Enter a job title or keyword

Chief Information Security Officer (CISO)

MasterControl


Job Location:

Salt Lake, UT - USA

Monthly Salary: Not provided by the employer
Posted: 21 August 2026 (3 days ago)
Application Deadline: 19 November 2026
Vacancies: 1 Vacancy

Job Summary

About MasterControl

MasterControl Inc. is a leading cloud-based quality and compliance software provider for life sciences and other regulated industries. Our mission is to enableour customers to bring life-changing products to market faster while ensuring compliance and quality throughout the product lifecycle. We are committed toinnovation customer success and making a positive impact on the world.

SUMMARY

We are looking for a Chief Information Security Officer reporting to the CTO to own our enterprise security strategy and risk program including the security and governance of AI use across our engineering organization. Youll be the executive owner of risk assessment security governance and incident response and a close partner to Sales Customer Success and Compliance when customer security reviews or due diligence conversations need executive-level backing. This is not a primarily customer-facing role but you should be comfortable stepping into a customer conversation when a deal or renewal calls for it.

WHY THIS ROLE MATTERS

Our customers trust us with sensitive data in a highly regulated industry and much of our customer base is in life sciences where a security or privacy failure doesnt just cost a deal it can jeopardize a customers own regulatory standing (GxP FDA-regulated processes clinical and quality data). Security and data governance are not back-office functions here; they are part of the products value proposition and a precondition for enterprise and government customers to say yes.

We also operate infrastructure across multiple regions which means data privacy and residency obligations - including GDPR and other cross-regional requirements are a standing part of the job not a one-time compliance exercise. This role will shape how confidently we can expand into new regions and regulated verticals and how well we protect the trust weve already built with existing customers.

RESPONSIBILITIES

Cybersecurity Strategy & Governance

  • Define and execute the companys enterprise security strategy aligned with business objectives and compliance obligations (including FedRAMP).
  • Own security governance policies standards and risk management practices across the organization.
  • Embed security-by-design principles across systems applications cloud infrastructure and engineering workflows.
  • Set policy for access control data protection and secure development practices partnering with Engineering to embed requirements into the SDLC without becoming a bottleneck.
  • Own data privacy and residency requirements across the regions where we operate infrastructure including GDPR and other applicable cross-regional obligations.

AI Security & Governance

  • Own the security and governance model for how AI and LLM tooling are used across engineering controlling what data can reach which models and keeping regulated data inside trusted boundaries.
  • Implement guardrails for AI and agentic workflows to catch data leakage prompt injection and unsafe outputs before they reach production or customers.
  • Partner with Engineering leadership to make security a built-in part of our AI-driven SDLC tooling not a gate bolted on afterward.
  • Evaluate and where appropriate pursue recognized AI governance frameworks (e.g. ISO 42001) to give customers confidence in how we govern AI use.
  • Help turn our AI security posture into a competitive advantage in customer conversations in partnership with Sales and Compliance.

Risk Assessment & Management

  • Own the enterprise risk assessment program: identify quantify and track risk across infrastructure applications vendors and third parties.
  • Run and continuously improve a formal risk register with clear ownership remediation timelines and executive reporting.
  • Lead risk assessments for cloud infrastructure and key third-party dependencies (e.g. AWS Azure) and for new products features or architecture changes before launch.
  • Translate technical risk into business terms for executive reporting.

Customer Security Support & Compliance

  • Support Sales and Customer Success in customer security conversations questionnaires and due diligence reviews working closely with the Compliance team who own the customer relationship.
  • Maintain and mature our compliance posture (e.g. FedRAMP SOC 2 ISO 27001 as applicable) in partnership with Compliance/Validation.
  • Contribute to customer-facing security collateral (architecture summaries trust documentation) that scales beyond 1:1 conversations.
  • Be available for direct customer engagement when a deal or renewal requires executive-level security assurance.

Incident Response & Operational Security

  • Own the cybersecurity incident response program: detection escalation communication and remediation.
  • Lead cross-functional incident response involving Legal Engineering and executive leadership as needed.
  • Ensure continuous monitoring threat intelligence integration penetration testing and vulnerability management.
  • Mature our detection and response capability (SIEM monitoring managed detection/response) to steadily reduce mean-time-to-detect.
  • Drive post-incident reviews and continuous improvement.

Leadership

  • Build lead and develop the security team (or oversee the security function depending on current staffing).
  • Represent security at the executive/leadership table; advise the CEO/CTO on risk posture and security investment priorities.
  • Set and manage the security budget and tooling stack.

REQUIRED SKILLS

  • 8-10 years in security leadership with direct experience owning risk assessment programs (enterprise product and/or third-party risk).
  • Hands-on experience securing cloud environments on AWS and/or Azure.
  • Experience governing the security of AI/LLM usage data boundaries guardrails against prompt injection and data leakage and secure use of AI in engineering workflows.
  • Deep working knowledge of at least one major compliance framework (FedRAMP SOC 2 ISO 27001 or similar).
  • Experience with data privacy and cross-regional compliance requirements (e.g. GDPR) for organizations operating infrastructure in multiple regions.
  • Experience building or maturing a formal risk register and executive risk reporting.
  • Strong written and verbal communication able to translate technical security concepts for customers and executives and to work cross-functionally with Sales Compliance and Engineering.
  • Track record of leading incident response for a SaaS or cloud-based product.

PREFERRED QUALIFICATIONS

  • Prior experience at a company servicing regulated or security-conscious enterprise/government customers.
  • Experience in life sciences or another regulated vertical with GxP FDA or similar quality/regulatory
  • FedRAMP compliance or authorization experience.
  • Experience pursuing or maintaining ISO 42001 or similar AI governance certification.
  • Experience partnering with Sales/Customer Success/Compliance as a named security resource in customer due diligence.
  • Relevant certifications (CISSP CISM CRISC or equivalent)

PHYSICAL DEMANDS AND WORKING CONDITIONS

  • Ability to operate a computer and work at a desk for extended periods of time
  • Ability to communicate effectively in writing in person over the telephone and in e-mail
  • Ability to work occasional overtime and travel depending on the organizations needs

#WhyWorkAnywhereElse
MasterControl is a place where Exceptional Teams come together to do their fact hiring Exceptional Teams is a core value of ours. MasterControl
employees are surrounded by intelligent motivated and collaborativeindividuals. We like to call it #TheBestTeamOnThePlanet.


We work hard to develop and challenge our employees skillsets recognize theircontributions encourage professional development and offer a one-of-a-kindculture. This is why we say #WhyWorkAnywhereElse

MasterControl could be your next (and last) career move!

Here are some of the benefits MasterControl employees enjoy:
Competitive compensation
100% medical premium coverage (yes you read that right!)
401(k) plan with company match
Generous PTO packages that increase with tenure
Schedule flexibility
Onsite massage therapist
Dental/vision plans
Employer-paid life insurance policy
Much much more!


Applicants must be currently authorized to work in the United States on a full-time is an Equal Opportunity Employer. If you are an individual with a
disability and require a reasonable accommodation to complete any part of theapplication process or are limited in the ability or unable to access or use this
online application process and need an alternative method for applying you maycontact or call and ask to speak
with a member of Human Resources.

Equal Opportunity Employer including disability and protected veteran status


Required Experience:

Chief


About Company

Company Logo

MasterControl’s modern MES and QMS ensure compliance with regulations, reduce risks, and improve the quality and safety of products for regulated industries like Life Sciences.

View Profile View Profile