We're looking for a CISO who can do two things exceptionally well: build and run a robust security compliance program AND do hands-on technical security work. This isn't a role where you'll spend 100% of your time on PowerPoint and vendor questionnaires (though there will be some of that). You'll be reviewing architecture, working with our development team on secure design, and making real technical decisions. The immediate challenge: We're transitioning from a limited exemption to full NYDFS (23 NYCRR 500) compliance, with our first full certification due April 2026. You'll be building our compliance program while also establishing long-term security practices that actually make us more secure, not just check regulatory boxes. The Reality of Year 1 We want to be transparent: The first year will be challenging. You'll be: Building the TPSP governance program from scratch (we have a lot of vendors) Getting us ready for our first full NYDFS certification (April 2026) Overseeing MFA implementation across thousands of users Documenting and formalizing security practices we're already doing It's going to be a mix of rewarding technical work and necessary compliance grinding. After Year 1, the job shifts more toward proactive security work, architecture reviews, and continuous improvement. If you want a CISO role where you only do compliance paperwork, this isn't it. If you want a role where you only do technical security with zero regulatory work, this also isn't it. But if you want to build a security program that's both compliant AND actually makes the company more secure - and you want to stay technical while doing it - this might be perfect. This position is a 100% remote U.S. based opportunity that can be based in one of the following states only: AL, AZ, FL, GA, KY, LA, MA, MO, NC, NJ, NY, OH, OR, PA, SC, TX, UT, VA, WA, WI. Some travel for day-to-day work, team meetings, and training will be required.