Chief Information Security Officer (CISO)
CAIS is the pioneer in democratizing access to and education about alternative investments and structured products for independent financial advisors, empowering them to engage and transact with leading asset managers and bank issuers on a massive scale through a wide variety of alternative investment products and technology solutions. CAIS provides financial advisors with a broad selection of alternative investment strategies, including hedge funds, private equity, private credit, real estate, digital assets, and capital market solutions including structured notes, market-linked CDs, and hedging strategies for concentrated stock positions. CAIS also delivers industry-leading technology, operational efficiency, and world-class client service throughout the pre-trade, trade, and post-trade experience. CAIS supports over 50,000 advisors who oversee more than $6 trillion in network assets. CAIS is seeking a Chief Information Security Officer (CISO) who pairs deep technical expertise with strategic vision to lead the firm’s cybersecurity program and Operational Risk Management practices. This role will drive security strategy—including AI security strategy—mitigate risks, ensure regulatory compliance, and protect critical financial assets and client data. The CISO will oversee all cybersecurity and operational risk functions while remaining hands-on with architecture, tooling, and incident response, and will ensure third-party and vendor security align with the firm’s risk management framework. Responsibilities Cybersecurity Leadership: Develop and execute a comprehensive security strategy aligned with industry standards (NIST, ISO 27001, CIS Controls) to safeguard sensitive financial data. Risk Management & Threat Intelligence: Continuously assess cyber threats, vulnerabilities, and implement proactive security measures. Operational Risk Oversight: Lead the firm's operational risk management framework, including identification, assessment, and mitigation of operational risks across business processes, technology systems, and third-party relationships. Regulatory Compliance & Audit: Ensure compliance with financial industry regulations (SEC, FINRA, SOC 2), managing audits and certifications. Third-Party & Vendor Security: Evaluate and manage security risks associated with external partners, vendors, and cloud service providers, ensuring compliance with cybersecurity policies. Incident Response & Crisis Management: Lead the firm’s response to security incidents, breaches, and fraud, ensuring swift resolution and recovery. Technology & Infrastructure Security: Lead secure architecture design, cloud security, endpoint protection, and network security—personally engaging in design reviews, tooling evaluations, and technical decision-making. AI Security Strategy: Develop and implement security policies and governance frameworks for AI and machine learning systems, ensuring responsible AI deployment, data integrity, model secur...