Hippo
Chief Information Security Officer (CISO)
Austin, TX / Morristown, NJ (hybrid) · Exec
Sponsorship not specifiedDetected 33 days ago
CybersecurityComplianceRoadmappingBudgetingSupply ChainLeadershipCollaboration
About the role
- You will be responsible for protecting Hippo's systems, data, and customers against an evolving threat landscape while ensuring the company meets its regulatory and compliance obligations as a publicly traded, multi-state insurance carrier.
- This is a high-visibility leadership role that requires equal fluency in security engineering, regulatory compliance, and executive communication.
Responsibilities
- Further develop and execute Hippo's enterprise cybersecurity strategy, aligned with business risk appetite and regulatory requirements
- Build and lead the security operations function, including threat detection, incident response, vulnerability management, and threat intelligence
- Own Hippo's SOC 2 program end-to-end, including control design, evidence collection, readiness assessments, and auditor engagement
- Lead the governance, risk, and compliance function, maintaining the cybersecurity risk register, policy framework, standards, and control library
- Drive compliance with applicable state and federal cybersecurity and insurance regulations
- Support SEC cybersecurity disclosure obligations in coordination with Legal and Finance
- Lead identity governance, including access certification, privileged access management policy, and separation of duties enforcement
- Own privacy and data protection compliance strategy, partnering with Legal on data handling, breach notification, and policyholder data protection
- Manage the third-party and vendor cybersecurity risk management program
- Provide second-line oversight and security control design input to the SOX ITGC program
Requirements
- You are a seasoned cybersecurity leader who has built and run security programs at a publicly traded, regulated company.
- You have navigated regulatory examinations and SOX audit cycles, and you can move seamlessly between a technical incident response scenario and a board presentation.
- You think in terms of risk, you quantify what you can, and you communicate what you can't with intellectual honesty.
- You understand that a great security program enables the business rather than slowing it down, and you know how to embed security into engineering culture without creating friction.
- 10+ years of progressive experience in cybersecurity or information security, with at least 5 years in a senior secu
This listing is sourced directly from Hippo's careers page and normalized into a canonical job model.