Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
JobTailor Logo

See all jobs on JobTailor

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
MasterControl Japan

Chief Information Security Officer – CISO

MasterControl Japan

. Define and execute the company's enterprise security strategy, aligned with business objectives and compliance obligations (including FedRAMP).

Posted 7/21/2026full-timeSalt Lake City • Utah • 🇺🇸 United StatesLeadWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates expertise in defining and executing enterprise security strategies, managing risk assessment programs, and ensuring compliance with frameworks such as FedRAMP and GDPR. Proven ability to lead incident response efforts and integrate security into AI-driven engineering workflows.

Highest-signal resume keywords
Enterprise Security StrategyRisk Assessment ProgramsCloud Security (AWS, Azure)Compliance Frameworks (FedRAMP, SOC 2, ISO 27001)Incident Response Leadership

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
Risk ManagementData ProtectionSecurity GovernanceAI GovernanceSecurity Incident ResponseVulnerability ManagementPenetration TestingThreat IntelligenceSecurity Policy DevelopmentSecure Development Practices
Soft Skills
Strong CommunicationCross-Functional CollaborationExecutive ReportingCustomer EngagementTeam Leadership
Tools & Technologies
SIEMMonitoring ToolsManaged Detection/ResponseCloud InfrastructureAI/LLM Tooling
Certifications & Qualifications
FedRAMPSOC 2ISO 27001
Industry Keywords
Data PrivacyGDPRRisk RegisterSecurity PostureCompliance Obligations

Tech Stack

Tools & technologies
AWSAzureCloudCyber SecuritySDLC

About the role

Key responsibilities & impact
  • Define and execute the company's enterprise security strategy, aligned with business objectives and compliance obligations (including FedRAMP).
  • Own security governance, policies, standards, and risk management practices across the organization.
  • Embed security-by-design principles across systems, applications, cloud infrastructure, and engineering workflows.
  • Set policy for access control, data protection, and secure development practices, partnering with Engineering to embed requirements into the SDLC without becoming a bottleneck.
  • Own data privacy and residency requirements across the regions where we operate infrastructure, including GDPR and other applicable cross-regional obligations.
  • Own the security and governance model for how AI and LLM tooling are used across engineering — controlling what data can reach which models and keeping regulated data inside trusted boundaries.
  • Implement guardrails for AI and agentic workflows to catch data leakage, prompt injection, and unsafe outputs before they reach production or customers.
  • Partner with Engineering leadership to make security a built-in part of our AI-driven SDLC tooling, not a gate bolted on afterward.
  • Evaluate and, where appropriate, pursue recognized AI governance frameworks (e.g., ISO 42001) to give customers confidence in how we govern AI use.
  • Help turn our AI security posture into a competitive advantage in customer conversations, in partnership with Sales and Compliance.
  • Own the enterprise risk assessment program: identify, quantify, and track risk across infrastructure, applications, vendors, and third parties.
  • Run and continuously improve a formal risk register with clear ownership, remediation timelines, and executive reporting.
  • Lead risk assessments for cloud infrastructure and key third-party dependencies (e.g., AWS, Azure), and for new products, features, or architecture changes before launch.
  • Translate technical risk into business terms for executive reporting.
  • Support Sales and Customer Success in customer security conversations, questionnaires, and due diligence reviews — working closely with the Compliance team, who own the customer relationship.
  • Maintain and mature our compliance posture (e.g., FedRAMP, SOC 2, ISO 27001 as applicable) in partnership with Compliance/Validation.
  • Contribute to customer-facing security collateral (architecture summaries, trust documentation) that scales beyond 1:1 conversations.
  • Be available for direct customer engagement when a deal or renewal requires executive-level security assurance.
  • Own the cybersecurity incident response program: detection, escalation, communication, and remediation.
  • Lead cross-functional incident response involving Legal, Engineering, and executive leadership as needed.
  • Ensure continuous monitoring, threat intelligence integration, penetration testing, and vulnerability management.
  • Mature our detection and response capability (SIEM, monitoring, managed detection/response) to steadily reduce mean-time-to-detect.
  • Drive post-incident reviews and continuous improvement.
  • Build, lead, and develop the security team (or oversee the security function, depending on current staffing).
  • Represent security at the executive/leadership table; advise the CEO/CTO on risk posture and security investment priorities.
  • Set and manage the security budget and tooling stack.

Requirements

What you’ll need
  • 8-10 years in security leadership, with direct experience owning risk assessment programs (enterprise, product, and/or third-party risk).
  • Hands-on experience securing cloud environments on AWS and/or Azure.
  • Experience governing the security of AI/LLM usage — data boundaries, guardrails against prompt injection and data leakage, and secure use of AI in engineering workflows.
  • Deep working knowledge of at least one major compliance framework (FedRAMP, SOC 2, ISO 27001, or similar).
  • Experience with data privacy and cross-regional compliance requirements (e.g., GDPR) for organizations operating infrastructure in multiple regions.
  • Experience building or maturing a formal risk register and executive risk reporting.
  • Strong written and verbal communication — able to translate technical security concepts for customers and executives, and to work cross-functionally with Sales, Compliance, and Engineering.
  • Track record of leading incident response for a SaaS or cloud-based product.

Benefits

Comp & perks
  • Competitive compensation
  • 100% medical premium coverage (yes, you read that right!)
  • 401(k) plan with company match
  • Generous PTO packages that increase with tenure
  • Schedule flexibility
  • Onsite physician and massage therapist
  • Dental/vision plans
  • Employer-paid life insurance policy
  • Much, much more!