Back to Jobs
Legal & HR Just now

Field Chief Information Security Officer (CISO)

United StatesUnited States
Full-time
$210,000 - $350,000
Lead/Manager

Job Description

Key Skills Required

Master these to land this role

CybersecurityComplianceSaaSLeadershipGRC

Want to know if you're a match for this job?

Calculate My Match Score

What you’ll do:

  • Partner with our amazing Sales, Customer Success, and Marketing teams on our most strategic enterprise and F500/G2000 opportunities—bringing tried-and-true security and GRC expertise into the conversation when customers need it most.

  • Lead executive briefings and CISO-to-CISO conversations that build trust and help prospective customers feel confident in their decision.

  • Represent Drata at industry conferences, CISO dinners, and regional roundtables across the Americas, EMEA, and APAC regions, building genuine relationships across the security and GRC community.

  • Share what you’re hearing in the field through webinars, panels, bylines, and press opportunities that build Drata’s voice and credibility in the security and GRC market.

  • Advise our CISO, CMO, CRO, and executive leadership team members directly on emerging regulatory shifts, systemic industry risk, and where Drata's security and GRC strategy needs to head next.

  • Provide strategy and direction to company-wide responses to major shifts in our industry, such as new regulatory regimes, major certifications, systemic risk events surfaced by our customers, reaffirming the direction set has a lasting effect on Drata's market position.

  • Raise the overall security and GRC bar across Drata and industry-wide through knowledge sharing, internal and external forums, and pattern-setting.

  • Equip our sales teams with the security and GRC context and talking points they need to navigate technical conversations with confidence.

  • Draw on your own relationships and reputation in the security and GRC community to open doors and build trust for Drata.

  • Partner with Marketing and GTM leadership to help plan executive events, speaking engagements, dinners, and roundtables throughout the year.

  • Act as a real, ongoing influence on our product roadmap and go-to-market growth strategy — not just relaying field feedback, but helping shape the decisions themselves based on hands on experience corroborated with customer needs.

  • Step in on the highest-stakes, least-defined security and GRC questions facing the business—the ones without an existing playbook—and provide the strategic direction to resolve them.

  • Approach every external conversation as an extension of Drata’s security and GRC program, with the same care and integrity you’d bring internally.

  • Work alongside our own internal security and GRC team members to support any critical company initiatives as deemed necessary.

What you’ll bring:

  • 15+ years of progressive experience in security and GRC, including 10+ years leading and managing teams and 5+ years in the CISO seat (as a CISO, Deputy CISO, or equivalent senior security and GRC leader).

  • A strong grasp of the compliance frameworks our customers care about — including ISO 27001, SOC 2, HIPAA, FedRAMP, GDPR, NIST CSF, PCI DSS, and CCPA — and the practical experience to speak to them with real depth.

  • Excellent communication skills, with the ability to move comfortably between boardroom conversations and technical deep-dives.

  • A genuine reputation and network within the security and GRC community, built through your own experience leading programs and engaging with peers.

  • A track record of operating at the most senior individual contributor level of a security or GRC organization, where leadership and peers already come to you for strategic direction, not just execution.

  • Comfort working with ambiguity — turning undefined, fast-moving problems like regulatory direction, market shifts, or systemic risk into clear strategy, not just talking points.

  • Experience partnering with go-to-market teams in customer-facing conversations, and comfort with the pace and cadence of enterprise sales cycles.

  • A track record of thought leadership—speaking, writing, or other public and social engagement that reflects your experience and perspective.

  • Familiarity with SaaS and cloud-native environments, along with a thoughtful perspective on how AI is shaping both security and GRC risk and practice.

  • Familiarity with compliance automation platforms like Drata, so you can speak to our own product with the same credibility you bring to security and GRC itself.

  • Openness to travel regularly and represent Drata’s security and GRC program in a public-facing capacity.

  • A curious, thoughtful approach to using AI in your own work, with the judgment to apply it responsibly.

Requirements:

  • 15+ years in security and GRC, including 10+ years leading and managing security and GRC teams and 5+ years in the CISO seat (as a CISO, Deputy CISO, or equivalent senior security and GRC leader).

  • Ideally either based on the East Coast of the U.S. or willing to work EST hours to support coverage across the Americas and EMEA time zones.

  • Willingness to travel regularly - 50-75% (including international travel) for customer meetings, conferences, and field events.

  • Professional certifications such as CISSP, CISM, CRISC, or CCSP are a plus (though real, tenured experience carries more weight).

How would you rate this job post?

See what other professionals think about this role.

Safety First

  • Never pay for a job application.
  • Do not share sensitive bank info.
  • Verify the client before starting work.
Learn More