Head of Information Security & IT

Chronograph · Brooklyn, New York, United States · Engineering

Posted 2026-08-27

Apply for this role →

Bring your expertise to a highly collaborative, creative, and innovative team with a market-leading technology product suite. We hire technologists with a broad set of technical skills who are eager to solve a wide range of challenges. The thread that unites us at Chronograph is a focus on delivering great, secure products that drive value for our clients.

We are looking for a Head of Information Security & IT to own Chronograph's security strategy, architecture, and execution as we continue to scale.

This is a hands-on leadership role spanning security strategy, governance, technical execution, and external assurance. We expect you to continuously strengthen our information security program and certifications while remaining technically close enough to investigate issues, prototype solutions, and implement controls where appropriate.

The security landscape is changing rapidly, particularly as AI expands both attacker capabilities and the attack surface of modern software. We want someone who follows emerging threats closely, continuously reassesses whether our security posture remains appropriate, and responds to credible new threats with urgency.

Our ideal candidate has a strong sense of ownership, excellent judgment, and a bias toward action. You are equally comfortable defining security strategy, representing it with sophisticated clients and external stakeholders, and getting technically involved when that is the best way to move an issue forward.

As Head of Information Security & IT at Chronograph, you will:

Leadership & Strategy

Own Chronograph's information security program, strategy, architecture, and roadmap

Serve as Chronograph's senior security leader in strategic client, partner, and external engagements

Lead and mentor a small team of senior security, compliance, and IT practitioners

Continuously assess our security posture and prioritize pragmatic, high-impact improvements

Communicate material security risks, priorities, and tradeoffs clearly to executive leadership

Develop a deep understanding of the business, product, and infrastructure to make sound security decisions

Technical Leadership

Develop technical approaches for security initiatives, validate assumptions, and build proofs of concept where useful

Implement security controls directly where appropriate, while partnering with engineering and infrastructure teams on more complex efforts

Maintain sufficient technical depth across cloud, application architecture, identity, logging, and security tooling to investigate issues and guide implementation

Evaluate and configure security tooling and automation

Application & Cloud Security

Own the security posture and requirements for our cloud and application environments, partnering with infrastructure and engineering teams on implementation

Lead vulnerability management and threat modeling programs, hands-on where needed

Partner with engineering on secure development practices and application security architecture

Own and improve application security tooling, including SAST, SCA, DAST, SOAR, secrets detection, and infrastructure-as-code scanning

Prioritize vulnerabilities based on exploitability and business risk

AI Security & Emerging Threats

Own security strategy for Chronograph's use of AI internally and within our products

Secure employee use of AI tools, agents, models, and integrations, including controls around sensitive data, third-party services, and agent permissions

Threat-model AI-enabled functionality, including prompt injection, data exfiltration, insecure tool use, excessive agency, and supply-chain risks

Track developments in offensive and defensive AI security and quickly assess their relevance to Chronograph

Evaluate AI-enabled security tooling and automation where it can improve our defensive capabilities

Corporate Security

Own our detection and response stack, including SIEM, EDR, WAF, and DLP, as well as the automation routing alerts between them

Lead threat detection and incident response strategy, including security partner relationships

Set direction for corporate IT, identity, endpoint management, and employee technology, with the IT team owning day-to-day operations

GRC & Compliance

Own Chronograph's SOC 1, SOC 2, ISO 27001, and broader security assurance strategy, with the GRC team managing day-to-day audit and evidence processes

Ensure our certifications, policies, risk management processes, and technical controls operate as a coherent information security program

Set direction for our annual risk assessment, risk register, policy lifecycle, and third-party risk program

Partner closely with compliance, sales, and customer teams on security due diligence, customer requirements, and strategic client engagements

Represent Chronograph's controls, certifications, and approach to risk with authority and credibility to customers, prospects, and auditors

You will be successful in this role if you have:

7+ years of information security experience, including meaningful hands-on technical experience and increasing ownership of security programs

Strong technical judgment and the ability to investigate problems, develop solutions, build proofs of concept, and implement controls when appropriate

Broad experience across cloud and application security, identity, vulnerability management, and detection and response

Experience owning or materially leading an information security program, including risk management, policies, controls, and security roadmap, leveraging frameworks such as NIST, CIS, or GDPR.

Experience leading SOC1, SOC 2, ISO 27001, or comparable security assurance and certification programs

Experience representing an organization's security controls, certifications, and risk posture with sophisticated enterprise customers and auditors

Strong security instincts and curiosity about emerging threats, including the rapidly evolving implications of AI

Strong executive communication skills and the ability to translate technical controls, risks, and security strategy into clear business language

Even if you do not meet all criteria, we would still encourage you to apply or get in touch! Chronograph offers an entrepreneurial environment where you will be able to proactively identify opportunities to develop and strengthen our team.

Why Join Chronograph?

We value creativity, open communication, cutting edge technology, striving for excellence in all things – and having fun along the way. We want you to be happy here for the long-term.

We offer:

Competitive salary

Equity Participation

401k

Unlimited and flexible vacation

Generous health benefits

Team week events in HQ (Brooklyn, NY) three times annually for all employees

Fully-paid parental leave

...and more!

Chronograph is committed to promoting a diverse and inclusive culture, and we welcome applicants from all backgrounds. If you’re a passionate team player who wants to have an outsized impact on a diverse and dynamic team, we’d love to hear from you!

Salary Range (dependent on experience)

$215,000—$250,000 USD

Apply for this role →

← Back to all jobs