Chief Information Security Officer (CISO)

RunBuggy OMITempe, AZ
Hybrid

About The Position

RunBuggy is seeking a Chief Information Security Officer (CISO) to provide enterprise leadership for the company’s cybersecurity, risk management, compliance, IT infrastructure, end-user technology operations, and enterprise data governance. This executive role is responsible for ensuring the company’s technology environment is secure, resilient, scalable, and aligned with business priorities, regulatory obligations, and the company’s risk tolerance. The successful candidate will be a seasoned, business-minded, hands-on security executive with proven experience leading cybersecurity strategy, incident response, governance, cloud security, regulatory compliance, IT operations, data governance, fraud prevention, and high-performing teams. This individual will act as both a strategic advisor and an operational leader, working proactively with product and engineering teams to secure the platform, anticipate threats, and protect the business from cyber, physical-theft, fraud, and organized-crime risks. This is a hybrid role based out of Tempe, AZ, requiring 2-3 days per week in the office.

Requirements

  • Bachelor’s degree in cybersecurity, computer science, information systems, business, or a related field; advanced degree preferred.
  • 12+ years of progressive experience in information security, cybersecurity, technology risk, or a related discipline, with at least 5 years of experience leading security teams or enterprise security programs.
  • Demonstrated experience developing and executing an enterprise cybersecurity strategy.
  • Strong background in security governance, risk management, compliance, audit, and enterprise data governance.
  • Experience leading incident response and organizational recovery from security events.
  • Experience with cloud security, identity and access management, application security, and security operations.
  • Experience partnering with product and engineering teams to secure customer-facing platforms and reduce abuse, fraud, and operational security risk.
  • Experience communicating cybersecurity risks and recommendations to executive leadership and boards.
  • Strong knowledge of recognized security frameworks and practices, including NIST, ISO 27001, CIS Controls, or equivalent.
  • Excellent written, verbal, analytical, and presentation skills.
  • Ability to translate complex technical issues into clear business and risk considerations.

Nice To Haves

  • Professional certifications such as CISSP, CISM, CRISC, CISA, CCSP, or GIAC credentials.
  • Experience supporting a fast-growing distributed organization.
  • Experience managing customer security reviews and enterprise trust programs.
  • Experience with privacy programs, data-protection regulations, and enterprise data governance or data management frameworks.
  • Familiarity with AI security, machine-learning security, or emerging technology risk.
  • Previous experience presenting to a board of directors or board-level committee.

Responsibilities

  • Set and lead the company’s enterprise cybersecurity strategy, priorities, policies, standards, and operating plans.
  • Advise executive leadership and the board on cybersecurity risk, business impact, investment priorities, and emerging threats.
  • Take a hands-on, offensive security posture by anticipating threat activity, challenging assumptions, and driving proactive risk reduction across the business.
  • Promote a companywide security culture through education, awareness, and accountable business practices.
  • Lead security governance, risk, compliance, audit readiness, and regulatory alignment across the enterprise.
  • Oversee processes to identify, assess, prioritize, mitigate, and report information-security risks.
  • Maintain compliance with applicable laws, regulations, and security frameworks, including SOC 2, ISO 27001, NIST, PCI DSS, HIPAA, GDPR, or other relevant standards.
  • Manage third-party security risk and partner with Legal and Compliance on privacy, data protection, data governance, contracts, and regulatory matters.
  • Oversee core security operations, including monitoring, vulnerability management, identity and access management, endpoint security, application security, cloud security, and threat intelligence.
  • Establish, test, and continuously improve incident-response, disaster-recovery, and business-continuity plans.
  • Lead response to significant security incidents, including executive, customer, regulator, law-enforcement, and stakeholder communications as appropriate.
  • Partner with Operations, Legal, Compliance, and law enforcement as appropriate to prevent, investigate, and respond to physical theft, fraud, organized-crime activity, and related security threats.
  • Work directly with Product and Engineering to embed secure-by-design practices into the platform, product roadmap, software delivery, technology architecture, and cloud environments.
  • Partner with Engineering and IT to strengthen infrastructure, network, application, data, and platform security.
  • Lead hands-on offensive security efforts, including penetration testing, red-team exercises, abuse-case reviews, security assessments, code reviews, and remediation programs.
  • Support secure adoption of emerging technologies, including artificial intelligence and automation.
  • Own the company's enterprise data governance strategy, including data classification, quality standards, retention, disposal, and metadata management, ensuring data assets are inventoried and protected in accordance with company policy and applicable law.
  • Partner with Legal, Compliance, Product, and Engineering to align data governance practices with applicable privacy laws, contractual obligations, and regulatory requirements across all business functions.
  • Oversee reliable, secure IT infrastructure and end-user technology services, including networking, cloud storage, device management, identity and access, backups, and recovery.
  • Manage IT service providers, managed-service providers, and technology vendors to ensure performance, accountability, and value.
  • Coordinate infrastructure changes, maintenance windows, upgrades, and planned service interruptions to minimize business disruption.
  • Build, lead, and develop a high-performing security and IT team with clear roles, accountability, and talent strategy.
  • Establish performance metrics, service-level expectations, operating procedures, budgets, and investment priorities.
  • Foster strong collaboration across security, engineering, IT, compliance, privacy, legal, product, operations, and business teams.
  • Other duties as assigned.

Benefits

  • Market-competitive pay based on education, experience, and location.
  • Highly competitive medical, dental, vision, Life w/ AD&D, Short-Term Disability insurance, Long-Term Disability insurance, pet insurance, identity theft protection, and a 401(k) retirement savings plan.
  • Employee wellness program.
  • Employee rewards, discounts, and recognition programs.
  • Generous company-paid holidays (12 per year), vacation, and sick time.
  • Paid paternity/maternity leave.
  • Monthly connectivity/home office stipend if working from home 5 days a week.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service