Head of Information Security & IT
Brooklyn, New York, United States·Posted today
climatetechcybersecuritygo
<p><strong>Overview</strong></p> <p>Chronograph was founded to bring next-generation technology to private capital markets. Through our suite of cloud-based analytics and data management solutions, we help many of the world's largest and most sophisticated venture capital, private equity, and credit funds understand their investment performance in unprecedented detail, with over 258,000 private companies and 15,000 private capital funds monitored via our solution suite.</p> <p>At Chronograph, we get to go "behind the scenes" and work directly with investors who are driving some of the most impactful changes across high growth start-ups, global infrastructure and renewable energy, growth equity, and all other private capital strategies. The firm is backed by Sixth Street Growth, Summit Partners, Carlyle AlpInvest, and Nasdaq Inc., and has seen continuous rapid growth since its founding in 2016. Our client base today includes hundreds of investors and asset managers monitoring more than $5.9 trillion in invested capital with 8 of the 10 largest GPs and 5 of the 10 largest LPs using Chronograph. </p> <p><strong>The Opportunity</strong></p> <p>Bring your expertise to a highly collaborative, creative, and innovative team with a market-leading technology product suite. We hire technologists with a broad set of technical skills who are eager to solve a wide range of challenges. The thread that unites us at Chronograph is a focus on delivering great, secure products that drive value for our clients.</p> <p>We are looking for a Head of Information Security & IT to own Chronograph's security strategy, architecture, and execution as we continue to scale.</p> <p>This is a hands-on leadership role spanning security strategy, governance, technical execution, and external assurance. We expect you to continuously strengthen our information security program and certifications while remaining technically close enough to investigate issues, prototype solutions, and implement controls where appropriate.</p> <p>The security landscape is changing rapidly, particularly as AI expands both attacker capabilities and the attack surface of modern software. We want someone who follows emerging threats closely, continuously reassesses whether our security posture remains appropriate, and responds to credible new threats with urgency.</p> <p>Our ideal candidate has a strong sense of ownership, excellent judgment, and a bias toward action. You are equally comfortable defining security strategy, representing it with sophisticated clients and external stakeholders, and getting technically involved when that is the best way to move an issue forward.</p> <p><strong>As Head of Information Security & IT at Chronograph, you will:</strong></p> <p><strong>Leadership & Strategy</strong></p> <ul> <li>Own Chronograph's information security program, strategy, architecture, and roadmap</li> <li>Serve as Chronograph's senior security leader in strategic client, partner, and external engagements</li> <li>Lead and mentor a small team of senior security, compliance, and IT practitioners</li> <li>Continuously assess our security posture and prioritize pragmatic, high-impact improvements</li> <li>Communicate material security risks, priorities, and tradeoffs clearly to executive leadership</li> <li>Develop a deep understanding of the business, product, and infrastructure to make sound security decisions</li> </ul> <p><strong>Technical Leadership</strong></p> <ul> <li>Develop technical approaches for security initiatives, validate assumptions, and build proofs of concept where useful</li> <li>Implement security controls directly where appropriate, while partnering with engineering and infrastructure teams on more complex efforts</li> <li>Maintain sufficient technical depth across cloud, application architecture, identity, logging, and security tooling to investigate issues and guide implementation</li> <li>Evaluate and configure security tooling and automation</li> </ul> <p><strong>Application & Cloud Security</strong></p> <ul> <li>Own the security posture and requirements for our cloud and application environments, partnering with infrastructure and engineering teams on implementation</li> <li>Lead vulnerability management and threat modeling programs, hands-on where needed</li> <li>Partner with engineering on secure development practices and application security architecture</li> <li>Own and improve application security tooling, including SAST, SCA, DAST, SOAR, secrets detection, and infrastructure-as-code scanning</li> <li>Prioritize vulnerabilities based on exploitability and business risk</li> </ul> <p><strong>AI Security & Emerging Threats</strong></p> <ul> <li>Own security strategy for Chronograph's use of AI internally and within our products</li> <li>Secure employee use of AI tools, agents, models, and integrations, including controls around sensitive data, third-party services, and agent permissions</li> <li>Threat-model AI-enabled functionality, including prompt injection, data exfiltration, insecure tool use, excessive agency, and supply-chain risks</li> <li>Track developments in offensive and defensive AI security and quickly assess their relevance to Chronograph</li> <li>Evaluate AI-enabled security tooling and automation where it can improve our defensive capabilities</li> </ul> <p><strong>Corporate Security</strong></p> <ul> <li>Own our detection and response stack, including SIEM, EDR, WAF, and DLP, as well as the automation routing alerts between them</li> <li>Lead threat detection and incident response strategy, including security partner relationships</li> <li>Set direction for corporate IT, identity, endpoint management, and employee technology, with the IT team owning day-to-day operations</li> </ul> <p><strong>GRC & Compliance</strong></p> <ul> <li>Own Chronograph's SOC 1, SOC 2, ISO 27001, and broader security assurance strategy, with the GRC team managing day-to-day audit and evidence processes</li> <li>Ensure our certifications, policies, risk management processes, and technical controls operate as a coherent information security program</li> <li>Set direction for our annual risk assessment, risk register, policy lifecycle, and third-party risk program</li> <li>Partner closely with compliance, sales, and customer teams on security due diligence, customer requirements, and strategic client engagements</li> <li>Represent Chronograph's controls, certifications, and approach to risk with authority and credibility to customers, prospects, and auditors</li> </ul> <p><strong>You will be successful in this role if you have:</strong></p> <ul> <li>7+ years of information security experience, including meaningful hands-on technical experience and increasing ownership of security programs</li> <li>Strong technical judgment and the ability to investigate problems, develop solutions, build proofs of concept, and implement controls when appropriate</li> <li>Broad experience across cloud and application security, identity, vulnerability management, and detection and response</li> <li>Experience owning or materially leading an information security program, including risk management, policies, controls, and security roadmap, leveraging frameworks such as NIST, CIS, or GDPR.</li> <li>Experience leading SOC1, SOC 2, ISO 27001, or comparable security assurance and certification programs</li> <li>Experience representing an organization's security controls, certifications, and risk posture with sophisticated enterprise customers and auditors</li> <li>Strong security instincts and curiosity about emerging threats, including the rapidly evolving implications of AI</li> <li>Strong executive communication skills and the ability to translate technical controls, risks, and security strategy into clear business language</li> </ul> <p>Even if you do not meet all criteria, we would still encourage you to apply or get in touch! Chronograph offers an entrepreneurial environment where you will be able to proactively identify opportunities to develop and strengthen our team. </p> <p><strong>Why Join Chronograph?</strong></p> <p>We value creativity, open communication, cutting edge technology, striving for excellence in all things – and having fun along the way. We want you to be happy here for the long-term.</p> <p>We offer:</p> <ul> <li>Competitive salary </li> <li>Equity Participation</li> <li>401k</li> <li>Unlimited and flexible vacation</li> <li>Generous health benefits</li> <li>Team week events in HQ (Brooklyn, NY) three times annually for all employees</li> <li>Fully-paid parental leave</li> <li>...and more! </li> </ul> <p>Chronograph is committed to promoting a diverse and inclusive culture, and we welcome applicants from all backgrounds. If you’re a passionate team player who wants to have an outsized impact on a diverse and dynamic team, we’d love to hear from you!</p><div class="content-pay-transparency"><div class="pay-input"><div class="title">Salary Range (dependent on experience)</div><div class="pay-range"><span>$215,000</span><span class="divider">—</span><span>$250,000 USD</span></div></div></div>