Drata
Field CISO
Remote role where the employee must remain based in a particular country.
United States only
Employer listed it 2 months ago · Added 2 days ago
Been open since 2 months ago. Long-running listings are sometimes left up after the role is filled.
Salary
$210k to $350k per year
Location
United States only
Timezone
Not stated
Contract
Full-time
Experience
Senior
Category
Software
Stated by the employer in the job description
Remote flexibility
Work from home
This is a remote role, but the employee must be based in United States. It is work from home rather than work from anywhere.
What the employer says
- Source listing states candidate location: "Remote - US, Remote"
- Job description states: "U.S.-based"
What Nomaders makes of it
- Payroll and tax are likely handled in that country only
The quotes above are the employer's own words; the reading is ours. Always check the original listing and employment terms before working from another country.
About the role
Drata is building the trust layer between great companies - automating compliance, managing risk, and helping organizations prove trust continuously as they scale. We're Dratanauts: a global crew of 600+ professionals united by a culture that rewards integrity, ownership, and raising the bar, no matter where in the world we're working from. Why Join the Drata Team? At Drata, you're not maintaining legacy compliance software - you're building the agentic AI platform defining what trust looks like for the next generation of companies. Here's what makes the work itself worth showing up for:
Problems without a playbook: You'll work at the edge of AI and security, building agentic governance, continuous compliance, and real-time trust verification to solve problems that don't have an established answer yet. You're writing it as you go.
Real ownership, not just process: Our values center on owning outcomes and raising the bar, not checking boxes. You're expected to have opinions and back them.
A seat at the table: Your perspective is unique and valued. Open debate and diverse viewpoints are built into how decisions actually get made here, at every level.
Growth at rocketship speed: Drata is scaling fast, which means scope grows fast too. High performers get more ownership, visibility, and experience.
A crew, not just coworkers: Dratanauts consistently describe a "come as you are" culture with sharp, curious people—the kind of team that makes hard problems genuinely fun to solve. See what they say here and follow us on LinkedIn for company news, employee stories, and career updates.
Job Summary:
As Drata scales, we want our security and GRC leadership to be able to meet our customers’ needs in more places at once—in strategic customer conversations, on stage at industry events, and in the broader conversations happening across our security and GRC communities. We’re looking for a Field Chief Information Security Officer to join Drata’s Security & GRC organization, reporting directly to our SVP, Security & CISO, to help carry our vision to a wider audience. Your primary mission: be Drata's credible, practitioner-level security and GRC voice in the field.
This role is a senior, remote, U.S.-based security and GRC leadership role, ideally based on the East Coast to cover both the Americas and EMEA regions. As one of the most senior individual contributor roles in Drata's Security & Trust organization, this role shapes how Drata responds to the industry, informs the product experience, and aids in the strategic positioning of Drata’s future to acutely meet industry needs. This position is built for someone who has led security and GRC programs before and is excited to bring that experience directly to our customers, prospects, and industry peers. You’ll work closely with our go-to-market, customer success, and marketing teams, but your foundations are still rooted in technical security and GRC leadership—that is what will make you credible in the room among peers and is critical to the success of this role. Given the nature of our platform, this person will spend as much time in GRC conversations as in traditional security conversations due the complementary nature and inseparability of these functions.
What you’ll do:
Partner with our amazing Sales, Customer Success, and Marketing teams on our most strategic enterprise and F500/G2000 opportunities—bringing tried-and-true security and GRC expertise into the conversation when customers need it most.
Lead executive briefings and CISO-to-CISO conversations that build trust and help prospective customers feel confident in their decision.
Represent Drata at industry conferences, CISO dinners, and regional roundtables across the Americas, EMEA, and APAC regions, building genuine relationships across the security and GRC community.
Share what you’re hearing in the field through webinars, panels, bylines, and press opportunities that build Drata’s voice and credibility in the security and GRC market.
Advise our CISO, CMO, CRO, and executive leadership team members directly on emerging regulatory shifts, systemic industry risk, and where Drata's security and GRC strategy needs to head next.
Provide strategy and direction to company-wide responses to major shifts in our industry, such as new regulatory regimes, major certifications, systemic risk events surfaced by our customers, reaffirming the direction set has a lasting effect on Drata's market position.
Raise the overall security and GRC bar across Drata and industry-wide through knowledge sharing, internal and external forums, and pattern-setting.
Equip our sales teams with the security and GRC context and talking points they need to navigate technical conversations with confidence.
Draw on your own relationships and reputation in the security and GRC community to open doors and build trust for Drata.
Partner with Marketing and GTM leadership to help plan executive events, speaking engagements, dinners, and roundtables throughout the year.
Act as a real, ongoing influence on our product roadmap and go-to-market growth strategy — not just relaying field feedback, but helping shape the decisions themselves based on hands on experience corroborated with customer needs..
Step in on the highest-stakes, least-defined security and GRC questions facing the business—the ones without an existing playbook—and provide the strategic direction to resolve them.
Approach every external conversation as an extension of Drata’s security and GRC program, with the same care and integrity you’d bring internally.
Work alongside our own internal security and GRC team members to support any critical company initiatives as deemed necessary.
Requirements
- ·15+ years of progressive experience in security and GRC, including 10+ years leading and managing teams and 5+ years in the CISO seat (as a CISO, Deputy CISO, or equivalent senior security and GRC leader).
- ·A strong grasp of the compliance frameworks our customers care about — including ISO 27001, SOC 2, HIPAA, FedRAMP, GDPR, NIST CSF, PCI DSS, and CCPA — and the practical experience to speak to them with real depth.
- ·Excellent communication skills, with the ability to move comfortably between boardroom conversations and technical deep-dives.
- ·A genuine reputation and network within the security and GRC community, built through your own experience leading programs and engaging with peers.
- ·A track record of operating at the most senior individual contributor level of a security or GRC organization, where leadership and peers already come to you for strategic direction, not just execution.
Benefits
No benefits package published with this listing. Ask about it at first interview.
How to apply
- 1Check the flexibility label above, work from home, matches where you plan to live and work.
- 2Tailor your CV to the role at Drata, mentioning your remote working experience.
- 3Apply directly on the employer's careers page using the button below. Nomaders never handles your application.
Found 2d ago. Last checked 24 Sept. Always confirm the details on the original posting, salary and location can change after publication.
Listing sourced from Company boards.
Similar roles
Other open software roles with comparable remote rules.
Free to apply, no account needed.
$210k to $350k per year · You'll be taken to the employer's careers page.