[![Image]() Meet Jobicy Copilot — free AI autofill for job applications + remote job alerts ›](#)   [All remote jobs](https://jobicy.com/jobs.md)Open role[![UpGuard logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/474a12c7-221.png)](https://jobicy.com/company/upguard.md)Remote opportunity at[UpGuard](https://jobicy.com/company/upguard.md)

# Chief Information Security Officer

Review the role, location requirements, compensation details, and application process before deciding whether this opportunity fits your next career move.

[Apply for this job](#job-application)[View company](https://jobicy.com/company/upguard.md)Share14 Sep 2026Published34Listing views0Application actions14 Oct 2026Apply before  Opportunity details

## About this role.

AI SummaryUpGuard is seeking a hands-on Chief Information Security Officer to own enterprise security, infrastructure, identity, cloud, end-user computing, networking, and workplace security under one accountable executive. The role leads IT and Security Operations, Cloud Platform Engineering, and GRC while maturing security operations for both enterprise and product environments. Key technical priorities include GCP, Google SecOps, n8n-based automation, IAM, zero-trust access, macOS/ChromeOS fleet management, and cloud perimeter controls. The CISO will also own compliance and enterprise risk activities, including SOC 2 and ISO 27001, and serve as "customer zero" for UpGuard's CRPM platform. This is a high-autonomy, remote-first scale-up role reporting directly to the CEO and requiring board-level communication.

## Role DNA

A quick view of the complexity, pace, ownership and collaboration implied by the job description.

### Job Complexity

5/5EasyHard

### Pace & Pressure

5/5RelaxedFast-paced

### Autonomy Level

5/5GuidedFull ownership

### Communication Load

5/5IndependentCollaborative

AI insightThis is an unusually broad CISO remit that combines executive accountability with hands-on architecture and operational leadership across security, infrastructure, identity, compliance, and workplace technology. The successful candidate must scale outcomes through automation and a lean team while operating effectively with executives, boards, auditors, customers, and product stakeholders.

## Salary analysis

Estimated compensation compared with the broader US market for similar roles.

Estimated job medianMarket rate$350,000US market range$275k–$450k0$495k

AI insightNo actual salary was disclosed; the figures are estimated US-market annual base-salary benchmarks in USD for a hands-on CISO at a growth-stage cybersecurity company. Actual compensation may vary substantially based on geography, equity, bonus structure, company stage, and scope of infrastructure ownership.

## Core skills

Skills and capabilities most closely associated with this opportunity.

[Information Security Leadership](https://jobicy.com/jobs?search_keywords=Information%20Security%20Leadership.md)[Cloud Security](https://jobicy.com/jobs?search_keywords=Cloud%20Security.md)[GCP](https://jobicy.com/jobs?search_keywords=GCP.md)[Security Operations](https://jobicy.com/jobs?search_keywords=Security%20Operations.md)[Identity and Access Management](https://jobicy.com/jobs?search_keywords=Identity%20and%20Access%20Management.md)[Zero Trust](https://jobicy.com/jobs?search_keywords=Zero%20Trust.md)[Incident Response](https://jobicy.com/jobs?search_keywords=Incident%20Response.md)[SOC 2](https://jobicy.com/jobs?search_keywords=SOC%202.md)[ISO 27001](https://jobicy.com/jobs?search_keywords=ISO%2027001.md)[GRC](https://jobicy.com/jobs?search_keywords=GRC.md)

Sample interview questionsHow would you mature security operations for both enterprise and product systems without significantly increasing headcount?I would begin with a risk-based assessment of telemetry, detection coverage, incident workflows, and ownership across both environments. I would prioritize high-fidelity use cases in Google SecOps, automate enrichment and response through n8n, define measurable service objectives, and continuously tune detections based on incident outcomes. The objective is to use automation for repeatable work while reserving expert time for architecture, investigations, and risk reduction.

Describe how you would approach identity governance across a global SaaS and GCP estate.

I would establish identity as the primary control plane, with a clear source of truth for workforce identity, role-based access, strong lifecycle controls for joiners, movers, and leavers, and regular entitlement reviews. For GCP, I would enforce least privilege through group-based access, privileged-access workflows, service-account governance, and continuous monitoring of OAuth consent and anomalous activity. I would measure success through reduced standing privilege, timely deprovisioning, and auditable access decisions.

What would your first 90 days look like in this role?

In the first 30 days, I would complete the transition, map critical services and risks, meet key leaders, and validate incident, identity, cloud, and compliance baselines. By 60 days, I would publish a prioritized operating roadmap covering security operations, GCP and network controls, IAM, endpoint management, and audit commitments. By 90 days, I would align the team around measurable outcomes, initiate the highest-impact automation and risk-reduction work, and provide the CEO and board with a clear risk posture and investment plan.

How have you owned compliance programs such as SOC 2 or ISO 27001 beyond policy authoring?

I treat compliance as evidence that operational controls work rather than as a documentation exercise. My approach includes assigning control owners, integrating evidence collection into normal workflows, testing control effectiveness throughout the year, resolving exceptions through accountable remediation plans, and preparing leadership for material risks before an audit. This creates a durable program that supports customer trust and business growth.

How would you turn UpGuard's internal use of its platform into value for Product, Sales, and Customer Success?

I would run the platform deeply against our own enterprise and product risk scenarios, document the highest-value workflows and measurable outcomes, and identify friction or coverage gaps. I would share validated use cases, automation patterns, and customer-relevant proof points with Product, Sales, and Customer Success on a regular cadence. This ensures our operating experience directly informs product priorities and credible go-to-market narratives.

### Who are we?

At UpGuard, we are replacing manual security bottlenecks with AI-driven precision. Fresh off a US$75M Series C, we are scaling our infrastructure to process 100 billion risk signals daily. This isn’t just growth; it’s a total reimagining of how the world manages cyber risk.

We build the Cyber Risk Posture Management (CRPM) platform that security teams actually love. By integrating security ratings, threat intel, and agentic AI, we empower organisations to stay ahead of an ever evolving attack surface.

We aren’t just building another tool; we’re defining a category. We provide the autonomy to ship world-class technology and the resources to do it at a global scale.

### Where does this role fit in?

This is not a conventional CISO role, and we’d rather say that up front than have you discover it in week three.

You will own the entire enterprise technology stack — security and infrastructure, identity, end user compute, networking, cloud platform, and the technology and physical security services behind our workspaces. Security is the substrate, or underlay, for that stack – not a separate function that reviews someone else’s work. If you have run infrastructure or operations at scale and layered security over it, this remit will feel natural. If your background is governance-first, it won’t.

The environment you’re inheriting has been run deliberately lean for through start-up and scale-up, and it is opinionated by design. There is no Microsoft directory, productivity, or desktop footprint anywhere in the estate — Google Workspace, Okta, macOS and ChromeOS, managed browser for BYOD. Attack surface has been controlled by refusing to acquire it. We want that philosophy continued and extended, not unwound.

You’ll lead a team – currently nine FTE in size, across four functions: IT Operations, Security Operations, Cloud Platform Engineering and GRC. Your first structural job is maturing security operations to serve both enterprise and product systems — deeper investment in Google SecOps and our n8n automation platform to lift analytics, orchestration and response well beyond what a team this size would normally reach.

And because our product is the leading Cyber Risk Posture Management platform, you are customer zero. You and your team run UpGuard Cyber Risk harder than any of our customers do, turning what you learn into use cases Sales and Customer Success can take to market and signal Product can build on. That is a real, recurring part of the job, not a nice-to-have.

You’ll report directly to the CEO, with a defined transition period alongside the outgoing CISO. Details of the remit are below.

### What will you do?

*

Own the full technology and security remit. Enterprise infrastructure, security, identity, applications, and workplace technology under a single accountability. No handoffs, no shared ownership of outcomes

*

Lead and grow three functions. IT & Security Operations, Cloud Platform Engineering, and GRC. Coach the existing leaders, set the technical bar, and build the team you need beneath you — while holding the line on lean

*

Mature security operations. Build detection, analytics, orchestration and response capability that covers both enterprise and product systems. Drive investment into Google SecOps and n8n so that automation, not headcount, carries the load

*

Own identity end to end. IAM across our GCP project estate and identity governance and administration for the entire global workforce — joiner/mover/leaver, entitlement review, privileged access, and OAuth consent risk (which, fittingly, we control with our own User Risk product)

*

Own the network and cloud perimeter. ZTNA as the strategic access model, GCP perimeter security and networking

*

Own end user compute globally. A predominantly macOS fleet with selective use of ChromeOS and enterprise managed browser services for BYOD. Device provisioning and retrieval across all operating regions

*

Own the workspaces. Technology and physical security services for our offices — two today, potentially four by the end of 2027 across Australia and the US

*

Own the compliance program. [Delegated to the Infosec GRC Lead] SOC-2 Type II today, with ISO 27001 targeted to facilitate European growth. Own the enterprise risk register, and the security function’s inputs into vendor management and procurement

*

Be customer zero. Use our own platform to its full extent and beyond, integrating with external systems via our Risk Automations product, feeding real operating experience back into Product, with co-creation of the cases and proof points that Sales and Customer Success will turn into new deals and expands

*

Communicate at executive level. Brief the executive team, the Steering Committee and the Board, and be credible in front of customers and prospects when their security teams want to talk to ours

### What will you bring?

We care far more about your track record than your tenure. The bar is a leader who has personally built and operated technology at scale, with security as the discipline layered over it.

*

An infrastructure and operations foundation. You have run a data centre, an infrastructure function, or a substantial operations function — and security became your remit because you were already accountable for the systems. Architecture is where you’re strongest

*

Process discipline learned somewhere consequential. You’ve operated in an environment where failure had real consequences and process was the answer — financial services is a strong example of the discipline we mean, though not the only one. You know how to defend, operate, and structure

*

A demonstrated ability to do a lot with a little. You have built and scaled capability without heavy resourcing, and you reach for automation before headcount. This is the single most important thing we’re selecting for. If your effectiveness has depended on a large team, this role will frustrate you

*

Genuine comfort owning infrastructure, security, applications and identity together. Not as a stretch, but as your natural shape

*

Hands-on credibility. You are a leader, not a manager. You can architect a control, review a Terraform change, or lead an incident yourself — and you set the technical bar by example, not from the org chart

*

Cloud-native depth. Substantial GCP experience strongly preferred; deep AWS or Azure experience considered where the architectural instincts transfer. Zero trust access, identity-centric security models, and modern SaaS estate management

*

Ownership of a compliance program. You have carried SOC 2, ISO 27001, or equivalent as the accountable owner — through audit, not just through policy authoring

*

The ability to absorb context at speed. You’ll have a structured handover and then it’s yours. We need someone who is oriented in weeks, not quarters

*

Personal drive that doesn’t need to be managed. High-energy, self-directed, and relentless about the work. You’ll be given full ownership from day one, and we expect you to use it

*

Comfort operating in a fast-paced, high-growth, remote-first environment

### What’s in it for you?

*

Monthly Lifestyle subsidy: Use this for financial, physical, and mental well-being

*

WFH set-up allowance: To ensure you have the right environment to work in, we will help you get set up within your first 3 months at UpGuard

*

$1500 USD annual Learning & Development allowance: To support your career development, all team members will be able to expense development opportunities against this allowance

*

Annual leave: PTO plus two additional UpGuardian leave days to give you time to recharge your batteries.

*

18 weeks paid Parental Leave: Irrespective of parenting role

*

Personal Leave Allowance: This includes sick & carer’s leave

*

Fully remote working environment: While we have physical offices in Sydney & Hobart, we do not mandate compulsory attendance

*

Top-spec hardware: All team members will be provided with top-spec laptops for their role

*

Generative AI subsidy: UpGuard provides paid subscriptions for all team members to access generative AI tools to support their work

UpGuard is a Certified Great Place to Work® in the US, Australia, UK and India, establishing its position as a leading global technology employer. 99% of team members agree that UpGuard is a great place to work! Apply now to find out why!

As an Equal Employment Opportunity and Affirmative Action Employer, qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender perception or identity, national origin, age, marital status, protected veteran status, or disability status.

Please Note: Not all roles can be performed from the United States. Please check your specific job listing to confirm its advertised location. If the role you are applying for is listed as based in the US, we are currently only able to support hiring in the following locations: CA, CO, FL, IL, LA, MA, MD, MO, OR, PA, TX, WA, and DC.

Before starting work with us, you will need to undertake a national police history check and reference checks. Also, please note that at this time, we cannot support candidates requiring visa sponsorship or relocation.

Show more

[Apply now >](https://jobicy.com/jobs/153270-chief-information-security-officer-2.md)

>  Annual salary information is not provided for this position. Explore salary ranges for similar roles in our [Salary Directory ›](https://jobicy.com/salaries.md)

*

![Upload CV](data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSI2NSIgaGVpZ2h0PSI2NSIgZmlsbD0ibm9uZSIgeG1sbnM6dj0iaHR0cHM6Ly92ZWN0YS5pby9uYW5vIj48ZyBjbGlwLXBhdGg9InVybCgjQSkiPjxwYXRoIGQ9Ik0wIDBINjVWNjVIMFYwWiIgZmlsbD0iIzAyOWFlYiIvPjxnIGZpbGw9IiNmZmYiIHN0cm9rZT0iI2ZmZiIgc3Ryb2tlLXdpZHRoPSIyIj48cGF0aCBkPSJNMzMuMDQ5IDE1LjQ1NGExLjQzIDEuNDMgMCAwIDAtMi4wOTcgMGwtNy41NzkgOC4xNDdhMS4zOCAxLjM4IDAgMCAwIC4wOSAxLjk3MyAxLjQ0IDEuNDQgMCAwIDAgMi4wMDgtLjA4OGw1LjEwOS01LjQ5MnYyMC42MWExLjQxIDEuNDEgMCAwIDAgMS40MjEgMS4zOTdjLjc4NSAwIDEuNDIxLS42MjUgMS40MjEtMS4zOTd2LTIwLjYxbDUuMTA5IDUuNDkyYTEuNDQgMS40NCAwIDAgMCAyLjAwOC4wODggMS4zOCAxLjM4IDAgMCAwIC4wOS0xLjk3M2wtNy41NzktOC4xNDZ6TTE2Ljc2OSAzOC40YzAtLjc3My0uNjItMS40LTEuMzg1LTEuNFMxNCAzNy42MjcgMTQgMzguNHYuMTAybC4yMTUgNi4yMjljLjIyMyAxLjY4LjcwMSAzLjA5NSAxLjgxMyA0LjIxOHMyLjUxIDEuNjA3IDQuMTcyIDEuODMzYzEuNi4yMTggMy42MzYuMjE4IDYuMTYuMjE4aDExLjI4bDYuMTYtLjIxOGMxLjY2Mi0uMjI2IDMuMDYxLS43MDkgNC4xNzItMS44MzNzMS41ODktMi41MzggMS44MTMtNC4yMThDNTAgNDMuMTEzIDUwIDQxLjA1NSA1MCAzOC41MDNWMzguNGMwLS43NzMtLjYyLTEuNC0xLjM4NS0xLjRzLTEuMzg1LjYyNy0xLjM4NSAxLjRsLS4xOSA1Ljk1OGMtLjE4MiAxLjM3LS41MTUgMi4wOTUtMS4wMjYgMi42MTJzLTEuMjI4Ljg1My0yLjU4MyAxLjAzOGMtMS4zOTUuMTktMy4yNDMuMTkzLTUuODkzLjE5M0gyNi40NjJjLTIuNjUgMC00LjQ5OC0uMDAzLTUuODkzLS4xOTMtMS4zNTUtLjE4NC0yLjA3Mi0uNTIxLTIuNTgzLTEuMDM4cy0uODQ0LTEuMjQyLTEuMDI2LTIuNjEyYy0uMTg3LTEuNDEtLjE5MS0zLjI3OS0uMTkxLTUuOTU4eiIvPjwvZz48L2c+PGRlZnM+PGNsaXBQYXRoIGlkPSJBIj48cGF0aCBmaWxsPSIjZmZmIiBkPSJNMCAwaDY1djY1SDB6Ii8+PC9jbGlwUGF0aD48L2RlZnM+PC9zdmc+)

### Upload your resume now

To unlock remote work opportunities and be discovered by global employers.

This job listing has been manually reviewed by the Jobicy Trust & Safety Team for compliance with our posting guidelines, including verification of the company's legitimacy, accuracy of job details, clarity of remote work policy, and absence of misleading or fraudulent content.

Next step

## Apply now.

Follow the employer’s application method and review Jobicy’s safety guidance before sharing personal information.

Keep exploring

## Related remote jobs.

Matched by job category10 related opportunities[Cybersecurity](https://jobicy.com/categories/cybersecurity.md) [Browse all jobs](https://jobicy.com/jobs.md)
*
![BetterHelp logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/0b48fde8-221.jpeg)
BetterHelp  Sep 13

### [Head of Security Engineering](https://jobicy.com/jobs/153174-head-of-security-engineering.md)

Who are we and why should you join us? BetterHelp is on a mission to remove the traditional barriers to therapy and make mental health care more accessible to everyone….

*
![Deloitte logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2021/09/370c2482dacb3fffbd4043cfca5674fe.png)
Deloitte  Sep 13

### [Manager, Cyber Compliance, Deloitte Global Technology](https://jobicy.com/jobs/150563-manager-cyber-compliance-deloitte-global-technology.md)

Job Type: Permanent Work Model: Remote Reference code: 134501 Primary Location: Toronto, ON All Available Locations: Toronto, ON   Our Purpose   At Deloitte, our Purpose is to make an impact that matters. We exist to inspire…

*
![1Password logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2020/09/WRILS-200909195848-296323.png)
1Password  Sep 12

### [Manager, Security Incident Response](https://jobicy.com/jobs/153123-manager-security-incident-response.md)

1Password is growing. We’ve surpassed $400M in ARR and we’re continuing to accelerate, earning a spot on the Forbes Cloud 100 for four years in a row and teaming up…

*
![Sporty Group logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/8e6c246a-221.png)
Sporty Group  Sep 12

### [Offensive Security Engineer](https://jobicy.com/jobs/149060-offensive-security-engineer.md)

About the roleMission Strengthen Sporty’s offensive security posture by proactively testing and identifying vulnerabilities across our external perimeter, standalone virtual private servers (VPS), physical office infrastructure, and endpoint defenses. The…

*
![Rithum logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/fe3986d8-221-1.jpeg)
Rithum  Sep 12

### [Staff Information Security Engineer – AI First](https://jobicy.com/jobs/153112-staff-information-security-engineer-ai-first.md)

Rithum™ is the world’s most trusted commerce network, accelerating how brands, suppliers, and retailers work together to deliver seamless e-commerce experiences. We provide an unmatched platform for brands and retailers,…

*
![Liftoff logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/c47aea9f-221.png)
Liftoff  Sep 12

### [Security Engineer, Detection & Response](https://jobicy.com/jobs/153102-security-engineer-detection-response.md)

Liftoff is a leading AI-powered performance marketing platform for the mobile app economy. Our end-to-end technology stack helps app marketers acquire and retain high-value users, while enabling publishers to maximize…

*
![Stripe logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2020/10/WRILS-201011073943-272457.png)
Stripe  Sep 11

### [Abuse Research Engineer](https://jobicy.com/jobs/153053-abuse-research-engineer.md)

Who we are About Stripe Stripe is a financial infrastructure platform for businesses. Millions of companies—from the world’s largest enterprises to the most ambitious startups—use Stripe to accept payments, grow…

*
![Luna Physical Therapy logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2026/07/fcb34e841928-221.webp)
Luna Physical Therapy  Sep 11

### [Director , Information Security and IT](https://jobicy.com/jobs/153041-director-information-security-and-it.md)

Luna is seeking a Director of Information Security & IT to lead the strategy, execution, and continuous evolution of the company’s enterprise technology and information security programs. Reporting to the…

*
![CertiK logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2021/03/Jobicy-210308091023-955845.jpg)
CertiK  Sep 10

### [Blockchain Security Expert Intern – AI Track](https://jobicy.com/jobs/152979-blockchain-security-expert-intern-ai-track.md)

About the Company Founded in 2018 by professors of Yale University and Columbia University, CertiK is a pioneer in blockchain security, utilizing best-in-class AI technology to secure and monitor blockchain…

*
![CertiK logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2021/03/Jobicy-210308091023-955845.jpg)
CertiK  Sep 10

### [Blockchain Security Expert – Security Audit Track](https://jobicy.com/jobs/152975-blockchain-security-expert-security-audit-track.md)

About You You’re a self-starter. You believe in tackling the most important problems, even if they are the most difficult problems. You’re comfortable with the unknown and understand that #startuplife…