Chief Information Security Officer
IT · Full-time
San Francisco, CA, USA
Chief Information Security Officer (CISO)
San Francisco Office · Full-time
About Slash
Slash is building the future of business banking, one industry at a time. We think businesses deserve financial infrastructure built around how they actually operate. That's why we combine what businesses expect from a bank (high yields, strong rewards, serious security) with industry-specific tools that make them faster, leaner, and more profitable.
Slash was founded in 2021 and is one of the fastest-growing fintechs in the world. We power over $10B a year in business purchasing. We recently raised a $100M Series C led by Ribbit Capital, with participation from Khosla Ventures, Goodwater Capital, NEA, and Y Combinator. We're headquartered in San Francisco and have a strong in-person culture.
About the role
Our customers trust us with their operating cash, their cards, their payroll, and their cross-border payments. Keeping that money and data safe is one of the most important things we do.
We're hiring our first CISO to own security across the whole company. You'll be responsible for the product, the infrastructure, our people, our vendors, and our relationships with bank partners and auditors. This is not a policy-and-slide-deck role. You'll write threat models, review architecture, and get hands-on when it matters. You'll also build the team and program that let Slash scale to many times its current size without slowing down.
You'll report to CTO and work closely with engineering, compliance, legal, risk, and our partner banks.
What you'll do
Own Slash's security strategy and program end-to-end. That includes deciding what matters most, what to build versus buy, and what we can safely leave for later.
Build and lead the security team, starting with our Security Engineering hire, and recruit a small group of exceptional engineers.
Secure a platform that moves real money. Scope includes card issuing and PCI DSS, ACH and wire flows, stablecoin payments, treasury, working capital, and our public API.
Lead account-security and anti-takeover work, including MFA and passkeys, session and device security, rate limiting, and admin and permission controls. Partner with fraud and risk teams on the threats that sit between security and fraud.
Set the approach for securing AI agents and automation that act on customer accounts. Define permissions, guardrails, auditability, and abuse prevention for autonomous financial actions.
Own cloud and infrastructure security posture across AWS and Cloudflare, including identity and access, secrets management, logging, detection, and response.
Build and run incident response. Own the playbooks, the on-call process, and customer, partner, and regulatory communication when something goes wrong.
Own our compliance frameworks and audits, including SOC 2 Type II and PCI. Support partner-bank oversight reviews, due diligence, and examinations, and answer enterprise customer security reviews.
Stand up third-party and vendor risk management across our banking, crypto, lending, and infrastructure partners.
Run pen testing, the bug bounty program, and red-team exercises, and make sure findings actually get fixed.
Brief leadership and the board on security risk in plain language.
What we're looking for
10+ years in security, with meaningful time leading security at a fintech, payments company, bank, or crypto company, where the stakes were real money.
A builder's track record. You've stood up a security program from an early stage and scaled it through hypergrowth.
Deep technical credibility. You can go line by line through an auth flow with a senior engineer, and then explain the risk to our board in five minutes.
Hands-on experience with PCI DSS and SOC 2, and with the security expectations of sponsor banks and the FFIEC-style examinations they run.
Strong cloud security experience, ideally AWS, in a modern engineering environment that ships quickly.
Good judgment about tradeoffs. You make security the fast path for engineers, not the blocker.
Calm and decisive during incidents.
Bonus: experience securing crypto or stablecoin infrastructure, card issuing programs, or global and multi-entity payment operations. Also a plus: you've been a founder, or an early security leader at a company that went through a big growth arc.
What's in it for you
Build the security function at one of the fastest-growing fintechs in the world, with real ownership and a direct line to leadership
Competitive salary + equity
High autonomy + ownership culture
Comprehensive health, dental, and vision benefits
Free lunch every day, and dinner if you stay past 9 PM
Working out of our downtown San Francisco office
Unlimited PTO