWS, Azure), and for new products, features, or architecture changes before launch.
  • Translate technical risk into business terms for executive reporting.
  • Support Sales and Customer Success in customer security conversations, questionnaires, and due diligence reviews — working closely with the Compliance team, who own the customer relationship.
  • Maintain and mature our compliance posture (e.g., FedRAMP, SOC 2, ISO 27001 as applicable) in partnership with Compliance/Validation.
  • Contribute to customer‑facing security collateral (architecture summaries, trust documentation) that scales beyond 1:1 conversations.
  • Be available for direct customer engagement when a deal or renewal requires executive‑level security assurance.
  • Own the cybersecurity incident response program: detection, escalation, communication, and remediation.
  • Lead cross‑functional incident response involving Legal, Engineering, and executive leadership as needed.
  • Ensure continuous monitoring, threat intelligence integration, penetration testing, and vulnerability management.
  • Mature our detection and response capability (SIEM, monitoring, managed detection/response) to steadily reduce mean‑time‑to‑detect.
  • Drive post‑incident reviews and continuous improvement.
  • Build, lead, and develop the security team (or oversee the security function, depending on current staffing).
  • Represent security at the executive/leadership table; advise the CEO/CTO on risk posture and security investment priorities.
  • Set and manage the security budget and tooling stack.

Skills

Security leadership
Cloud security (AWS/Azure)
AI governance
Security frameworks (FedRAMP, SOC 2, 1

Job description

MasterControl, Inc. is seeking a Chief Information Security Officer to own our enterprise security strategy, risk program, and AI governance across engineering. You will lead data privacy, security governance, and incident response, partnering with Sales, Compliance, and Legal as needed.

This senior role emphasizes risk assessment, governance, and secure development practices across cloud infrastructure and applications, with direct engagement in executive discussions about security investments.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

CISO: AI Security & Enterprise Risk Leader
CISO: AI Security & Enterprise Risk Leader

Qualer, Now a MasterControl Company • Utah

On-site
USD 220,000 - 280,000
Competitive compensation
100% medical premium coverage
401(k) plan with company match
+5
CISO — AI Security & Enterprise Risk Leader
CISO — AI Security & Enterprise Risk Leader

Obsidian Security • Palo Alto (CA)

On-site
USD 300,000 - 380,000
Equity & 401k
Healthcare benefits
PTO & holidays
+1
CISO: Autonomous AI Security & Enterprise Trust
CISO: Autonomous AI Security & Enterprise Trust

Lineation AI • Carlsbad (CA)

Hybrid
USD 235,000 - 275,000
Chief Information Security Officer
Chief Information Security Officer

Glocomms • Charlotte (NC)

On-site
USD 150,000 - 200,000
CISO, Enterprise Security, Compliance & AI Governance
CISO, Enterprise Security, Compliance & AI Governance

Spring Health • New York (NY), San Francisco (CA)

Hybrid
USD 299,000 - 344,000
Health benefits
401(k) match
Professional development reimbursement
+1
Global CISO: AI-Driven Cyber Defense & Cloud Security
Global CISO: AI-Driven Cyber Defense & Cloud Security

The Security Executive Council • New York (NY)

On-site
USD 350,000 - 400,000
CISO - AI Risk & Security Strategy Leader
CISO - AI Risk & Security Strategy Leader

METR • Berkeley (CA), Northern (KY)

Hybrid
USD 493,000 - 579,000
Catered meals
In-office gym
Shower facilities
+9
Deputy CISO: AI & Data Security Leader
Deputy CISO: AI & Data Security Leader

Socure • San Francisco (CA), Northern (KY)

Hybrid
USD 250,000 - 450,000
Chief Technology & Security Officer | AI Governance Leader
Chief Technology & Security Officer | AI Governance Leader

Preferred Mutual Insurance Company • New York (NY)

On-site
USD 170,000 - 230,000
Short-term disability
Long-term disability
Life insurance
+12
Board-Ready CISO & Strategic Cyber Resilience Leader
Board-Ready CISO & Strategic Cyber Resilience Leader

Motion • Birmingham (AL), Northern (KY)

Hybrid
USD 250,000 - 350,000