FloatMe

FloatMe

Chief Information Security Officer (CISO)

San Antonio, TX or Jacksonville, FL · Exec

Sponsorship not specifiedDetected 28 days ago
GoFlutterAWSCloud PlatformsRESTCybersecurityPenetration TestingSIEMIncident ResponseComplianceFirewallLeadershipCommunicationPublic SpeakingPlain LanguageCISSP

About the role

  • The ideal candidate should be very hands-on, not just a "policy manager".
  • We need someone who can sit in a compliance review one hour and be configuring security tooling themselves the next.
  • This role reports to our SVP, Engineering.

Responsibilities

  • Steer the architecture of our Cloud, Device, Code, App, AI, and Network infrastructure with a mind for security-first designs and plans.
  • Set the direction for a small number of our staff regarding our infrastructure design, security, integrations and partnerships, and more (IT, Data, and Security).
  • Serve as the primary security point of contact for our bank and fintech partners, completing security questionnaires, third-party risk assessments, and due diligence requests.
  • Own our SOC 2 Type II program end-to-end, including scoping, control design, evidence collection, and auditor management.
  • Maintain and strengthen our compliance posture across GLBA, PCI DSS, and other applicable financial services regulatory frameworks.
  • Manage and improve our core security infrastructure: SIEM, EDR, WAF, IAM, secrets management, and vulnerability scanning tools.
  • Conduct or manage regular penetration testing and vulnerability assessments, and drive remediation to closure.
  • Lead incident response efforts - including hands-on triage, containment, forensics, post-incident review, and breach notification processes.
  • Build and run security awareness training and phishing simulations across the company.
  • Review and negotiate security requirements in partner and vendor contracts.

Requirements

  • Practical knowledge of GLBA, PCI DSS, and other financial services compliance requirements.
  • Hands-on experience with penetration testing methodologies or managing third-party pen test engagements.
  • Strong working knowledge of SIEM, EDR, vulnerability management, and secrets management tooling.
  • Excellent written and verbal communication skills - you can explain technical risk to non-technical stakeholders.

Nice to have

  • 10+ years' of progressive experience in information security, with at least 2 years in a senior IC or leadership role.
  • Prior leadership experience in a role adjacent to "Head of Infrastructure and Security" preferred.
  • The key here is that you can both be the thinker and leader we need, but also still feel very comfortable being hands-on.
  • Proficiency with cloud security (AWS and Cloudflare preferred), including IAM, VPCs, CloudTrail, GuardDuty, or equivalents.
  • Experience in fintech, neobank, lending, or another consumer financial services environment strongly preferred.
  • CISSP, CISM, CISA, or equivalent certification are a plus.

This listing is sourced directly from FloatMe's careers page and normalized into a canonical job model.