Jobs and Careers
WE

Chief Information Security Officer

Webflow
U.S. Remote, United StatesRemotefull_timeVerifiedPosted 25 Mar 2025
💰 $350,000/yr($200,000/yr$350,000/yr)

About the role

At Webflow, our mission is to bring development superpowers to everyone. Webflow is a Website Experience Platform (WXP) that empowers modern marketing teams to visually build, manage, and optimize stunning websites. With AI-driven personalization baked in, Webflow enables teams to significantly boost conversion rates, translating directly into measurable business growth. From independent designers and creative agencies to Fortune 500 companies, millions worldwide use Webflow to be more nimble, creative, and collaborative.

We’re looking for a Chief Information Security Officer (CISO) to play a pivotal role in securing our platform, protecting our customers’ data, and innovating to ensure our security posture aligns with the industry’s highest standards.

About the role:

  • Location: Remote-first (United States)
  • Full-time
  • Permanent 
  • Exempt
  • The cash compensation for this role is tailored to align with the cost of labor in different geographic markets. We've structured the base pay ranges for this role into zones for our geographic markets, and the specific base pay within the range will be determined by the candidate’s geographic location, job-related experience, knowledge, qualifications, and skills.
  • United States  (all figures cited below are in USD and pertain to workers in the United States) 
    • $200,000 - $350,000

This role is also eligible to participate in Webflow's company-wide bonus program. Target amounts are a percentage of base salary and vary by career level. Payouts are based on company performance against established financial and operational goals. 

Please visit our Careers page for more information on which locations are included in each of our geographic pay zones. However, please confirm the zone for your specific location with your recruiter.

Reporting to the Chief Technology Officer, as Webflow’s Chief Information Security Officer (CISO), you will:

  • Develop and Lead Security Strategy: Create and implement a comprehensive security vision that safeguards Webflow’s infrastructure, products, user data, and company data.
  • Drive Cross-Functional Collaboration: Partner with engineering, product, legal, compliance, and executive leadership to embed security into every layer of our business.
  • Ensure Regulatory Compliance: Oversee compliance with security-related regulations such as GDPR, SOC 2 Type 2, ISO 27001, and ISO 42001 ensuring robust data privacy and integrity.
  • Respond to Emerging Threats: Proactively identify, assess, and mitigate cybersecurity risks in Webflow’s dynamic, cloud-first environment.
  • Establish Metrics and Reporting: Define and report on key security program metrics to measure the maturity and effectiveness of security initiatives.
  • Foster a Security-Conscious Culture: Lead initiatives to educate employees and customers about cybersecurity best practices.

In addition to the responsibilities outlined above, at Webflow we will support you in identifying where your interests and development opportunities lie and we'll help you incorporate them into your role.

About you:

You’ll thrive as our CISO if you have:

  • Experience:
    • 10+ years in information security, with at least 5 years in a leadership role, ideally within SaaS or high-growth environments.
    • Proven track record of securing dynamic, cloud-based platforms (strong preference for AWS).
    • Expertise in implementing and monitoring adherence to compliance frameworks (e.g., SOC 2 Type 2, ISO 27001, FedRAMP).
    • Experience leading security teams, conducting audits, and managing security incident response in a SaaS environment.
  • Technical Skills:
    • Deep knowledge of security protocols, tools, and standards such as NIST Cybersecurity Framework or CIS Controls.
    • Familiarity with DevSecOps practices in CI/CD pipelines.
    • Proficiency in risk assessment, penetration testing, and vulnerability management.
  • Leadership:
    • Excellent communication skills to translate technical security issues into actionable insights for diverse audiences.
    • Ability to build and develop high-performing, inclusive security teams.
  • Certifications:
    • Preferred certifications: CISSP, CISM, or equivalent.

Our Core Behaviors:

  • Obsess over customer experience. We deeply understand what we’re building and who we’re building for and serving. We define the leading edge of what’s possible in ou

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Webflow

View company profile →