Elevate your campus experience through transformative payments and credential-driven transactions and privileges.
Chief Information Security Officer (CISO)
Location
United States
Posted
53 days ago
Salary
$200K - $280K / year
Seniority
Lead
Job Description
Chief Information Security Officer (CISO)
Transact Campus
Chief Information Security Officer (CISO) Illumia | A Roper Technologies Portfolio Company Remote-Friendly About Illumia Illumia empowers education, healthcare, and corporate enterprises with secure, intelligent technology that streamlines operations and enriches experiences for everyone they serve. Formed by the merger of Transact and CBORD, Illumia is a portfolio company of Roper Technologies (NYSE: ROP) serving more than 1,750 client institutions across higher education, healthcare, corporate, and senior living markets. Illumia serves over 12 million students, facilitates over $58 billion in transactions annually, and connects more than 1,100 colleges and universities through over 300 technology and integration partners. We operate across three business units — Campus ID and Commerce, Integrated Payments, and Healthcare — with a portfolio spanning campus identity and access, commerce and payments, food and nutrition management, and data analytics. As a registered partner and ISO of Elavon (U.S. Bancorp), Illumia operates at the intersection of institutional technology and regulated financial services. Our values are Authenticity, Responsibility, Passion, and Excellence. At Illumia, we believe diverse perspectives make us stronger as a team and as a technology partner. We are committed to building an inclusive workplace where people of all backgrounds feel valued, respected, and empowered to do their best work. Position Summary The CISO is a senior technology leader responsible for Illumia’s enterprise-wide information security strategy, program, and culture. Reporting to the CTO, this role serves as the company’s top security leader — translating cyber risk into business language, protecting customer and institutional data, enabling compliant product growth, and building a world-class security organization. This is both a transformation and leadership role. The CISO will unify two legacy security programs (Transact and CBORD) into a single, cohesive operating model while maintaining continuous compliance and operational readiness. The ideal candidate thrives in complex, multi-product SaaS environments, understands how security is evolving in an AI-first world, and can operate confidently in the boardroom while remaining deeply trusted by engineering and product teams. Security Program Illumia follows NIST’s cybersecurity framework and maintains a public Security and Trust Center (trustcenter.illumiatech.com). Current certifications and compliance posture include: - SOC 2 Type I and Type II (including SOC 2+ HITRUST Type II for healthcare products) - PCI DSS v4.0.1 across multiple product lines; listed on Visa’s Global Registry of Service Providers - TX-RAMP and GovRAMP authorizations - HIPAA Security Compliance for healthcare products The CISO will inherit this foundation and be expected to evaluate, evolve, and unify it into a single enterprise-class security operation. Key Responsibilities - Define and evolve a multi-year enterprise security roadmap across all three business units, aligned to business objectives and risk appetite - Serve as primary security advisor to the executive leadership team and primary security liaison to Roper Technologies - Lead the unification of security programs, toolsets, and policies inherited from Transact and CBORD - Lead Security Operations, GRC, Application Security, and Cloud Security functions - Own SOC 2, PCI DSS, HITRUST, TX-RAMP, GovRAMP, FERPA, and HIPAA compliance programs - Secure SaaS platforms and cloud environments through secure SDLC, vulnerability management, and penetration testing programs - Partner with Engineering and Product to embed security by design without impeding delivery velocity - Establish AI security governance to manage AI tool adoption and AI-specific risks across the organization - Lead or manage security operations (SIEM, EDR, XDR, threat intelligence) through in-house, MSSP, or hybrid models - Own the incident response program and business continuity / disaster recovery testing - Oversee corporate IT security including endpoint protection, patch management, and identity hygiene - Establish cross-business unit security governance to drive consistency while accommodating domain-specific requirements - Recruit, develop, and retain a high-performing security team; manage external vendors, MSSPs, and auditors - Maintain and evolve the public Security and Trust Center Required Experience - 12+ years in information security, with 4+ years as CISO, Deputy CISO, or VP of Security - Proven leadership at a B2B SaaS or cloud-native company; experience scaling security through mergers, acquisitions, or platform consolidation - Deep expertise in cloud security architecture (AWS, Azure, and/or GCP), secure SDLC, and modern threat detection and response - Hands-on leadership of SOC 2 Type II and PCI DSS audits; PCI Level 1 experience strongly valued. HITRUST, GovRAMP, or TX-RAMP experience is a plus - Experience with FERPA, HIPAA, or other education and healthcare regulatory frameworks - Demonstrated ability to communicate security risk to non-technical executives, boards, and parent company leadership - Track record building and scaling security teams, including organizational design and vendor management - Experience in a portfolio company or PE-backed environment is a plus Education and Certifications - Bachelor’s degree in Computer Science, Information Systems, Cybersecurity, or related field required; Master’s or MBA preferred - CISSP, CISM, CCSP, CISA, CRISC, or CCISO strongly preferred Security Technology Experience Experience with modern security platforms across cloud security (Wiz, Prisma Cloud, or equivalent), endpoint/XDR (CrowdStrike, SentinelOne, or equivalent), SIEM/SOAR, identity/IAM, application security (SAST/DAST), GRC automation, and patch management. Familiarity with AI security governance tools and Zero Trust architecture frameworks preferred. Leadership Qualities We hire and develop people who are humble, hungry, and smart — and we hold our leaders to the highest standard across all three. - Humble: They lack excessive ego or concerns about status - Hungry: They are always looking for more — more things to do, more to learn, more responsibility to take on - Smart: They have common sense about people, dealing with others in the most effective way, and picking up on the needs and feelings of others Core Competencies - Executive presence with the ability to build trust at the C-suite level, with parent company leadership, and across business units - Strong business acumen — understands how security decisions impact revenue, customer trust, and institutional relationships - Exceptional communication: able to explain complex security concepts in plain language to diverse audiences - Collaborative leader who can influence without authority and build bridges across security, engineering, product, legal, and sales - Resilient under pressure with sound judgment in high-stakes incident scenarios - Comfortable operating in a post-merger environment where ambiguity is high and organizational norms are still being established Location Remote-friendly with regular travel expectations. Illumia’s teams are distributed across Atlanta, GA; Phoenix, AZ; Ithaca, NY; and international offices in Australia, Ireland, and India. Quarterly on-site engagement, incident response availability, and participation in Roper Technologies events (including the annual Cyber Summit) are expected. Compensation Illumia offers a competitive executive compensation package including base salary, performance-based incentive, and comprehensive benefits. Compensation will be discussed in detail during the recruitment process and will reflect the scope of the role, individual qualifications, and market data. Equal Opportunity and Accommodations Illumia is an Equal Opportunity Employer. We do not discriminate on the basis of race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, veteran status, genetic information, marital status, or any other characteristic protected by applicable law. We are committed to providing reasonable accommodations to qualified individuals with disabilities throughout the hiring process.
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Principal Cyber Risk Advisor, Cybersecurity M&A
General Electric - GEBuilt on more than 130 years of experience, GE Vernova, a division of General Electric (GE), is leading a new era of energy by electrifying the world while work
• Lead cybersecurity due diligence for acquisitions, divestitures, carve-outs, joint ventures, minority investments, and other strategic transactions across GE Vernova’s global portfolio. • Serve as a primary cybersecurity lead across the transaction lifecycle, from early-stage diligence and pre-sign assessments through closing, Day 1 readiness, and 30/60/100-day execution. • Represent the Cyber function holistically in M&A activities, while assessing risks and ensuring alignment with GE Vernova cybersecurity standards, controls, playbooks, and strategic priorities. • Lead cyber diligence activities aligned to recognized frameworks and standards, including NIST CSF, NIST SP 800-53, NIST SP 800-171, and NIST SP 800-82, while applying GE Vernova cybersecurity practices and expectations. • Quantify cyber risk and remediation requirements and translate findings into business terms, including transaction risk, remediation investment, Day 1 requirements, TSA needs, and post-close priorities. • Drive Day 1 cybersecurity readiness, including minimum control requirements, risk-based exceptions, interim safeguards, and stabilization planning. • Build and execute 30/60/100-day cybersecurity integration or separation plans and support long-term roadmap development. • Develop and maintain repeatable playbooks, templates, and standards for cyber diligence, integration, separation, and post-close execution. • Lead safe, practical strategies for OT/ICS integration and separation, including segmentation, cyber resilience, and operational continuity considerations. • Establish secure data-sharing, clean-room, and transaction confidentiality protocols in partnership with Legal, Privacy, and other stakeholders. • Partner closely with Digital Technology M&A/PMO, Business Development, Legal, Privacy, Finance, Insurance, Sourcing, business leaders, and cybersecurity teams across GE Vernova. • Lead and manage external cybersecurity advisors and service providers supporting diligence, testing, regulatory advisory, and execution activities. • Prepare executive-ready cyber risk summaries, decision materials, and recommendations for senior stakeholders. • Track and report key performance indicators related to diligence quality, execution speed, Day 1 readiness, TSA reduction, and post-close remediation progress. • Help define and advance AI use cases for cybersecurity M&A, including opportunities to improve diligence efficiency, risk analysis, control mapping, remediation prioritization, and integration planning, in alignment with GE Vernova governance and responsible AI requirements.
Senior Cyber Security Engineer
General Electric - GEBuilt on more than 130 years of experience, GE Vernova, a division of General Electric (GE), is leading a new era of energy by electrifying the world while work
• Lead key product cyber security programs from inception through completion, ensuring alignment with key stakeholders, business priorities, regulatory requirements, and product roadmaps • Assess current product security posture against applicable regulatory requirements, identify gaps, and develop structured remediation plans and roadmaps • Lead the effort to achieve and/or maintain standards-based certification for the product security program and/or specific Wind products • Manage audit preparation activities, including coordination with internal auditors and third-party certification bodies, evidence collection, and providing responses to findings • Support and/or drive the development, maintenance, and usage of internal tools for product security • Design, develop, and support OT/ICS cybersecurity solutions for wind farm, based on customer requests, regulatory requirements, and commercial strategy • Design, develop, and implement cybersecurity solutions and controls that address identified risks, vulnerabilities, and gaps across Wind’s products • Lead root cause analysis efforts for security vulnerabilities and non-conformities • Support incident response activities related to product security vulnerabilities
Security Engineer – AI
Best Friends Animal SocietyOur mission is to bring about a time when there are No More Homeless Pets.
• Implement and maintain security controls for enterprise AI tools, including Microsoft Copilot and other AI-enabled SaaS platforms. • Support the secure onboarding, configuration, and monitoring of AI features and other enterprise SaaS platforms. • Enforce data access boundaries and usage restrictions for AI tools based on data classification and identity. • Assist in reviewing custom AI use cases and integrations for security risks, including data exposure through prompts or outputs, improper access to sensitive information, and misuse of AI-driven automation. • Design, review, and enforce security controls for enterprise AI platforms, including productivity copilots, internal large language models (LLMs), and third-party AI services. • Partner with security engineering and cloud teams to secure AI infrastructure. • Participate in architecture and security design reviews for AI-enabled systems prior to production deployment, ensuring appropriate guardrails for data exposure. • Support secure configuration for AI agent usage and implement monitoring and audit logging for AI interactions and tool usage. • Design and implement security controls for AI systems leveraging the Model Context Protocol (MCP). • Enforce least-privilege access for AI agents interacting with tools, APIs, and data sources. • Secure AI data flows, including retrieval-augmented generation (RAG) pipelines. • Expand logging and monitoring for AI platforms, cloud environments, and SaaS activity. • Participate in incident response efforts by investigating security alerts and supporting response to incidents involving cloud, SaaS, and AI tools. • Assist in developing and maintaining runbooks and response procedures for platform-related incidents. • Partner with engineering teams to embed security into AI platform architectures. • Support and assist with security reviews of cloud-hosted applications and services and overall application security. • Support identity and access management controls across Cloud platforms, SaaS applications, AI tools and integrations. • Implement and maintain, Role based access controls (RBAC), Least privilege access models, Conditional access and MFA policies. • Assist with access reviews and security remediation efforts. • Contribute to the development and maintenance of security standards and technical guidelines. • Providing security input to IT, Cloud, and Application teams during solution design and implementation. • Document configurations, processes, and operational procedures related to security controls. • Provide practical, security focused guidance to engineering, IT, and business teams on safe AI usage.
• Oversee and enforce security policies, protocols, and compliance requirements • Execute and document security audits • Assist in investigations of security incidents and breaches • Ensure adherence to mandated security standards



