← All rolesCISO
Chief Information Security Officer
Hippo Insurance · Financial Services · 501-1,000 employees
Austin, Texas Metropolitan Area · Hybrid · full_time
Listed by the employer as “Chief Information Security Officer (CISO)”. Title normalized for comparability.
CLI Career Level
Enterprise CISO
Moderate confidence
Opportunity Score
79/100
Above average
High confidence
Executive Fit
Sign in
Add your background to score this role against you
Career Level and Opportunity Score describe the role itself. Executive Fit is the only figure that depends on your profile.
First seen Aug 17, 2026 · Last verified 2 days ago · Sourced from LinkedIn — CISO (US)
CLI Take
Scope matches the title
CLI reads this as an Enterprise CISO mandate, consistent with how the employer has titled it. CLI's analysis of the posting describes a strategic build or transformation mandate, and it reports to Chief Technology Officer and carries board-level exposure. Team size is not disclosed and remains the main open question before pursuing it.
Why this role scores the way it does
79/100 — above average opportunity quality. CLI reads this as an Enterprise CISO mandate. Strongest signal: CLI's analysis of the posting describes a strategic build or transformation mandate. 2 of 10 dimensions are not disclosed, which lowers confidence rather than the score.
Career level read
Enterprise CISO — The employer lists this as “Chief Information Security Officer (CISO)”. CLI reads it as Enterprise CISO because the role shows reports to a C-level executive, board or committee interaction; executive committee exposure, board-level exposure expected.
Moderate confidence
What makes it attractive
- CLI's analysis of the posting describes a strategic build or transformation mandate.
- Board-level exposure is expected in the role.
- The role carries more scope than the employer's title suggests.
- The role reports to a C-level executive.
What to probe before applying
- No material concerns identified in the posting.
Scoring components · Above average
Compensation versus comparable roles55 · weight 15%
The employer discloses a base range, but there is no comparable set to benchmark it against yet.
Reporting level71 · weight 12%
The role reports to a C-level executive.
Functional and geographic scope64 · weight 12%
Scope language covers board or committee interaction; executive committee exposure.
Quality of the mandate100 · weight 12%
CLI's analysis of the posting describes a strategic build or transformation mandate.
Executive and board exposure100 · weight 10%
Board-level exposure is expected in the role.
Role authority versus title100 · weight 10%
The role carries more scope than the employer's title suggests.
Company scale and trajectory67 · weight 10%
Employer profile: 501-1,000 employee organization, publicly traded, revenue 250m 1b.
Team ownershipNot disclosed · excluded from the score
Team size: not disclosed.
Budget ownershipNot disclosed · excluded from the score
Budget ownership: not disclosed.
Risk signals100 · weight 5%
No adverse signals identified in the posting.
Dimensions the employer does not disclose are excluded and the remaining weights are rebalanced, so missing information lowers confidence rather than the score.
Sign in to see how this role scores against your background, and add your career goal to evaluate career value.
Compensation
$237,500 – $390,000 base salary, disclosed by employer
Sample size not yet sufficient for a market comparison
See the full benchmark bands by level and region
The mandate
Lead cybersecurity strategy, security operations, and GRC for a publicly traded, multi-state insurance carrier. The CISO will protect systems and customer data while ensuring compliance with SEC disclosures, state insurance regulations, and SOC 2 requirements.
Reports to the Chief Technology Officer; remit includes security operations, GRC, security engineering, and identity governance across the enterprise.
Scope
- Reports to Chief Technology Officer
- Board-level exposure expected
- Public company experience required
Domains and regulation
- Cyber Defense
- GRC
- Compliance
- Identity
- Privacy
- Third-Party Risk
- Incident Response
- DevSecOps
- Application Security
- Resilience
- SOX
- SOC 2
- CCPA
Requirements
Must have
- 10+ years of progressive experience in cybersecurity or information security
- 5+ years in a senior security leadership role (CISO, VP, or Head of Security)
- Experience at a regulated, publicly traded company including SOX audit cycles
- End-to-end ownership of a SOC 2 program from control design to audit preparation
- Experience presenting cybersecurity risk and incident information to boards of directors and audit committees
- Track record of building and managing security operations and third-party risk programs
Preferred / bonus
- Nothing listed as optional.
Only must-have items are scored as hard constraints in Executive Fit.
Likely challenges
- Navigating multi-state insurance regulatory examinations and SOX audit cycles as a public carrier platform
- Embedding security into engineering culture without creating friction in a tech-native environment
- Managing supply chain vulnerabilities across open-source dependencies and third-party service providers
- Leading cybersecurity across a multi-entity corporate structure while maintaining SOC 2 and SOX ITGC compliance
Not stated in the posting: Specific team size (headcount) not disclosed; Budget range for the cybersecurity department not disclosed; Salary range for the Austin, TX location not disclosed (only Morristown, NJ provided).
About Hippo Insurance
Hippo is an insurtech company that provides homeowners insurance products integrated with smart home technology and proactive maintenance services. The firm utilizes data analytics and IoT devices to automate underwriting and mitigate risks for residential property owners. For a security leader, the environment involves managing high volumes of consumer PII and integrating security protocols across a distributed network of smart home hardware.
- Industry
- Financial Services
- Headcount
- 501-1,000 employees
- Headquarters
- Palo Alto, California
- Founded
- 2015
- Ownership
- Public company · NYSE:HIPO
- Funding
- Publicly traded · $1.3B raised
- Revenue
- $250M – $1B
- Investors
- Ribbit Capital, Dragoneer Investment Group, Felicis Ventures, Bond, Comcast Ventures
Full company profile for Hippo Insurance →
View original job description
Title: Chief Information Security Officer (CISO)Location: Austin, TX / Morristown, NJ (hybrid)Reports To: Chief Technology OfficerAbout Hippo:Hippo was built on a promise: make homeownership effortless. Nearly a decade later, that mission still drives us. We use technology and data to help our customers stay ahead of problems and protect what matters most.Today, that same tech-native approach powers our work beyond homeowners. Hippo operates as a diversified carrier platform, partnering with MGAs to deliver tailored program solutions that help them grow and deliver better customer experiences. Behind that work is a team that values ownership, curiosity, collaboration, and continuous improvement.If you're energized by building what's next, we'd love to meet you.About the Role:Hippo is hiring a Chief Information Security Officer to lead cybersecurity strategy, security operations, and governance, risk, and compliance across the enterprise. You will be responsible for protecting Hippo's systems, data, and customers against an evolving threat landscape while ensuring the company meets its regulatory and compliance obligations as a publicly traded, multi-state insurance carrier.This role owns Hippo's SOC 2 program, leads security operations, and drives compliance with applicable state and federal cybersecurity regulations. You will also own identity governance, privacy and data protection strategy, and third-party risk management. This is a high-visibility leadership role that requires equal fluency in security engineering, regulatory compliance, and executive communication.About You:You are a seasoned cybersecurity leader who has built and run security programs at a publicly traded, regulated company. You have navigated regulatory examinations and SOX audit cycles, and you can move seamlessly between a technical incident response scenario and a board presentation. You think in terms of risk, you quantify what you can, and you communicate what you can't with intellectual honesty.You bring a builder's mindset to security. You understand that a great security program enables the business rather than slowing it down, and you know how to embed security into engineering culture without creating friction. Whether your background is in Insurtech, fintech, healthcare, or another heavily regulated sector, you understand multi-regulator environments and lead with clarity and high standards.What You'll Do:Further develop and execute Hippo's enterprise cybersecurity strategy, aligned with business risk appetite and regulatory requirementsBuild and lead the security operations function, including threat detection, incident response, vulnerability management, and threat intelligenceOwn Hippo's SOC 2 program end-to-end, including control design, evidence collection, readiness assessments, and auditor engagementLead the governance, risk, and compliance function, maintaining the cybersecurity risk register, policy framework, standards, and control libraryDrive compliance with applicable state and federal cybersecurity and insurance regulationsSupport SEC cybersecurity disclosure obligations in coordination with Legal and FinanceLead identity governance, including access certification, privileged access management policy, and separation of duties enforcementOwn privacy and data protection compliance strategy, partnering with Legal on data handling, breach notification, and policyholder data protectionManage the third-party and vendor cybersecurity risk management programReport to the Board of Directors and Audit and Risk Committee on cybersecurity posture, risk trends, and incident activityProvide second-line oversight and security control design input to the SOX ITGC programBuild and lead the security engineering function, owning secure design standards and threat modeling practices that ensure security is embedded from architecture through to deploymentBuild, mentor, and develop the cybersecurity team and drive a culture of security awareness across the organizationLead cybersecurity budgeting, roadmap planning, and technology rationalizationOwn disaster recovery and business continuity planning across the enterprise, working closely with the CIO and CTO to drive regular testing, validate recovery capabilities, and ensure organizational resilience is aligned to business and cybersecurity riskOwn the enterprise Incident Response Plan, lead the Security Incident Response Team (SIRT) across the full incident lifecycle from detection and containment through recovery and post-incident review, define severity classifications and escalation paths, and ensure cross-functional stakeholders (Legal, Compliance, IT, and executive leadership) are engaged appropriately during active incidentsDrive a continuous improvement program with outcomes tracked to remediation and reported to the Audit and Risk CommitteeLead the enterprise response to supply chain vulnerabilities across open-source dependencies and third-party service providers, owning risk assessment, mitigation, and remediation Must Haves:10+ years of progressive experience in cybersecurity or information security, with at least 5 years in a senior security leadership role (CISO, VP of Security, or Head of Information Security)Experience at a regulated, publicly traded company, including direct involvement in SOX audit cyclesTrack record of building and managing security operations capabilitiesEnd-to-end ownership of a SOC 2 program, including control design, audit preparation, and remediationExperience with cybersecurity regulations in a regulated industry (financial services, insurance, or healthcare preferred)Strong GRC background with experience maintaining risk registers, policy frameworks, and control librariesProven ability to present cybersecurity risk and incident information to boards of directors, audit committees, and regulatorsExperience managing third-party and vendor cybersecurity risk programsExcellent cross-functional leadership skills with a track record of partnering effectively with Legal, Finance, Internal Audit, and Engineering Nice to Have:Experience in the insurance, Insurtech, or fintech industryFamiliarity with privacy frameworks and data protection requirements (CCPA/CPRA, state breach notification laws)Relevant certifications such as CISSP, CISM, CRISC, or CISABackground in security engineering or application security in addition to GRC and security operationsExperience managing cybersecurity programs across multi-entity corporate structures1 Benefits and Perks:Hippo treats its team members with the same level of dedication and care as we do our customers, which is why we’re fortunate to provide all of our Hippos with:Healthy Hippos Benefits - Multiple medical plans to choose from and 100% employer covered dental & vision plans for our team members and their families. We also offer a 401(k)-retirement plan, short & long-term disability, employer-paid life insurance, Flexible Spending Accounts (FSA) for health and dependent care, and an Employee Assistance Program (EAP) Equity - This position is eligible for equity compensation Training and Career Growth - Training and internal career growth opportunities Flexible Time Off - You know when and how you should recharge Little Hippos Program - We offer 12 weeks of parental leave for primary and secondary caregivers Hippo Habitat - Snacks and drinks available and catered lunches for onsite employeesThe Morristown, NJ base pay range for this role is $237,500 - $390,000. Exact compensation may vary based on several job-related factors that are unique to each candidate, including but not limited to: skill set, experience, education/training, location, business needs and market demands.Hippo is an equal opportunity employer, and we are committed to building a team culture that celebrates diversity and inclusion. Hippo’s applicants are considered solely based on their qualifications, without regard to an applicant’s disability or need for accommodation. Any Hippo applicant who requires reasonable accommodations during the application process should contact the Hippo’s People Team to make the need for an accommodation known.Hippo CCPA
Cyber Leadership Index is not the employer and does not represent candidates for these roles. Verify all details with the employer before acting.