Chief Information Security Officer; CISO
Listed on 2026-01-12
-
IT/Tech
Cybersecurity, Information Security, Data Security, IT Consultant
Chief Information Security Officer (CISO) – Locations: US – Georgia (Atlanta office), US – California (Virtual). Full‑time. Posted yesterday. Candescent is a leading cloud‑based digital banking solutions provider and an equal‑opportunity employer.
Role OverviewAs we expand our fintech ecosystem, AI capabilities, and security offerings, we are seeking a Chief Information Security Officer (CISO) to lead enterprise security, compliance, and trust. The CISO reports directly to the Chief Technology Officer (CTO) and serves as a core member of the Technology Leadership Team. This executive will define and execute Candescent’s enterprise‑wide security, compliance, and risk management strategy, ensuring regulatory alignment (FFIEC, SOC2, ISO 27001, PCI‑DSS, GDPR) and advancing product‑embedded identity and fraud detection capabilities.
Key Responsibilities- Security & Compliance Leadership
- Lead enterprise‑wide information security strategy and governance aligned to FFIEC, GLBA, NIST CSF, SOC2, ISO 27001, PCI‑DSS, and GDPR.
- Manage regulatory relationships and ensure audit readiness with customers, regulators, and independent assessors.
- Define and monitor security risk metrics, dashboards, and board‑level reporting.
- Partner with Legal, Risk, and Compliance teams to maintain proactive adherence to evolving banking and fintech regulations.
- Product, Platform, and API Security
- Build and mature Secure SDLC practices integrating SAST/DAST, dependency scanning, and threat modeling.
- Lead a comprehensive API Security program addressing authentication, authorization, token management, rate limiting, payload inspection, and anomaly detection.
- Secure Open Banking and Fintech APIs, ensuring compliance with data security and privacy standards.
- Oversee penetration testing and bug bounty programs, emphasizing API and data‑layer resilience.
- Collaborate with Product and Engineering to ensure secure‑by‑design principles are applied to all services, including microservices deployed in GCP and AWS.
- Embed fraud detection and identity protection mechanisms—such as device fingerprinting, behavioral analytics, and AI‑based anomaly detection—directly into platform and product architectures.
- Identity, Fraud Detection & Trust
- Oversee the architecture, compliance, and integrity of Candescent’s Identity and Fraud Detection products.
- Partner with Product and Engineering to enhance fraud prevention models and partner integrations for fraud detection.
- Establish governance and controls around customer identity data protection, in compliance with privacy frameworks.
- AI Governance & Responsible AI
- Define and implement AI security and compliance frameworks covering model and AI tooling development, deployment, and monitoring.
- Partner with Candescent AI Labs to secure AI pipelines and defend against prompt injection, model inversion, and data leakage.
- Lead Responsible AI initiatives, aligning with regulatory guidance and customer expectations.
- Serve as an executive sponsor for AI risk management, bridging security, ethics, and compliance.
- Cloud & Infrastructure Security
- Oversee identity and access management (IAM), encryption, key management (KMS), and Zero‑Trust Architecture across hybrid environments.
- Lead incident response, root‑cause analysis, and business continuity exercises.
- Collaborate with SRE and Platform teams to strengthen resiliency, observability, and reliability in production systems.
- Fintech Ecosystem & Third‑Party Risk
- Govern security and compliance for fintech integrations, payment networks, and core banking partners.
- Strengthen and lead a Vendor Risk Management (VRM) and Third‑Party Assurance program.
- Engage directly with customer CISOs, auditors, and regulatory stakeholders to communicate Candescent’s security posture and roadmap.
- Ensure all third‑party integrations meet FFIEC and GLBA security requirements.
- 15+ years in Information Security, including 5+ years in a CISO or senior security leadership role within financial services, fintech, or SaaS.
- Bachelor’s degree in computer science, information technology, or cybersecurity.
- Deep expertise in API Security, Cloud Security, Product Security, and Identity/fraud detection systems.
- Proven…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).