Chief Information Security Officer (CISO)
Obsidian Security
- Location
- Palo Alto, CA
- Work model
- On-Site
- Level
- Mid
- Salary
- $300k/yr
- Posted
- 1h ago
Skills
About this role
Obsidian Security is the leading SaaS security platform, trusted by global enterprises like Snowflake, T-Mobile, and Algolia. We protect 200+ organizations across North America, Europe, the Middle East, Southeast Asia, Australia, and New Zealand, including many of the world’s largest Fortune 1000 and Global 2000 companies.
Founded in 2017 and backed by top investors like Greylock, Obsidian was built to close a critical gap: securing SaaS apps where business happens—Microsoft 365, Salesforce, and hundreds more. The company does this by offering a complete SaaS security platform to reduce risk, detect and respond to threats, and prevent breaches at the source. Obsidian was built by leaders who redefined endpoint and identity security at CrowdStrike, Okta, Cylance, and Carbon Black. Now, they’re transforming how SaaS is secured.
With AI driving rapid SaaS growth and complexity, agentic AI tools gain privileged access to sensitive data through integrations, creating new risks most security tools miss. Obsidian uniquely detects anomalous OAuth token activity and manages integration risks. Major announcements are on the horizon. Recognizing that SaaS security needs to evolve, Obsidian enables growing organizations to start with a lightweight, prevention-focused browser extension and expand coverage over time.
With global momentum, a growing partner ecosystem including SentinelOne, Databricks, and Google Cloud, and a major fundraise ahead, Obsidian is scaling rapidly toward long-term growth and IPO readiness.
The Role
The CISO will own Obsidian's internal security program end-to-end while serving as a visible security leader to our customers, partners, and the broader market. This role reports to the Chief Legal and Trust Officer.
Responsibilities
• Security Strategy & Executive Communication: Design and execute a global security strategy aligned with business growth objectives. Advise the board and executive leadership on critical cyber risk domains with clear, actionable mitigation plans.
• Cyber Risk Management: Own the cyber risk management program, including security risk assessments, third-party vendor reviews, and executive-backed mitigation initiatives targeting measurable risk reduction.
• Security Architecture, Engineering & Operations: Build and lead teams spanning product/application security, infrastructure protection, and security engineering. Oversee threat detection, vulnerability management (with SLA-based performance tracking), and incident response. Establish a guardrail-based controls model for cloud and container workloads.
• Product Security: Embed secure-by-design principles across engineering workflows, integrating security early and consistently throughout the SDLC, including secure coding standards, penetration testing, bug bounty programs, and security requirements for AI/ML components (model integrity, training data protection, prompt injection prevention, output validation).
• AI Security & Governance: Establish enterprise AI governance (acceptable use, data loss prevention for AI inputs, vendor risk assessments for third-party AI services). Build detection and response capabilities for AI-powered attack vectors. Drive adoption of AI and automation across the security function, including AI-assisted threat detection, automated incident response, and intelligent vulnerability prioritization.
• Cross-Functional Partnerships: Partner with Engineering and Product to embed security throughout the development lifecycle, AI/ML feature delivery, and infrastructure architecture decisions. Support Sales and TAM teams by participating in customer security reviews, responding to questionnaires, and enabling the team to speak confidently about Obsidian’s security posture.