management
Posted Jun 4Chief Information Security Officer
Hybrid
Responsibilities
- Develop and execute the enterprise-wide information security strategy, overseeing risk management, governance, compliance, and threat mitigation to protect highly sensitive data, intellectual property, customer environments, and Mission Hero infrastructure.
- Represent Defense Unicorns' security posture in customer-facing engagements, contract negotiations, government interactions, and partnership discussions.
- Foster a collaborative, mission-first security culture, one that empowers Unicorns to move fast while minimizing risk to the business and our customers.
- Own and execute on a strategy for responsible, cross-cutting AI usage in all functions which enables Unicorns while maintaining a verifiable information security posture. Application Security
- Build and scale defensive security tooling that enables teams to shift-left and safeguard themselves and their work products, from emergent threats including software supply chain security, advanced security hunting, and advanced foreign actors.
- Lead cross-functional efforts to safeguard production infrastructure, cloud platforms, and mission-critical systems against advanced cyber threats, ensuring resilience, regulatory adherence, and alignment with strategic business objectives.
- Build and lead a high-performing security engineering function responsible for securing Defense Unicorns' production environments and customer-facing platforms, including architecture, hardening, threat detection, and defensive controls across cloud, hybrid, and on-premise infrastructure.
- Champion automation of security processes to reduce mean time to detection and containment, and drive continuous improvement across security operations.
- Own the enterprise Governance, Risk, and Compliance (GRC) framework, setting policy standards, defining residual risk thresholds, and ensuring accountability across organizational units.
- Oversee the third-party risk management (TPRM) program and supply chain risk management aligned to NIST SP 800-161, providing final approval authority on technology investments with compliance implications.
- Report on cyber risk posture, program health, and compliance status to senior leadership on a regular cadence. Culture, Awareness & Communication
- Build and sustain a security-aware culture across the organization, one that treats security as mission-enabling, not mission-blocking.
- Lead enterprise security awareness and training programs, ensuring all Unicorns and contractors understand their role in maintaining the company's security posture.
- Advocate for risk-informed decision-making at every level, empowering teams to operate confidently within well-understood guardrails. Required
Requirements
- Adapt Defense Unicorns application security processes to the AI-native threat hunting realities. Operate and scale bug triage and/or bounty programs that are compatible with Open Source software practices and the trends in responsible disclosure.
- experience in cybersecurity, information assurance, or a related field, with demonstrated
- experience in a senior leadership or executive role.
- Deep, hands-on familiarity with CMMC Level 2
- experience leading a DoD contractor compliance program, including DFARS 252.204-7012, SPRS reporting, and SAM.gov obligations.
- Proven ability to lead, manage, and develop high-performing security and IT teams, including direct management of director-level reports. •
- Active CISSP, CISM, CCISO, or equivalent certification.
- Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or a related field; Master's degree preferred. Direct
- experience as a C3PAO assessor, CMMC Registered Practitioner, or third-party assessment participant.
- Familiarity with ITAR, EAR, and export control compliance in a DoD supply chain context. •
- Experience with cloud-native and hybrid environments and evaluating SaaS platforms against CMMC control requirements. •
- Experience with emerging AI governance frameworks and the intersection of AI tooling with security and compliance obligations.
- experience delivering technology programs across the federal market. What We Do
- We proudly support defense and civil agencies across the U.S. government and we work closely with the creators of leading-edge software solutions to deliver value to the mission-owner by improving the security and consumability of commercial software products. What We Work On Kubernetes
- Cloud Environments (AWS/GCP and Azure)
- Infrastructure-as-code (like Terraform/Pulumi)
- Building Kubernetes and cloud native applications
Benefits
- Direct strategy for security architecture and infrastructure protection at scale, setting the technical vision while empowering the Director of IT to implement.
- Full compensation packages are based on candidate experience.
- Compensation ranges are established using national benchmarking data and apply across all geographic locations within the United States.
- Remote - USA $260,000 — $300,000 USD Who We Are
- We share a vision of freedom and security for the advancement of progress and innovation.
- Our commitment to this vision, and to our mission-driven customers, means a commitment to speed, user
- Medical/Dental/Vision
- Premiums are 100% Company Paid
- Health Savings Account Life Insurance
- Disability Insurance Financial:
- 401k Retirement Plan
- Home Office Budget Leave:
- We offer all full-time Unicorns Flexible Time Off (FTO) plus all Federal Holidays, one week for Thanksgiving, and two weeks for Christmas and New Year’s
- Paid Parental Leave Learning:
Additional details
- The Chief Information Security Officer (CISO) is the executive leader responsible for Defense Unicorns' enterprise-wide information technology and security strategy, governance, and risk posture.
- Reporting directly to the CEO and working in close partnership with senior leadership, the CISO owns the full security function, including direct oversight of the Director of Security Compliance and the Director of Information Technology.
- This is a mission-critical leadership role at the intersection of national security, defense technology, and enterprise IT.
- The CISO ensures that Defense Unicorns can pursue and execute DoD and federal contracts confidently, with a security program that is not only audit-ready but genuinely resilient.
- Equally, the CISO provides executive direction over the information technology function, overseeing corporate infrastructure, systems, networks, and the technology platforms that enable our Unicorns to operate effectively and securely at scale.
- The right person brings both the technical credibility to earn trust with engineers and operators, and the executive presence to advise leadership and represent the company's security and technology posture to customers, partners, and government stakeholders.
- As the organization scales, the CISO will be the architect of a security culture that is embedded, not bolted on, enabling the mission rather than impeding it.
- This commitment to “The Unicorn Experience” is non-negotiable.
- This means not only governing risk and compliance, but ensuring the IT foundation beneath the business is modern, resilient, and capable of supporting a fast-growing defense technology company operating in highly sensitive environments.
- This dual ownership of security and IT is intentional: at Defense Unicorns, protecting the mission and enabling the workforce are not separate problems, they require a unified leader who can hold both. Direct Reports