← All roles
CISO

Head of Information Security

AD Mortgage · Financial Services · 501-1,000 employees

Troy, MI · Onsite · full_time

Listed by the employer as “Head Of Information Security”. Title normalized for comparability.

CLI Career Level

SVP-equivalent

Moderate confidence

Opportunity Score

94/100

Exceptional

Moderate confidence

Executive Fit

Sign in

Add your background to score this role against you

Career Level and Opportunity Score describe the role itself. Executive Fit is the only figure that depends on your profile.

First seen Aug 21, 2026 · Last verified 2 hours ago · Sourced from LinkedIn — VP / Head of Security (US)

CLI Take

Broader than the title suggests

This role reads SVP-equivalent despite being advertised as “Head Of Information Security” — the stated scope is wider than the employer's title implies. Scope language covers enterprise-wide remit; global responsibility; executive committee exposure, and it carries board-level exposure and carries SOC 2 accountability. The reporting line, total compensation and team size are not disclosed and remain the main open questions before pursuing it.

Why this role scores the way it does

94/100 — exceptional opportunity quality. CLI reads this as a SVP-equivalent mandate. Strongest signal: Scope language covers enterprise-wide remit; global responsibility; executive committee exposure. 4 of 10 dimensions are not disclosed, which lowers confidence rather than the score.

Career level read

SVP-equivalent — The employer lists this as “Head Of Information Security”. CLI reads it as SVP-equivalent because the role shows enterprise-wide remit; global responsibility; executive committee exposure, board-level exposure expected, 501-1,000 employee organization.

Moderate confidence

What makes it attractive

  • Scope language covers enterprise-wide remit; global responsibility; executive committee exposure.
  • CLI's analysis of the posting describes a strategic build or transformation mandate.
  • Board-level exposure is expected in the role.
  • The role carries more scope than the employer's title suggests.

What to probe before applying

  • No material concerns identified in the posting.

Scoring components · Exceptional

Compensation versus comparable rolesNot disclosed · excluded from the score

Compensation is not disclosed and there is no comparable set to place it against.

Reporting levelNot disclosed · excluded from the score

Reporting line: not disclosed.

Functional and geographic scope100 · weight 12%

Scope language covers enterprise-wide remit; global responsibility; executive committee exposure.

Quality of the mandate100 · weight 12%

CLI's analysis of the posting describes a strategic build or transformation mandate.

Executive and board exposure100 · weight 10%

Board-level exposure is expected in the role.

Role authority versus title100 · weight 10%

The role carries more scope than the employer's title suggests.

Company scale and trajectory67 · weight 10%

Employer profile: 501-1,000 employee organization, privately held, not applicable, revenue 250m 1b.

Team ownershipNot disclosed · excluded from the score

Team size: not disclosed.

Budget ownershipNot disclosed · excluded from the score

Budget ownership: not disclosed.

Risk signals100 · weight 5%

No adverse signals identified in the posting.

Dimensions the employer does not disclose are excluded and the remaining weights are rebalanced, so missing information lowers confidence rather than the score.

Sign in to see how this role scores against your background, and add your career goal to evaluate career value.

Compensation

No compensation disclosed and insufficient comparable data to estimate.

Sample size not yet sufficient for a market comparison

See the full benchmark bands by level and region

The mandate

A strategic leadership role (CISO/VP level) tasked with defining a multi-year security roadmap, authoring enterprise policies, and governing the complete lifecycle of security systems. The leader will be responsible for scaling the program, managing total risk exposure, and aligning security initiatives with the business objectives of a major mortgage lender.

CISO/VP level role based in Troy, MI, overseeing security engineers and specialists. The remit covers the entire security lifecycle including SOC, offensive security, infrastructure defense, and data governance.

Scope

  • Board-level exposure expected

Domains and regulation

  • Enterprise Security
  • GRC
  • Cyber Defense
  • Cloud Security
  • Infrastructure Security
  • Identity
  • Third-Party Risk
  • Incident Response
  • Product Security
  • SOC 2

Requirements

Must have

  • 5+ years of progressive experience in Information Security
  • Proven track record of authoring security policies and steering organizations through compliance audits
  • Experience presenting technical risk metrics to executive boards
  • Strong conceptual mastery of enterprise security classes (SIEM/SOAR, DLP, EDR, secure network routing)

Preferred / bonus

  • Preferred: Industry-recognized leadership certifications such as CISSP, CISM, or CISA

Only must-have items are scored as hard constraints in Executive Fit.

Likely challenges

Not stated in the posting: Reporting line (specific title) not disclosed; Budget size not disclosed; Specific team size not disclosed; Compensation range not disclosed.

About AD Mortgage

A&D Mortgage is a full-service direct mortgage lender that provides a range of residential and commercial loan products, including conventional, government-insured, and Non-QM loans. The company serves mortgage brokers and individual borrowers across most U.S. states. A security leader would be managing risk for a high-volume financial transaction platform subject to various federal and state lending regulations.

Industry
Financial Services
Headcount
501-1,000 employees
Headquarters
Hollywood, Florida
Founded
2005
Ownership
Privately held
Funding
Not applicable
Revenue
$250M – $1B

Full company profile for AD Mortgage →

View original job description
About This OpportunityWe are seeking a strategic and experienced Head of Information Security (CISO/VP level) to lead, scale, and govern our enterprise cybersecurity program. In this executive role, you will define the organization's multi-year security roadmap, align initiatives with business objectives, and manage our total risk exposure. You will oversee the complete lifecycle of security systems, policies, and frameworks while driving a culture of security awareness across the enterprise.Key ResponsibilitiesStrategic Leadership & Governance: Define, author, and oversee the enterprise Information Security Policies framework, ensuring alignment with global regulatory standards (e.g., ISO 27001, NIST, SOC 2).Security Controls Framework: Direct the strategic selection, implementation, and continuous auditing of preventative, detective, and corrective controls to manage the corporate risk appetite.Data Governance & Information Protection: Lead the strategic direction for automated data discovery, data classification workflows, and enterprise Data Loss Prevention (DLP) programs.Security Operations Oversight (SIEM / SOAR): Govern Security Operations Center (SOC) capabilities, evaluating high-level threat telemetry, establishing incident response playbooks, and reporting program ROI and risk posture to executive leadership.Endpoint & Infrastructure Defense (EPP / EDR): Establish corporate standards, vendor strategies, and lifecycle management for enterprise-wide endpoint defense architectures.Vulnerability & Offensive Security Programs: Define the scope, strategy, and budgeting for continuous vulnerability management frameworks, mandatory patching cycles, and annual third-party penetration testing (Red Team engagements).Network & Access Strategy: Guide the high-level architecture for secure network zoning across the OSI model, secure remote access gateways, and enterprise Virtual Private Network (VPN) infrastructures toward a Zero Trust model.Team & Resource Management: Recruit, mentor, and lead a high-performing team of security engineers and specialists while managing departmental budgets and critical vendor relationships.Location and ScheduleThis is a full-time, office-based position in a modern, cozy environment in our Troy, MI location.Our standard working hours are Monday to Friday, 9:00 AM to 6:00 PM, promoting a healthy work-life balance.Skills & QualificationsExperience: 5+ years of progressive experience in Information SecurityStrategic Expertise: Proven track record of authoring security policies, successfully steering organizations through complex compliance audits, and presenting technical risk metrics to executive boards.Technical Breadth: Strong conceptual mastery of enterprise security classes, including SIEM/SOAR architectures, DLP engines, EDR deployments, and secure network routing.Certifications: Industry-recognized leadership certifications such as CISSP, CISM, or CISA are highly preferred.What We Offer | Career and CultureCompany Culture: Inclusive, supportive company culture where you are not a number, but a voice that's heard and brings value.Growth Path: Defined paid training and clear pathways for career development.Benefits: Comprehensive benefits package including PTO, sick days, paid volunteer hours, medical, dental, vision insurance, and 401(k).Take the first step towards a rewarding career in the mortgage industry with AD Mortgage.Our Recruitment team will reach out to you shortly!Connect with us: Explore our social media to get a sense of our corporate culture.YouTubeInstagramTikTokWe are an equal opportunity employer and value diversity at our company. We do not discriminate on the basis of race, religion, color, national origin, sexual orientation, age, marital status, veteran status, or disability status.We will ensure that individuals with disabilities are provided reasonable accommodation to participate in the job application or interview process, to perform crucial job functions, and to receive other benefits and privileges of employment. Please contact us to request accommodation.AD Mortgage is a broker-voted Top 5 U.S. wholesale lender, and recognized as a top Non-QM lender in the U.S. With 20 years in the industry, we offer a full range of loan programs, including DSCR, Bank Statement, FHA, and Conventional loans.

Cyber Leadership Index is not the employer and does not represent candidates for these roles. Verify all details with the employer before acting.