SVP, Chief Information Security Officer
Overview
Are you ready to make a difference in the world of consumer finance? At Attain Finance , we bring over 50 years of expertise in providing credit solutions across the U.S. and Canada. Our deep roots in the financial industry have empowered us to develop convenient, easily accessible financial services that meet our customers' growing needs.
Join a leading consumer credit lender that thrives on innovation and collaboration, where your contributions are truly valued. Our portfolio includes distinguished brands like Cash Money®, LendDirect® and Heights Finance. Each brand is constantly evolving to better serve our customers.
Be part of a dynamic team that is shaping the future of consumer finance. Apply today and take the next step in your career with Attain Finance !
The SVP, Chief Information Security Officer (CISO) will serve as Attain Finance 's senior-most authority on information security, owning the strategy, execution, and governance of all security functions across the organization. Partnering closely with the Chief Technology Officer and reporting to the Chief Legal and Administrative Officer, the SVP, CISO will align security capabilities with the firm's growth objectives while managing risk in a highly regulated financial services environment.
Responsibilities
- Optimize, implement, and continuously mature an enterprise-wide information security strategy, framework, and roadmap aligned with Attain Finance 's business objectives and risk appetite
- Partner with the CTO to integrate security into technology architecture, infrastructure decisions, software development practices, and vendor selection
- Lead and develop a high-performing security team spanning domains such as security operations, vulnerability management, identity and access management, and data protection
- Own the firm's security risk management program, including risk assessments, control gap analysis, and remediation planning across all business lines and technology environments
- Improve and maintain a robust incident response capability, including detection, containment, recovery, and post-incident review processes
- Partner with the Chief Compliance Officer to ensure compliance with applicable regulatory requirements and industry frameworks, including the FTC Safeguards Rule
- Serve as the security liaison to the Board of Directors, executive leadership, investors, and external auditors, providing clear and actionable reporting on the firm's security posture
- Manage third-party and vendor risk, ensuring that security requirements are embedded in procurement, contracting, and ongoing oversight processes
- Champion a firm-wide security awareness and training program that builds a proactive security culture across all employees and business functions
- Evaluate and manage the security technology stack, ensuring investments are effective, scalable, and aligned with the threat landscape
- Stand up and lead a proactive threat hunting program — build the team, tooling, and playbooks to actively search for threats across our environment rather than waiting on alerts, and mature it from ad-hoc hunts to a repeatable, intel-driven capability. Build out an internal offensive security (red team) function — establish in-house ethical hacking, penetration testing, and adversary emulation to continuously probe our own systems, applications, and controls for weaknesses before attackers do.
Base Salary: $250,000 - $325,000 USD
The base salary range represents the low and high end of the anticipated salary range for this position based on the U.S. average. The actual base salary offered for this full-time position will be determined by various factors, including but not limited to, location, skills, knowledge, competencies, and experience.All full-time salaried employees are eligible for the following benefits, starting on day one: Flexible Paid Time Off Program, Medical, Dental, Vision, Life Insurance, Disability, an