Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
Chief Information Security Officer image - Rise Careers
Job details

Chief Information Security Officer

At TreviPay, we believe loyalty begins at the payment. Thousands of sellers use our global B2B payments and invoicing network to provide choice and convenience to buyers, open new markets and automate accounts receivables. With integrations to top eCommerce and ERP solutions and flexible trade credit options, TreviPay brings 40 years of experience serving leaders in manufacturing, retail and transportation.  

 

Every day, TreviPay employees are challenged and empowered in a supportive, collaborative, entrepreneurial environment. 


We are looking for an experienced, hands-on information security practitioner to lead our cybersecurity team. You will have leadership responsibility for protecting our SaaS platform, infrastructure, and customer data while enabling business growth and innovation. This position requires a talented and driven individual who uniquely combines leadership skill, information security expertise, and is a true technologist who likes to roll up their sleeves and work with architects and engineers to help launch software solutions that are secure by design. This position reports to the Chief Product and Technology Officer (CPTO).

 

Responsibilities:

Strategic Leadership

o   Develop and execute a comprehensive information security strategy aligned with business objectives

o   Lead the evolution of our security program to address emerging threats and regulatory requirements

o   Build and maintain relationships with key stakeholders, including board members, executives, clients, engineering leaders, and regulatory bodies

o   Provide regular security status updates and metrics to the board and executive team

 

Team Leadership

o   Continue to evolve and grow TreviPay’s talented and driven information security team through training andcoaching. Attract high performing security professionals to join the team as needed.

o   Help foster a security-first culture throughout the organization

o   Manage security budget

 

Security Operations & Architecture

o   Lead offensive security and security operations to including, incident response, threat detection, vulnerability management, and forensics

o   Direct the design, implementation, and maintenance of our security architecture

o   Ensure the security of our cloud infrastructure and SaaS platform

o   Stay current with cybersecurity threats and mitigation best practices. Work with the executive team to make strategic decisions related to the company’s security posture and investment

o   Work closely with product management and engineering teams to build a deep understanding of the TreviPay product suite and technology infrastructure. Use this understanding to influence priorities and define information security requirements.

o   Lead evaluation, adoption, and use of security tools and technologies

o   Own the execution of annual PCI-DSS and ISO-27001 certifications to include vendor management and project management of the process.

o   Ensure that data privacy requirements are understood and included in all solutions

Work with engineering leaders to define secure coding practices, standards and training

 

Compliance & Risk Management

o   Maintain compliance with PCI DSS, ISO 27001, NIST, and other relevant standards

o   Oversee security risk assessments and implement risk mitigation strategies

o   Develop and maintain security policies, procedures, and standards

o   Ensure compliance with financial services regulations and data protection laws

 

Requirements:

o   10+ years of combined engineering and information security experience

o   3+ years of leadership experience

o   Bachelor’s degree in Computer Science, Information Systems, or equivalent work experience.

o   One or more of the following certifications: Certified Ethical Hacker (CEH), Certified Information Systems Security Professional (CISSP), or Certified Information Security Manager (CISM)

o   A deep understanding of and experience with one or more of the following compliance frameworks: NIST, PCI-DSS, ISO 27001, SOC 2.

o   An empowering leadership style with a proven ability to build positive, energized teams

o   Excellent judgement and critical thinking skills. Able to weigh multiple and often conflicting constraints and make rapid, logical decisions in a fast-moving company with complex financial products

o   Direct experience with threat hunting, penetration testing, and red teaming

o   Executive-level verbal and written communications skills that can synthesize technical issues into concise points


Why you will love working at TreviPay

·       Competitive salary

·       Paid parental leave

·       Generous paid time off

·       Medical, dental, vision, FSA, Life/AD&D, long and short term disability

·       401K matching

·       Employee referral program

 

At TreviPay we believe:

·       in saying yes to unique and challenging requirements

·       empowered team members are creative team members

·       our products make the customer’s day just a little bit better

·       work/life balance makes us all more effective

 

TreviPay is an Equal Opportunity and Affirmative Action Employer.  We welcome all veterans and disabled applicants.

 

Individuals with disabilities will be provided reasonable accommodation to participate in the job application and/or interview process. Please contact Recruiting@trevipay.com to request an accommodation.

TreviPay Glassdoor Company Review
4.0 Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon Glassdoor star icon
TreviPay DE&I Review
No rating Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon
CEO of TreviPay
TreviPay CEO photo
Brandon Spear
Approve of CEO

Average salary estimate

$135000 / YEARLY (est.)
min
max
$120000K
$150000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Chief Information Security Officer, TreviPay

At TreviPay, we’re on the lookout for a Chief Information Security Officer who is not just experienced but ready to roll up their sleeves and take charge of our cybersecurity efforts. With our established B2B payments and invoicing network, safeguarding our SaaS platform, customer data, and infrastructure is vital for enabling business growth and innovation. As the Chief Information Security Officer, you’ll develop and execute a comprehensive security strategy that aligns with our goals while leading our talented cybersecurity team. Your hands-on approach will be crucial in fostering a security-first culture, overseeing security operations, and ensuring compliance with key industry standards like PCI DSS and ISO 27001. You will collaborate closely with engineers and product management to promote secure coding practices and influence system designs that are inherently secure. In this role, you’ll also maintain relationships with key stakeholders both within and outside the company, providing valuable insights through regular security status updates. TreviPay values creativity and unique problem-solving, so your experience in threat hunting and risk assessments will directly contribute to our mission. If you’re ready for a challenge in a supportive, collaborative environment where innovation is encouraged, we’d love to hear from you!

Frequently Asked Questions (FAQs) for Chief Information Security Officer Role at TreviPay
What are the main responsibilities of the Chief Information Security Officer at TreviPay?

The Chief Information Security Officer (CISO) at TreviPay is responsible for developing and executing a comprehensive information security strategy that aligns with business objectives. This includes leading the evolution of the security program to meet emerging threats, managing security operations like incident response and threat detection, and ensuring compliance with pivotal industry standards such as PCI DSS and ISO 27001.

Join Rise to see the full answer
What qualifications are required for the Chief Information Security Officer position at TreviPay?

To be considered for the Chief Information Security Officer role at TreviPay, candidates should have over 10 years of combined experience in engineering and information security, with at least 3 years in a leadership capacity. A Bachelor’s degree in Computer Science or Information Systems, along with relevant certifications such as CISSP, CEH, or CISM, is preferred.

Join Rise to see the full answer
How does TreviPay foster a security-first culture under the Chief Information Security Officer?

At TreviPay, the Chief Information Security Officer plays a pivotal role in fostering a security-first culture by attracting and developing top-tier security professionals, providing ongoing training, and ensuring that information security is a shared responsibility across all teams and levels of the organization.

Join Rise to see the full answer
What tools and technologies will the Chief Information Security Officer at TreviPay utilize?

The Chief Information Security Officer at TreviPay will lead the evaluation, adoption, and utilization of various security tools and technologies aimed at enhancing our overall security architecture and addressing compliance requirements. This includes tools for threat detection, vulnerability management, and incident response.

Join Rise to see the full answer
What are the growth opportunities for the Chief Information Security Officer at TreviPay?

The Chief Information Security Officer role at TreviPay offers numerous growth opportunities, such as leading strategic initiatives to adapt to evolving regulatory landscapes and cyber threats, mentoring a talented security team, and playing a significant role in shaping the overall security posture while driving innovation and business growth.

Join Rise to see the full answer
Common Interview Questions for Chief Information Security Officer
Can you describe your experience with cybersecurity frameworks as the Chief Information Security Officer?

As a Chief Information Security Officer, it's crucial to have hands-on experience with compliance frameworks such as NIST, PCI-DSS, and ISO 27001. Discuss specific projects where you implemented these frameworks to enhance security posture and ensure compliance, along with the outcomes realized.

Join Rise to see the full answer
How do you prioritize security initiatives at TreviPay?

Prioritizing security initiatives involves balancing business objectives with risk management. Demonstrate your methodical approach to assessing risks, aligning projects with business goals, and engaging stakeholders to build a consensus before implementing major initiatives.

Join Rise to see the full answer
What strategies would you employ to develop a security-first culture at TreviPay?

An effective strategy for cultivating a security-first culture includes instituting regular training, fostering an open communication environment, and developing strong interdepartmental relationships. Describe any successful programs you've previously implemented to engage and empower employees in prioritizing security.

Join Rise to see the full answer
How do you handle incident response and threat detection?

In this role, handling incidents involves establishing a clear process for incident response, including identification, containment, and eradication of threats. Share your experience with developing playbooks and leveraging analytical tools for detecting potential security breaches.

Join Rise to see the full answer
Can you explain a challenging security project you've led and its impact?

Discussing a challenging project you've led provides insight into your problem-solving abilities and leadership skills. Focus on a specific project where you faced unexpected challenges and how your solution had a significant positive impact on the organization’s security posture.

Join Rise to see the full answer
What is your approach to maintaining compliance with financial services regulations?

Maintaining compliance requires a thorough understanding of regulations and proactive engagement with relevant frameworks. Explain your systematic approach to auditing, assessment, policy development, and regular stakeholder communication to ensure consistent compliance.

Join Rise to see the full answer
How do you stay informed about emerging cybersecurity threats?

Staying updated on emerging threats is vital as the technology landscape constantly evolves. Discuss the resources you utilize, including industry publications, cybersecurity conferences, and networking with other professionals, to ensure you’re aware of the latest threats.

Join Rise to see the full answer
Describe your experience with leading a cybersecurity team.

Leading a cybersecurity team is about empowering team members while guiding them towards shared goals. Share your leadership style and how you’ve previously attracted talent, managed team dynamics, and fostered an environment of continuous improvement.

Join Rise to see the full answer
What role do you see for technology in enhancing security at TreviPay?

Technology plays a crucial role in enhancing security; discuss how you plan to leverage advanced technologies like AI and machine learning in threat detection, response automation, and overall security architecture improvements to ensure TreviPay remains secure against evolving threats.

Join Rise to see the full answer
How would you approach vendor management in terms of security compliance?

Vendor management involves assessing third-party risks and establishing clear policies and protocols to ensure compliance. Describe your experience with vendor assessments, contract negotiations, and continuous monitoring of vendor security practices to safeguard the organization.

Join Rise to see the full answer
Similar Jobs
Photo of the Rise User
Posted 8 days ago

Join TreviPay as a Financial Operations Analyst II and leverage your analytical skills in a dynamic finance environment.

Photo of the Rise User
Posted 5 days ago

Join TreviPay as a Customer Support Representative and help improve B2B payment experiences for clients worldwide.

Photo of the Rise User
Posted 4 days ago

Be a pivotal force in shaping cloud security at Qiddiya Investment Company as a Manager - Cloud Security.

Photo of the Rise User

Join Aviva as a Cybersecurity Incident Response Analyst, where your expertise will play a crucial role in protecting digital assets in a collaborative environment.

Photo of the Rise User
Customer-Centric
Rapid Growth
Diversity of Opinions
Reward & Recognition
Friends Outside of Work
Inclusive & Diverse
Empathetic
Feedback Forward
Work/Life Harmony
Casual Dress Code
Startup Mindset
Collaboration over Competition
Fast-Paced
Growth & Learning
Open Door Policy
Rise from Within
Maternity Leave
Paternity Leave
Flex-Friendly
Family Coverage (Insurance)
Medical Insurance
Dental Insurance
Vision Insurance
Mental Health Resources
Life insurance
Disability Insurance
Health Savings Account (HSA)
Flexible Spending Account (FSA)
401K Matching
Paid Holidays
Paid Sick Days
Paid Time-Off

Join a leading fintech firm as an Azure Infrastructure Engineer where you'll design and manage cloud solutions for high-impact applications.

Photo of the Rise User

Join Bazaarvoice as a Technical Services Engineer and leverage your technical skills to improve client product integrations and support.

Photo of the Rise User
Posted 11 days ago

Become a vital member of the healthcare team at Oak Street Health as a Medical Scribe, contributing to improved patient care documentation and outcomes.

Photo of the Rise User
Posted 6 days ago

COLSA Corporation is looking for a Senior Network/Computer Systems Analyst to enhance network operations and IT project management for the Armament Directorate.

Photo of the Rise User
Inclusive & Diverse
Rise from Within
Mission Driven
Diversity of Opinions
Work/Life Harmony
Friends Outside of Work
Empathetic
Feedback Forward
Take Risks
Emails over Meetings
Collaboration over Competition
Growth & Learning
Medical Insurance
Paid Time-Off
Maternity Leave
Mental Health Resources
Equity
Learning & Development
Health Savings Account (HSA)
Life insurance
Disability Insurance
Flexible Spending Account (FSA)
Conferences Stipend
Some Meals Provided

Become a vital part of SAP's Incident Response team as a Risk Coordinator, enhancing security risk strategies in a collaborative culture.

Photo of the Rise User

As a Senior Associate in IT Operations and Support at Grant Thornton, you will lead crucial network services that empower a global professional services team.

TreviPay is guided by a belief in continuous improvement through disruptive innovation. Sustaining this high-performance culture means putting our people first, and keeping employee success at the forefront of our mission. At TreviPay, we work to ...

40 jobs
MATCH
Calculating your matching score...
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, on-site
DATE POSTED
February 24, 2025

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!
LATEST ACTIVITY