{"id":945829,"url":"https://alion.io/job/mastercontrol-chief-information-security-officer-ciso","title":"Chief Information Security Officer (CISO)","company":{"id":679371,"name":"MasterControl","domain":"mastercontrol.com","url":"https://alion.io/company/mastercontrol","size_band":"11-50","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"Greenhouse","truth_index":null},"role":"Security","role_family":"Security","seniority":"head","employment_type":"full_time","work_mode":"hybrid","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"explicit","locations":["Salt Lake City, United States"],"countries":["US"],"hiring_countries":[],"hiring_countries_total":0,"salary":null,"salary_estimate":{"min_usd":133000,"max_usd":292000,"period":"year","method":"role_seniority_country_remote_cell","sample_n":73},"experience_years_min":8,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"Agentic Workflows","optional":false},{"name":"AWS","optional":false},{"name":"Azure","optional":false},{"name":"FedRAMP","optional":false},{"name":"GDPR","optional":false},{"name":"ISO 27001","optional":false},{"name":"ISO 42001","optional":false},{"name":"LLM","optional":false},{"name":"LLM Guardrails","optional":false},{"name":"SIEM","optional":false},{"name":"SOC 2","optional":false}],"status":"closed","first_seen_at":"2026-07-21T16:31:24Z","employer_posted_date":"2026-08-26","last_verified_at":"2026-09-26T01:57:01Z","board_verified":false,"closed_at":"2026-09-26T01:57:01Z","days_open":66,"trust":{"level":"not_scored","repost_count":null,"flags":[],"days_open":66},"description":"About MasterControl\nMasterControl Inc. is a leading cloud-based quality and compliance software provider for life sciences and other regulated industries. Our mission is to enable our customers to bring life-changing products to market faster while ensuring compliance and quality throughout the product lifecycle. We are committed to innovation, customer success, and making a positive impact on the world.\nSUMMARY\nWe are looking for a Chief Information Security Officer, reporting to the CTO, to own our enterprise security strategy and risk program, including the security and governance of AI use across our engineering organization. You'll be the executive owner of risk assessment, security governance, and incident response, and a close partner to Sales, Customer Success, and Compliance when customer security reviews or due diligence conversations need executive-level backing. This is not a primarily customer-facing role, but you should be comfortable stepping into a customer conversation when a deal or renewal calls for it.\nWHY THIS ROLE MATTERS\nOur customers trust us with sensitive data in a highly regulated industry, and much of our customer base is in life sciences - where a security or privacy failure doesn't just cost a deal, it can jeopardize a customer's own regulatory standing (GxP, FDA-regulated processes, clinical and quality data). Security and data governance are not back-office functions here; they are part of the product's value proposition and a precondition for enterprise and government customers to say yes.\nWe also operate infrastructure across multiple regions, which means data privacy and residency obligations - including GDPR and other cross-regional requirements - are a standing part of the job, not a one-time compliance exercise. This role will shape how confidently we can expand into new regions and regulated verticals, and how well we protect the trust we've already built with existing customers.\nRESPONSIBILITIES\nCybersecurity Strategy & Governance\nDefine and execute the company's enterprise security strategy, aligned with business objectives and compliance obligations (including FedRAMP).\nOwn security governance, policies, standards, and risk management practices across the organization.\nEmbed security-by-design principles across systems, applications, cloud infrastructure, and engineering workflows.\nSet policy for access control, data protection, and secure development practices, partnering with Engineering to embed requirements into the SDLC without becoming a bottleneck.\nOwn data privacy and residency requirements across the regions where we operate infrastructure, including GDPR and other applicable cross-regional obligations.\n AI Security & Governance\nOwn the security and governance model for how AI and LLM tooling are used across engineering - controlling what data can reach which models and keeping regulated data inside trusted boundaries.\nImplement guardrails for AI and agentic workflows to catch data leakage, prompt injection, and unsafe outputs before they reach production or customers.\nPartner with Engineering leadership to make security a built-in part of our AI-driven SDLC tooling, not a gate bolted on afterward.\nEvaluate and, where appropriate, pursue recognized AI governance frameworks (e.g., ISO 42001) to give customers confidence in how we govern AI use.\nHelp turn our AI security posture into a competitive advantage in customer conversations, in partnership with Sales and Compliance.\n Risk Assessment & Management\nOwn the enterprise risk assessment program: identify, quantify, and track risk across infrastructure, applications, vendors, and third parties.\nRun and continuously improve a formal risk register with clear ownership, remediation timelines, and executive reporting.\nLead risk assessments for cloud infrastructure and key third-party dependencies (e.g., AWS, Azure), and for new products, features, or architecture changes before launch.\nTranslate technical risk into business terms for executive reporting.\n Customer Security Support & Compliance\n Support Sales and Customer Success in customer security conversations, questionnaires, and due diligence reviews - working closely with the Compliance team, who own the customer relationship.\nMaintain and mature our compliance posture (e.g., FedRAMP, SOC 2, ISO 27001 as applicable) in partnership with Compliance/Validation.\nContribute to customer-facing security collateral (architecture summaries, trust documentation) that scales beyond 1:1 conversations.\nBe available for direct customer engagement when a deal or renewal requires executive-level security assurance.\n Incident Response & Operational Security\n Own the cybersecurity incident response program: detection, escalation, communication, and remediation.\nLead cross-functional incident response involving Legal, Engineering, and executive leadership as needed.\nEnsure continuous monitoring, threat intelligence integration, penetration testing, and vulnerability management.\nMature our detection and response capability (SIEM, monitoring, managed detection/response) to steadily reduce mean-time-to-detect.\nDrive post-incident reviews and continuous improvement.\n Leadership\n Build, lead, and develop the security team (or oversee the security function, depending on current staffing).\nRepresent security at the executive/leadership table; advise the CEO/CTO on risk posture and security investment priorities.\nSet and manage the security budget and tooling stack.\nREQUIRED SKILLS\n8-10 years in security leadership, with direct experience owning risk assessment programs (enterprise, product, and/or third-party risk).\nHands-on experience securing cloud environments on AWS and/or Azure.\nExperience governing the security of AI/LLM usage - data boundaries, guardrails against prompt injection and data leakage, and secure use of AI in engineering workflows.\nDeep working knowledge of at least one major compliance framework (FedRAMP, SOC 2, ISO 27001, or similar).\nExperience with data privacy and cross-regional compliance requirements (e.g., GDPR) for organizations operating infrastructure in multiple regions.\nExperience building or maturing a formal risk register and executive risk reporting.\nStrong written and verbal communication - able to translate technical security concepts for customers and executives, and to work cross-functionally with Sales, Compliance, and Engineering.\nTrack record of leading incident response for a SaaS or cloud-based product.\n PREFERRED QUALIFICATIONS\nPrior experience at a company servicing regulated or security-conscious enterprise/government customers.\nExperience in life sciences or another regulated vertical with GxP, FDA, or similar quality/regulatory\nFedRAMP compliance or authorization experience.\nExperience pursuing or maintaining ISO 42001 or similar AI governance certification.\nExperience partnering with Sales/Customer Success/Compliance as a named security resource in customer due diligence.\nRelevant certifications (CISSP, CISM, CRISC, or equivalent)\nPHYSICAL DEMANDS AND WORKING CONDITIONS\nAbility to operate a computer and work at a desk for extended periods of time\nAbility to communicate effectively in writing, in person, over the telephone, and in e-mail\nAbility to work occasional overtime and travel depending on the organization's needs\n#WhyWorkAnywhereElse?\nMasterControl is a place where Exceptional Teams come together to do their best work. In fact, hiring Exceptional Teams is a core value of ours. MasterControl\nemployees are surrounded by intelligent, motivated, and collaborative individuals. We like to call it #TheBestTeamOnThePlanet.\nWe work hard to develop and challenge our employees' skillsets, recognize their contributions, encourage professional development, and offer a one-of-a-kind culture. This is why we say #WhyWorkAnywhereElse?\nMasterControl could be your next (and last) career move!\nHere are some of the benefits MasterControl employees enjoy:\nCompetitive compensation\n401(k) plan with company match\nGenerous PTO packages \nSchedule flexibility\nDental/vision plans\nEmployer-paid life insurance policy\nMuch, much more!\nApplicants must be currently authorized to work in the United States on a full-time basis. MasterControl is an Equal Opportunity Employer. If you are an individual with a\ndisability and require a reasonable accommodation to complete any part of the application process, or are limited in the ability or unable to access or use this\nonline application process and need an alternative method for applying, you may contact  or call (801) 942-4000 and ask to speak\nwith a member of Human Resources.\nEqual Opportunity Employer, including disability and protected veteran status","description_format":"text","description_chars":8738,"description_truncated":false,"requirements":{"experience_years_min":8,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":null,"security_clearance":false,"languages":[]},"benefits":["Life insurance","Professional development"],"hiring_locations":[{"name":"United States","iso":"US","kind":"country"}],"hiring_excludes":[],"relocation_offered":false,"industries":["Information Security","Biotechnology","Scientific & Lab Software","Manufacturing & Industrial Software"],"lifecycle":[{"event":"open","at":"2026-09-15T20:39:50Z"},{"event":"close","at":"2026-09-26T01:57:01Z"}],"liveness":null,"pay":null,"html_url":"https://alion.io/job/mastercontrol-chief-information-security-officer-ciso","json_url":"https://alion.io/job/mastercontrol-chief-information-security-officer-ciso.json","meta":{"generated_at":"2026-10-01T19:47:05Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":2406,"day_limit":5000,"remaining_today":2594,"minute_limit":60,"resets_at":"2026-10-02T00:00:00Z"}}}