Hippo

Hippo

Chief Information Security Officer (CISO)

Morristown, NJ / Austin, TX (hybrid) · Exec

Sponsorship not specifiedDetected 33 days ago
CybersecurityComplianceRoadmappingBudgetingSupply ChainLeadershipCollaboration

About the role

  • You will be responsible for protecting Hippo's systems, data, and customers against an evolving threat landscape while ensuring the company meets its regulatory and compliance obligations as a publicly traded, multi-state insurance carrier.
  • This is a high-visibility leadership role that requires equal fluency in security engineering, regulatory compliance, and executive communication.

Responsibilities

  • Further develop and execute Hippo's enterprise cybersecurity strategy, aligned with business risk appetite and regulatory requirements
  • Build and lead the security operations function, including threat detection, incident response, vulnerability management, and threat intelligence
  • Own Hippo's SOC 2 program end-to-end, including control design, evidence collection, readiness assessments, and auditor engagement
  • Lead the governance, risk, and compliance function, maintaining the cybersecurity risk register, policy framework, standards, and control library
  • Drive compliance with applicable state and federal cybersecurity and insurance regulations
  • Support SEC cybersecurity disclosure obligations in coordination with Legal and Finance
  • Lead identity governance, including access certification, privileged access management policy, and separation of duties enforcement
  • Own privacy and data protection compliance strategy, partnering with Legal on data handling, breach notification, and policyholder data protection
  • Manage the third-party and vendor cybersecurity risk management program
  • Provide second-line oversight and security control design input to the SOX ITGC program

Requirements

  • You are a seasoned cybersecurity leader who has built and run security programs at a publicly traded, regulated company.
  • You have navigated regulatory examinations and SOX audit cycles, and you can move seamlessly between a technical incident response scenario and a board presentation.
  • You think in terms of risk, you quantify what you can, and you communicate what you can't with intellectual honesty.
  • You understand that a great security program enables the business rather than slowing it down, and you know how to embed security into engineering culture without creating friction.
  • 10+ years of progressive experience in cybersecurity or information security, with at least 5 years in a senior secur

This listing is sourced directly from Hippo's careers page and normalized into a canonical job model.