← Back to job listings
HI
Chief Information Security Officer
Hippo Insurance · Austin, United States
About The Role
Join Hippo, a rapidly growing insurtech company, as the Chief Information Security Officer (CISO). In this high-visibility leadership role, you will be responsible for leading cybersecurity strategy, security operations, and governance, risk, and compliance across the enterprise. You will protect Hippo's systems, data, and customers against an evolving threat landscape while ensuring the company meets its regulatory and compliance obligations as a publicly traded, multi-state insurance carrier. You will report to the Chief Technology Officer and have a significant impact on the company's success.
- Develop and execute Hippo's enterprise cybersecurity strategy, aligned with business risk appetite and regulatory requirements.
- Build and lead the security operations function, including threat detection, incident response, vulnerability management, and threat intelligence.
- Own Hippo's SOC 2 program end-to-end, including control design, evidence collection, readiness assessments, and auditor engagement.
- Experience managing third-party and vendor cybersecurity risk programs
- Proven ability to present cybersecurity risk and incident information to boards of directors, audit committees, and regulators
- Excellent cross-functional leadership skills with a track record of partnering effectively with Legal, Finance, Internal Audit, and Engineering
- End-to-end ownership of a SOC 2 program, including control design, audit preparation, and remediation
- 10+ years of progressive experience in cybersecurity or information security, with at least 5 years in a senior security leadership role (CISO, VP of Security, or Head of Information Security)
- Strong GRC background with experience maintaining risk registers, policy frameworks, and control libraries
- Experience at a regulated, publicly traded company, including direct involvement in SOX audit cycles
- Experience with cybersecurity regulations in a regulated industry (financial services, insurance, or healthcare preferred)
- Track record of building and managing security operations capabilities
- Experience managing cybersecurity programs across multi-entity corporate structures1
- Background in security engineering or application security in addition to GRC and security operations
- Relevant certifications such as CISSP, CISM, CRISC, or CISA
- Familiarity with privacy frameworks and data protection requirements (CCPA/CPRA, state breach notification laws)
- Experience in the insurance, Insurtech, or fintech industry
This is an external listing. JobSpring does not represent or verify the employer. Report this listing
JobSpring