- Company Name
- Candescent
- Job Title
- Chief Information Security Officer (CISO)
- Job Description
-
Job Title: Chief Information Security Officer (CISO)
Role Summary: Executive responsible for shaping and executing enterprise‑wide security, compliance, and risk management strategy for a cloud‑based digital banking platform, ensuring alignment with FFIEC, SOC 2, ISO 27001, PCI‑DSS, GDPR, and related regulations while embedding security into product, AI, and API architectures.
Expectations: Lead the Security & Compliance function, partner with Product, Engineering, Legal, Risk, and Customer teams to deliver secure, trustworthy solutions; oversee incident response, third‑party risk, and AI governance; report to board and regulatory bodies; maintain audit readiness and continuous improvement.
Key Responsibilities
- Define and implement security strategy and governance aligned to FFIEC, GLBA, NIST CSF, SOC 2, ISO 27001, PCI‑DSS, and GDPR.
- Manage regulatory relationships, audit readiness, and board‑level reporting.
- Drive secure SDLC practices: SAST/DAST, dependency scanning, threat modeling.
- Lead API security program: authentication, authorization, token management, rate limiting, payload inspection, anomaly detection.
- Oversee penetration testing, bug bounty, and API/data‑layer resilience.
- Embed fraud detection and identity protection (device fingerprinting, behavioral analytics, AI anomaly detection) into platform and product designs.
- Define AI security and compliance frameworks; secure AI pipelines, guard against prompt injection, model inversion, data leakage.
- Manage cloud and infrastructure security: IAM, encryption, KMS, Zero Trust Architecture, incident response, business continuity.
- Govern fintech ecosystem and third‑party risk; lead Vendor Risk Management and assurance program.
- Communicate security posture to customers, auditors, and regulators.
Required Skills
- Executive leadership and strategic vision in information security.
- Deep expertise in API security, cloud security (AWS, GCP), and secure SDLC.
- Proven experience with regulatory compliance (FFIEC, GLBA, PCI‑DSS, SOC 2, ISO 27001, GDPR).
- Knowledge of identity and fraud detection technologies; AI/ML security.
- Strong understanding of risk management, incident response, business continuity, and Zero Trust.
- Excellent stakeholder communication, board‑level reporting, and regulatory liaison.
- Vendor and third‑party risk management.
Required Education & Certifications
- Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or related field.
- Certificatory credentials: CISSP, CISM, CISA, or equivalent; additional certifications in cloud security (CCSP, AWS Certified Security – Specialty, GCP Professional Cloud Security Engineer) and compliance (PCI‑DSS, ISO 27001 Lead Implementer) preferred.