Jobs and Careers
PU

Chief Information Security Officer

Pushpay
Colorado Springs, United Statesfull_timeVerifiedPosted 1 Feb 2024
💰 $270,000/yr($210,000/yr$270,000/yr)

About the role

About the Role

The Chief Information Security Officer (CISO) is responsible for designing and implementing an information security program at Pushpay. The information security program will protect the company products, systems and personnel from both external and internal threats. This role applies to products and systems across Pushpay. The role is expected to work alongside company executives to establish and enforce policy, assess security risks and implement mitigation plans where needed. It is considered a VP/Sr VP level role.  

Ranked number 14 by Seattle Business Magazine in the ‘Washington’s 100 Best Companies to Work For’ list in the large companies category; and named as one of BuiltIn Seattle’s ‘Best Places to Work.

Benefits and Compensation

  • 100% employer-paid premiums for Medical, Dental, and Vision for employee
  • 75%+ employer-paid premiums for Medical, Dental, and Vision for dependents
  • 401K match
  • Flexible / remote working program
  • 12 paid company holidays
  • 25 days PTO 
  • Paid parental and adoption leave
  • Compensation Range: $210,000- $270,000
  • 10% STI

Compensation ranges are determined by role and location. The range displayed on each job posting reflects the pay range for the position across all US locations. Within the range, individual pay is determined by work location and additional factors, including job-related skills, experience, and relevant education or training.

What You'll Do

  • Supervise information security personnel. 
  • Responsible for the design, implementation, and monitoring of a company-wide information security program. 
  • Maintain responsibility for the development, socialization, approval, and implementation of procedures, standards, and policies to protect the privacy and integrity of Pushpay products, systems, and data.  
  • Ensure compliance with regulations and security policies that apply to Pushpay products and systems, such as PCI compliance and regional or national data privacy regulations.
  • Responsible for the internal PCI program and compliance. 
  • Responsible for identifying the standards and frameworks that apply to the company and maintaining compliance - such as SOC2, ISO 27001, NIST cybersecurity framework, or other relevant standards.  
  • Responsible for working with product and engineering to establish a "Security by Design" practice, including elements such as secure coding practices, threat modeling, and response and recovery plans from a cybersecurity event. 
  • Work across other executive functions to establish policies, assess risk, and implement mitigations where required. 
  • Develop and maintain a document framework of continuously up-to-date information security policies, standards, and guidelines. 
  • Responsible for company wide training necessary to maintain awareness internally of data privacy and security practices and expectations.  
  • Responsible for the development, maintenance, and execution of security-related incident response plans and procedures to ensure that business-critical services are recovered in the event of a security event; provides direction, support, and in-house consulting in these areas.
  • On a continuous basis, evaluate overall information security capabilities and needs of the company and ensure that policies and plans are sufficient and effective.  
  • Develop budget plans for personnel and non-personnel resources.
  • Act as the appointed Data Protection Officer for the company. 

Internal contacts

VP and C-Suite staff, IT and Operations leadership, Engineering and product leadership

External contacts

PCI Auditors; Regulatory agencies; 3rd party counsel 

What You'll Bring

Skills

  • Formal qualifications and considerable application experience in the field of cybersecurity, data privacy and internal security policy.  
  • Sound knowledge of relevant standards such as PCI, GDPR, CCPA, SOC2, ISO27001 and similar. 
  • Ability to design, implement and enforce enterprise wide policies and programs. 
  • Knowledge of Security by Design practices and practical applications in a SaaS business. 
  • Ability to lead and guide a team of cybersecurity professions. 
  • Outstanding relationship building and stakeholder management skills.
  • Ability to communicate effectively with both front line staff through senior leadership and board level audiences.  

Education/Experience

  • Bachelor’s degree in Computer Science, Computer of Software Engineering, Information Technology, or related field or equivalent indus

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Pushpay

View company profile →