Chief Information Security Officer (CISO)

Remote Full-time
At Swyfft, we're reshaping the way home insurance and commercial package products are priced and bound. We've created an insurance experience that's smart, instant, and designed to deliver unparalleled customer service. Our focus on lightning-fast quotes and seamless claims servicing is powered by cutting-edge technology and an Agent and Customer-centric approach that sets us apart in the industry. Joining Swyfft means becoming part of a dynamic team of forward-thinkers who thrive on moving fast and delivering exceptional products. We pride ourselves on fostering an environment where creativity and positive energy thrive. As we continue to grow and expand, we're on the lookout for experienced professionals like you to join us in transforming the insurance landscape. If you're passionate about leveraging technology to provide the best customer service experience and are ready to be a part of our journey, we welcome you to explore opportunities at Swyfft! About the Position: We're looking for a CISO who can do two things exceptionally well: build and run a robust security compliance program AND do hands-on technical security work. This isn't a role where you'll spend 100% of your time on PowerPoint and vendor questionnaires (though there will be some of that). You'll be reviewing architecture, working with our development team on secure design, and making real technical decisions. The immediate challenge: We're transitioning from a limited exemption to full NYDFS (23 NYCRR 500) compliance, with our first full certification due April 2026. You'll be building our compliance program while also establishing long-term security practices that actually make us more secure, not just check regulatory boxes. The Reality of Year 1 We want to be transparent: The first year will be challenging. You'll be: • Building the TPSP governance program from scratch (we have a lot of vendors) • Getting us ready for our first full NYDFS certification (April 2026) • Overseeing MFA implementation across thousands of users • Documenting and formalizing security practices we're already doing It's going to be a mix of rewarding technical work and necessary compliance grinding. After Year 1, the job shifts more toward proactive security work, architecture reviews, and continuous improvement. If you want a CISO role where you only do compliance paperwork, this isn't it. If you want a role where you only do technical security with zero regulatory work, this also isn't it. But if you want to build a security program that's both compliant AND actually makes the company more secure - and you want to stay technical while doing it - this might be perfect. • This position is a 100% remote U.S. based opportunity that can be based in one of the following states only: AL, AZ, FL, GA, KY, LA, MA, MO, NC, NJ, NY, OH, OR, PA, SC, TX, UT, VA, WA, WI. Some travel for day-to-day work, team meetings, and training will be required. Key Responsibilities: (What you'll be asked to do) • Security Program & Compliance (40-50% in Year 1, 30% ongoing) • Own Swyfft's cybersecurity program end-to-end, including NYDFS compliance • Build and manage our Third-Party Service Provider (TPSP) security governance program (vendor inventory, risk assessments, security questionnaires, ongoing monitoring) • Conduct annual risk assessments and coordinate penetration testing • Create and maintain security policies, incident response plans, and business continuity documentation • Prepare annual board reporting and regulatory certifications • Manage security awareness training program • Coordinate incident reporting to NYDFS when required (72-hour notification window) • Technical Security Work (50-60% in Year 1, 70% ongoing) • Oversee implementation of multi-factor authentication (MFA) across our web platform (currently in planning phase) • Review and improve security architecture for our C#/.NET applications and infrastructure • Work directly with engineering teams on secure development practices and code review for security issues • Manage vulnerability assessments and coordinate remediation with engineering • Design and implement security controls and monitoring capabilities • Evaluate and implement security tooling (SIEM, vulnerability scanning, etc.) • Respond to security incidents and conduct post-incident analysis • Review API security, authentication/authorization patterns, and data protection controls The Successful Candidate: (What we're looking for) • Pragmatic security mindset: You understand the balance between security and business needs • Self-starter: You can build a program from the ground up with limited hand-holding • Technical credibility: Engineers respect your technical opinions and will listen to your guidance • Efficient with compliance work: You can motor through vendor questionnaires and policy documentation without it consuming your life • Clear communicator: You can explain security risks and recommendations to non-security people without drowning them i

Apply tot his job

Apply To this Job
Apply Now

Similar Opportunities

Experienced Registered Behavior Technician for In-Home ABA Therapy - Atlanta, GA

Remote Full-time

Immediate Hiring: Experienced Registered Behavioral Technician (RBT) for Clinic-Based ABA Therapy Services

Remote Full-time

Experienced Registered Behavioral Technician (RBT) - ABA Therapy for Children with Autism Spectrum Disorder

Remote Full-time

Experienced Registered Nurse - Telehealth: Providing Remote Care Coordination and Patient Support

Remote Full-time

Experienced Substitute Teacher for Riverside County Schools - Join Scoot Education's Innovative Team

Remote Full-time

Experienced Substitute Teacher for San Bernardino County - Flexible Schedules & Competitive Pay

Remote Full-time

Experienced School Year Instructional Coach for High-Dosage Tutoring Programs in Edgewater Park, NJ

Remote Full-time

Experienced School Year Tutor for K-8 Students in Math and Literacy - Mickleton, NJ

Remote Full-time

Experienced Secondary Social Studies Teacher for Kansas - Flexible Hybrid Remote Arrangement

Remote Full-time

USPS Office Helper

Remote Full-time

Senior Manager, Commercial Sales Operations

Remote Full-time

**Experienced Customer Service Representative – Remote Work Opportunity with arenaflex**

Remote Full-time

Experienced Remote Live Chat Support Agent – Delivering Exceptional Customer Experiences through Digital Platforms at arenaflex

Remote Full-time

[Remote] Audit & Assurance Manager / Senior Manager (Remote: Open to residents of FL, GA, NC, SC & TX)

Remote Full-time

Experienced Virtual Customer Support Specialist for Travel Industry Leader – Delivering Exceptional Travel Experiences through Remote Work Opportunities

Remote Full-time

Managing CSR/Dispatcher

Remote Full-time

[Remote] Senior Digital Experience Data Architect

Remote Full-time

Patient Service Representative

Remote Full-time

**Experienced Remote Chat Support Specialist – Deliver Exceptional Customer Experience with arenaflex**

Remote Full-time

**Experienced Customer Success Manager – Driving Long-Term Value and Growth for blithequark Customers**

Remote Full-time
← Back to Home