Jobs and Careers
RO

Chief Information Security Officer

Root Inc.
United Statesfull_timeVerifiedPosted 1 May 2025
💰 $325,000/yr($300,000/yr$325,000/yr)

About the role

CURRENT ROOT EMPLOYEES - Please apply using the career page in Workday. This career site is for external applicants only.


 

The Opportunity

At Root, we’ve reimagined car insurance to make it smarter, more equitable, and a better experience for all. Using technology in smartphones, we’re able to measure driving behavior to give our customers the prices they deserve.

We are seeking a Chief Information Security Officer (CISO) to lead our Information Security and Information Technology functions. Reporting to the President & CTO, the CISO will be a critical member of Root’s senior leadership team. The CISO will be responsible for the development, execution, and continual improvement of our enterprise-wide cybersecurity and IT strategies. This dual-role executive will ensure that both security and IT operations are closely aligned with business objectives, regulatory requirements, and the company's growth ambitions.

The CISO will oversee the following functions:

  • Governance, Risk, and Compliance (GRC)

  • Security Engineering

  • Security Operations

  • Identity and Access Management (IAM)

  • IT Operations

The successful candidate will combine modern security leadership with hands-on operational excellence, contributing to a scalable, secure, and resilient technology environment. This leader will combine strong regulatory and compliance expertise with deep technical knowledge to support Root’s mission and technology-first culture.

Root is a “work where it works best” company. This means we will support you working in whatever location that works best for you across the US."

Salary Range: $300,000 - $325,000 (Bonus and LTI Eligible)

How You Will Make an Impact

  • Leadership & Strategy: 

    • Develop and execute a comprehensive information security and IT roadmap aligned to company strategy and risk tolerance.

    • Foster and grow a collaborative, high-performing culture across the organization.

    • Represent cybersecurity and IT initiatives at the executive and board levels, including quarterly reporting and strategic planning.

    • Serve as a trusted advisor to executive leadership on security, risk, technology, and compliance matters.

    • Drive awareness and alignment across cross-functional teams by championing the critical role of product security, and influence product roadmaps to ensure robust and proactive risk management.

  • Information Security Team Responsibilities: 

    • Security Engineering: set technical direction for security architecture, standards, and automation; build and maintain scalable security services (vulnerability management, secure CI/CD patterns, embedded security controls); provide technical oversight and assessment; act as internal consultant and enabler. 

    • Security Operations: facilitate rigorous endpoint protection, vulnerability management, threat monitoring, and security incident response; coordinate security awareness training programs; manage third-party security providers

    • Identity and Access Management (IAM): oversee user lifecycle management and IAM platform enhancements; promote operational excellence in access request handling; support continuous improvement initiatives

    • Governance, Risk and Compliance (GRC): lead rigorous periodic risk assessments, application risk management, and third party vendor security reviews; facilitate maintaining compliance with cybersecurity regulations and manage attestation process; oversee the security framework and policy lifecycle, control testing programs, and enterprise risk reporting; lead the execution of penetration test engagements. 

  • Information Technology Team Responsibilities: 

    • IT Operations: manage technology asset lifecycle, procurement, inventory, and secure disposal; supervise end-user support, device management, and IT infrastructure operations; oversee management of core business platforms and office network support; ensure consistent and secure onboarding, offboarding, and operational IT excellence 

What You Will Need to Succeed

  • 10+ years of leadership experience in cybersecurity, IT, and risk management roles, in highly regulated industries such as insurance or financial services.

  • Deep familia

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Root Inc.

View company profile →