CISO building Ent’s internal security program for its AI-native workspace security platform. Leading cloud, product, compliance, incident response, and enterprise customer security.
Responsibilities
Set Ent's company-wide security strategy and roadmap with priorities, ownership, and measurable outcomes
Personally drive critical assessments, control design, remediation, and incident work
Build a focused internal security team and operating model, using outside partners where useful
Own security risk across identities, employee endpoints, SaaS applications, cloud infrastructure, company data, software supply chain, and third-party vendors
Partner with Engineering and Product on architecture, threat modeling, secure design reviews, vulnerability management, secrets and dependency management, logging, monitoring, and remediation
Establish and improve controls for identity and access management, device security, privileged access, data protection, configuration management, and employee onboarding and offboarding
Build and lead incident response, including detection, escalation, investigation, containment, communications, tabletop exercises, post-incident reviews, business continuity, and disaster recovery improvements
Lead security assurance and compliance programs involving SOC 2, ISO 27001, FedRAMP, and customer-specific standards
Own customer and partner security diligence, including questionnaires, audits, penetration tests, security reviews, and contractual security commitments
Create policies and security education for sensitive data, approved AI tools, and risks from AI agents and automation
Use Ent's product internally and provide structured feedback to Product, Engineering, and Research
Report Ent's risk, readiness, incidents, and investment priorities to the executive team and board
Represent Ent in strategic customer security conversations when needed
Requirements
Experience operating at CISO, Deputy CISO, Head of Security, or equivalent scope in a high-growth technology company
Experience building a security program during an early stage of growth is strongly preferred
Deep technical understanding of cloud, identity, endpoint, application, product, and infrastructure security
Experience securing cloud-first environments and modern identity and device ecosystems
Experience with AWS, Azure, or GCP
Experience with Google Workspace or Microsoft Entra ID
Experience with macOS and Windows device management
Strong command of incident response, vulnerability management, security monitoring, third-party risk, data protection, and secure software development practices
Experience building and maintaining security assurance or compliance programs such as SOC 2, ISO 27001, or FedRAMP
Experience supporting diligence requirements of sophisticated enterprise or government customers
Current understanding of security risks created by AI systems, generative AI, autonomous agents, sensitive data flows, and changing development tools
Sound risk judgment and practical operating style
Ability to move between strategy and execution
Strong communication skills with technical teams, executives, board members, customers, auditors, and partners
Low-ego, highly collaborative approach and ability to build trust across functions
Benefits
Every teammate gets meaningful equity on top of their salary
90% of medical, dental, and vision is paid by Ent
Ent covers 75% for dependents
Flexible PTO
12 weeks of fully paid maternity leave (birth, adoption, or foster)
8 weeks fully paid paternity leave
$100 monthly lifestyle account for fitness, wellness, learning, and more
$500 home office stipend when joining as a remote employee
Distributed workplace with remote hiring across North America