Chief Information Security Officer (CISO)
Summary
Hands-on CISO role building a security program from the ground up for AI-native products and autonomous agents, remote from the US or Canada. Covers cloud and zero-trust infrastructure (AWS/GCP/Azure), AI threat modeling and red teaming, SOC 2/ISO/FedRAMP readiness, and turning security tooling into products.
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Chief Information Security Officer (CISO) based in United States .
This is a hands-on, entrepreneurial security leadership role focused on securing AI-native products, operations, and client environments. You will define and build the security strategy across infrastructure, data, cloud, and autonomous AI systems from the ground up. The role sits at the intersection of cybersecurity, AI engineering, product development, governance, and client advisory. You will design practical safeguards for AI agents, lead adversarial testing, strengthen compliance readiness, and respond to emerging threats that traditional security playbooks may not fully address. You will also have the opportunity to turn security capabilities into products and influence how organizations approach responsible AI adoption. This is an environment for a technical builder and strategic leader who is comfortable operating with ambiguity and shaping solutions where the standards are still being defined.
Accountabilities:
- Define and execute the organization’s security strategy across internal infrastructure, data, cloud environments, AI systems, and client-facing solutions, establishing governance models that support secure and responsible deployment of autonomous agents.
- Build security into AI agent systems as a core product capability by designing guardrails, monitoring, policy enforcement, audit mechanisms, anomaly detection, and controls that keep autonomous systems operating within defined boundaries.
- Establish and evolve security governance and compliance programs aligned with frameworks such as SOC 2 and ISO, while supporting potential readiness for FedRAMP and other requirements as the organization expands into enterprise and government environments.
- Design and operate security infrastructure hands-on, including zero-trust architectures, identity and access management, secure multi-tenant environments, monitoring and detection capabilities, and secure data pipelines.
- Lead threat modeling, incident response, red team exercises, and adversarial testing across complex systems, with particular attention to emerging AI-specific threats such as prompt injection, model extraction, data poisoning, and adversarial manipulation of agent behavior.
- Identify emerging security challenges and develop practical frameworks, controls, and response mechanisms for risks associated with autonomous and agentic AI systems.
- Develop internal security tooling and identify opportunities to transform successful security capabilities into standalone products or commercially valuable solutions in collaboration with product and engineering teams.
- Partner closely with engineering, product, client, and leadership teams to embed security throughout the development and deployment lifecycle while balancing technical risk with commercial and operational priorities.
- Represent the security function in client conversations, partner discussions, and relevant industry forums, communicating complex AI-security concepts clearly to both technical and non-technical stakeholders.
- Contribute to thought leadership around AI security, risk, alignment, governance, and responsible deployment through presentations, publications, industry engagement, and knowledge sharing.
- Build institutional security knowledge by documenting frameworks, lessons learned, technical decisions, and operational practices, helping establish scalable security processes as the organization grows.
- Significant leadership experience as a CISO, VP of Security, Head of Security, or equivalent senior security leadership position within a high-growth technology environment, ideally involving AI systems deployed at scale.
- Deep hands-on experience securing artificial intelligence and machine learning systems, including LLM architectures, model training pipelines, inference infrastructure, and production AI applications.
- Strong experience building and operating cloud-native security programs across AWS, GCP, and/or Azure, including zero-trust architectures, identity and access management, and secure multi-tenant environments.
- Deep understanding of threat modeling, red teaming, adversarial testing, security monitoring, and incident response, ideally including AI-specific attack vectors such as prompt injection, model inversion, data poisoning, or manipulation of agent behavior.
- Proven ability to design and implement scalable security, compliance, and governance programs that evolve from startup environments through enterprise readiness.
- Demonstrated track record of building or contributing to security products, platforms, or tooling that were shipped to customers or adopted as infrastructure by other teams.
- Strong technical capability and willingness to remain hands-on, including the ability to write code, configure security systems, troubleshoot production environments, and work directly with engineering teams.
- Entrepreneurial mindset with the ability to view security as both a strategic advantage and a potential product opportunity rather than solely as a compliance function.
- Comfort operating in ambiguous environments and solving emerging security problems where established industry practices or standards may still be developing.
- Strong product and commercial judgment, with the ability to understand business implications, communicate technical trade-offs, and earn credibility with executives, engineers, and clients.
- Excellent communication and stakeholder management skills, with the ability to translate complex cybersecurity and AI-risk concepts into clear recommendations for technical and business audiences.
- Strong sense of ownership, integrity, curiosity, and commitment to responsible security practices, with the ability to teach others and build institutional knowledge.
- For Canadian applicants, the engagement is structured as an independent contractor arrangement; U.S. applicants are considered for full-time employment.
- Ability to work remotely from Canada or the United States, as applicable to the employment arrangement.
- Fully remote opportunity available to candidates in Canada and the United States.
- Opportunity to shape security strategy at the frontier of AI and autonomous agent technology rather than maintaining legacy security infrastructure.
- Significant autonomy and ownership over security architecture, governance, AI safeguards, product security, and operational programs.
- Hands-on exposure to emerging AI-security challenges and the opportunity to develop solutions for problems that are still being defined across the industry.
- Opportunity to influence the development of security products and potentially transform internally developed capabilities into commercial offerings.
- Close collaboration with engineering, product, strategy, and client-facing teams in a highly cross-functional environment.
- Opportunity to contribute to AI security thought leadership through client engagements, industry forums, publications, and other external initiatives.
- A culture that values initiative, constructive feedback, continuous learning, and strong technical execution.
- Meaningful opportunity to influence responsible AI adoption and help organizations deploy AI systems securely in high-stakes environments.
Requirements
Benefits
Skills
As published by lever
Resume/CV, Full name, Email, Phone, Current location, Current company