Chief Information Security Officer (CISO)
Obsidian Security · Palo Alto, CA
- Senior
- Full-time
- $300,000 – $380,000
- Posted 2026-09-04
- Confirmed live on 25 September 2026
Job description
Obsidian Security is a global leader in cyber security protecting the SaaS and non-human identity layer modern enterprises run on — from Salesforce and Snowflake to the AI agents now deployed inside them. The Obsidian Security platform gives unified visibility into every human and machine identity, app, and integration across their SaaS estate, detects identity-based and supply chain attacks in real time, and enforces least-privilege access before it's exploited. Trusted by major Fortune 500 companies T-Mobile, Workday, Snowflake, and S&P Global, Obsidian ranked No. 95 on the 2025 Deloitte Technology Fast 500™, growing nearly 1000% from 2021–2024 — helping CISOs turn an unmonitored attack surface into one they can govern with confidence. Obsidian has also been recognized by Forbes as America's Best Startup Employers in 2026.
In August 2026, Obsidian raised $85 million in Series D financing led by Crescent Cove Advisors, with participation from existing investors including Greylock Partners, Menlo Ventures, Norwest Venture Partners, IVP, Wing Ventures, and GV — pushing Obsidian's valuation to $1.1 billion, crossing into unicorn status. Obsidian is using the funding to deepen its R&D in agentic AI security and extend its platform as the standard for governing what AI agents can access and do inside third-party applications.
With global momentum, a growing partner ecosystem including SentinelOne, Databricks, and Google Cloud, and fresh capital from its Series D behind it, Obsidian is scaling rapidly toward long-term growth and IPO readiness.
The Role
The CISO will own Obsidian's internal security program end-to-end while serving as a visible security leader to our customers, partners, and the broader market. This role reports to the Chief Legal and Trust Officer.
Responsibilities
• Security Strategy & Executive Communication: Design and execute a global security strategy aligned with business growth objectives. Advise the board and executive leadership on critical cyber risk domains with clear, actionable mitigation plans.
• Cyber Risk Management: Own the cyber risk management program, including security risk assessments, third-party vendor reviews, and executive-backed mitigation initiatives targeting measurable risk reduction.
• Security Architecture, Engineering & Operations: Build and lead teams spanning product/application security, infrastructure protection, and security engineering. Oversee threat detection, vulnerability management (with SLA-based performance tracking), and incident response. Establish a guardrail-based controls model for cloud and container workloads.
• Product Security: Embed secure-by-design principles across engineering workflows, integrating security early and consistently throughout the SDLC, including secure coding standards, penetration testing, bug bounty programs, and security requirements for AI/ML components (model integrity, training data protection, prompt injection prevention, output validation).
• AI Security & Governance: Establish enterprise AI governance (acceptable use, data loss prevention for AI inputs, vendor risk assessments for third-party AI services). Build detection and response capabilities for AI-powered attack vectors. Drive adoption of AI and automation across the security function, including AI-assisted threat detection, automated incident response, and intelligent vulnerability prioritization.
• Cross-Functional Partnerships: Partner with Engineering and Product to embed security throughout the development lifecycle, AI/ML feature delivery, and infrastructure architecture decisions. Support Sales and TAM teams by participating in customer security reviews, responding to questionnaires, and enabling the team to speak confidently about Obsidian’s security posture. Collaborate with Marketing to develop security-focused content, support thought leadership positioning and inform messaging around trust and security.
• Customer Trust & External Presence: Serve as the executive-level security contact for prospects and customers during sales cycles, audits, and security reviews. Represent Obsidian in industry forums and public engagements to build market credibility.
• Team Leadership & Budget: Recruit, mentor, and retain a high-performing security organization. Own the security budget with precise, on-target forecasts.
• M&A Due Diligence: Assess the security posture, risk exposure, and integration readiness of prospective acquisition targets.
Qualifications
• 15+ years in information security, with 5+ years in a senior leadership role (CISO, VP/Deputy CISO, Sr. Director of Security, or equivalent).
• Deep experience building and scaling security teams across product security, security architecture, infrastructure protection, and enterprise risk management.
• Strong track record securing cloud-native SaaS environments, including container-based workloads and next-generation security tooling (endpoint protection, CI/CD-integrated code scanning
Prepare for the interview
Nothing collected for this employer yet. The Blind 75 is what technical screens draw from; practise it here, with a coach, in Java or Python.
More at Obsidian Security
- Senior Product Security Engineer – Taiwan · Taipei, Taiwan
- Principal Solutions Engineer - APAC · Remote
- AI Security Engineer - Taiwan · Taipei, Taiwan
- Senior Threat Research Engineer – Taiwan · Taipei, Taiwan
- Senior Customer Marketing Manager · US Remote
- Lead IT Systems Engineer · Palo Alto, CA
- Head of GTM Enablement · Remote - US
- Software Engineer - AI Security Product · Palo Alto, California, USA