Executive hiring templates
CISO Job Description: Editable Template and Hiring Guide
Copy an editable CISO job description with variants for a first security leader or a regulated enterprise, reporting-line options, 90-day outcomes and an interview scorecard.
- By
- Fractional CTO Experts
- Published
- 2026-10-08
- Reviewed
- 2026-10-08
- Reading time
- 16 minutes

- Settle three questions before you write the first line
- Editable CISO job description template
- Variant A: first security leader at a SaaS scale-up
- Variant B: CISO in a regulated or listed enterprise
- CISO responsibilities mapped to the NIST CSF 2.0 functions
- Reporting line options and what each one trades away
- Worked example: turning an exposure into a mandate
- 90-day outcomes with acceptance evidence
- CISO interview scorecard
- When a fractional or virtual CISO fits instead
- Salary, level and title: what this template does not settle
- Review checklist before you publish the job description
A CISO job description should say which cybersecurity risks the chief information security officer owns, who they report to, what they are allowed to decide, and what they must deliver in their first 90 days. The responsibilities list matters less than those four facts, because good candidates judge the job by its authority and access, not by the adjectives. The template below is copyable and editable, with replacement text for two very different company contexts.
Use it to draft the role, decide the reporting line, agree first-quarter outcomes and run a consistent interview. It is a starting point for your own document, not a live vacancy. If the exposure does not yet justify a full-time executive, the section on fractional and virtual CISOs explains when a reserved-capacity arrangement fits better, and the fractional CISO hiring guide covers that route in depth.
Settle three questions before you write the first line
Most weak CISO job descriptions are weak because the company has not decided what problem the hire is solving. Write down the answers to these three questions first. They will change the title, the seniority, the reporting line and the candidates you attract.
What exposure is driving the hire? Name it. Enterprise customers may be sending security questionnaires that nobody can answer with confidence. A regulator, auditor or insurer may have raised findings. The company may have had an incident and discovered that no one owned the response. A public company may need a clear account of how management assesses and manages cybersecurity risk. Each of these calls for a different first year.
Which decisions will the CISO own outright? Security leaders fail most often when they are accountable for risk they cannot influence. List the decisions the CISO will make alone, the decisions where they have a veto or mandatory sign-off, and the decisions where they only advise. Typical candidates for ownership include security policy, incident command during an active incident, security tooling within an agreed budget and the acceptance criteria for third-party security reviews.
What already exists? Record the security people, tools, policies, audits and contracts already in place, even if they are informal. A candidate needs to know whether they are inheriting a program to improve or starting from an empty page. Overstating maturity to make the role sound attractive tends to come out in the first week and damages trust with the new leader.
The NIST Cybersecurity Framework 2.0 is a useful checklist for this exercise. Its Govern function, added in version 2.0, covers organizational context, risk management strategy, supply chain risk management, "roles, responsibilities, and authorities," policy and oversight, according to NIST CSWP 29. NIST is explicit that the framework describes outcomes rather than prescribing how to achieve them, so treat it as a way to check coverage rather than as a job description in itself.
Editable CISO job description template
Copy the text below into your own document and replace every bracketed field. Delete any responsibility that is outside the real mandate; an honest short list is more persuasive than a long generic one. Later sections give replacement paragraphs for a first-security-leader context and a regulated-enterprise context.
Role summary
Job title: Chief Information Security Officer (CISO).
Company: [Company name], [one sentence on what the company sells and to whom].
Reports to: [Named role, for example CEO, CTO, CIO or COO]. The CISO will also present to [board, audit committee or risk committee] [frequency, for example quarterly] and may request time with that body directly when a material risk requires it.
Location and working pattern: [Remote, hybrid or on-site; time zone overlap; expected travel].
Engagement: [Full-time employment / interim appointment / fractional arrangement of stated days per month].
Team: [Number and roles of direct reports, or "no direct reports at start; budget for [roles] in [period]"]. [Names of external providers, such as a managed detection and response provider or penetration testing firm, the CISO will manage.]
Why we are hiring now: [The exposure in one or two sentences, for example: "Our enterprise customers now require evidence of a security program during procurement, and no one on the leadership team owns cybersecurity risk."]
Purpose of the role
The CISO owns [Company]'s cybersecurity risk at executive level. They will set the security strategy, build and run the program that carries it out, lead the response to security incidents and give leadership and the board an honest, regular account of where the company stands. Success means that the business can make decisions about cybersecurity risk knowingly rather than discovering it after the fact.
In the first year the priority is [primary outcome, for example: "a documented, tested security baseline that lets sales answer customer assurance requests from evidence rather than from memory"]. Decisions about [reserved matters, for example: "accepting risks above the agreed threshold, spending outside the approved budget, and public statements about incidents"] remain with [owner].
Principal responsibilities
- Set and maintain the cybersecurity strategy and risk appetite statement, and get them approved by [executive team / board].
- Maintain a cybersecurity risk register with named owners, current treatment and review dates, and report the significant items to [sponsor and board] on an agreed cadence.
- Own security policy and standards, keeping them short enough that teams actually follow them.
- Lead incident preparation and response: maintain the incident response plan, run exercises with the executive team, and act as incident commander or appoint one during an incident.
- Work with engineering and IT on identity and access management, logging and monitoring, vulnerability management and secure development practices, with clear lines on who implements and who verifies.
- Run third-party and supply chain security review for vendors that handle [Company]'s data or production access.
- Own customer assurance: security questionnaires, trust documentation and the security portion of enterprise contracts, in partnership with sales and legal.
- Plan and lead [audits or attestations in scope, for example SOC 2, ISO/IEC 27001, PCI DSS or HIPAA-related work], including scope decisions and remediation tracking.
- Manage the security budget and security providers within the approved limits.
- Build the security team's capability through hiring, coaching and succession planning for [roles].
- Deliver security awareness activity that targets the company's real risks rather than generic training volume.
- Coordinate with legal, privacy and finance leaders on regulatory, contractual and insurance obligations relevant to cybersecurity.
Decision rights
The CISO decides [list, for example: security policy content; incident severity and escalation during an incident; selection of security tools within budget; whether a vendor passes security review]. The CISO has mandatory sign-off on [list, for example: production access changes for privileged roles; new processing of regulated data]. The CISO advises, and [owner] decides, on [list, for example: accepting risks above the threshold; delaying a release for security reasons; public or customer communications about an incident].
Where the CISO and a business leader disagree about a risk, the disagreement goes to [named escalation owner] with the CISO's written assessment attached. Risk acceptance is recorded in the register with the name of the person who accepted it.
Experience and capabilities
- Has led a security program, or a major part of one, at comparable complexity: [describe scale, cloud environment, regulated data, customer type].
- Has led or materially contributed to the response to real security incidents and can explain the decisions made under pressure.
- Can explain technical risk to non-technical executives and board members in terms of business consequences and options.
- Has built or improved a program using a recognized framework such as the NIST CSF, ISO/IEC 27001 or [sector framework], and can say where the framework did not fit.
- Has managed security providers and budgets, including renegotiating or ending contracts that did not deliver.
- [Sector-specific requirement only if genuinely needed, for example experience with payment card data or protected health information.]
Preferred, not required: [certifications, degrees or specific tools]. Do not make a certification or a number of years a hard requirement unless you can explain why the work needs it.
First 90 days
Within 90 days the CISO will deliver a current-state assessment against [chosen framework], a prioritized risk register approved by [sponsor], a tested incident response plan including one executive tabletop exercise, and a 12-month security roadmap with budget requirements. The next section lists acceptance evidence for each.
Practical information
[Compensation information required or appropriate for the jurisdiction], [benefits], [interview stages and expected timeline], [contact for adjustments or questions]. Ask candidates for [specific evidence at application stage, for example a short note on the most significant security program they built]. Keep the request proportionate.

Variant A: first security leader at a SaaS scale-up
In a growing software company, the first person with security in their title often starts with no team, a production environment built for speed and a sales pipeline full of security questionnaires. The job is part executive and part builder. Replace the template's purpose and responsibilities with language like the following, adjusted to your facts.
Purpose (variant A): You will be [Company]'s first dedicated security leader. There is no security team today; engineering has owned security informally. Your first job is to understand our real exposure, put a small, tested baseline in place and make it possible for sales to answer enterprise security reviews from evidence. You will do some of the hands-on work yourself and decide which parts to hire for, automate or outsource.
Responsibilities to emphasize in variant A:
- Map production systems, data flows and privileged access, and close the highest-risk gaps with engineering.
- Stand up the minimum incident capability: an on-call path, a written plan, a contact list for legal and communications, and one rehearsal.
- Build a reusable answer library and trust documentation for customer security reviews.
- Decide whether and when to pursue a formal attestation such as SOC 2 by weighing sales demand against the cost and distraction.
- Recommend the first security hire or provider and write its brief.
What to leave out of variant A: a large team to manage, board committee reporting that the company does not yet have, and multi-framework compliance programs that no customer has asked for. Listing them only confuses candidates about the real job. The honest difficulty of variant A is that the CISO may spend a large share of time on hands-on engineering and customer calls. If that is most of the job, the title may overstate it, and a senior security engineer plus part-time executive oversight may fit better.
Variant B: CISO in a regulated or listed enterprise
In a larger or regulated organization, the CISO usually inherits people, tools, audits and a governance structure. The job is to run and improve a program, to give the board a reliable view of risk and to hold the line when commercial pressure pushes against security decisions. Replace the purpose paragraph with language like the following.
Purpose (variant B): You will lead [Company]'s cybersecurity program across [business units, regions and team size]. You will own the cybersecurity risk picture presented to the executive committee and to the [audit / risk] committee of the board, lead a team of [number] across [security operations, governance, architecture], and coordinate with the [CIO, chief risk officer, general counsel and privacy officer] on regulatory and contractual obligations.
Responsibilities to emphasize in variant B:
- Maintain the cybersecurity risk management framework and its integration with enterprise risk management.
- Prepare and present regular board reporting on cybersecurity risk, incidents and program progress.
- Oversee regulatory examinations, external audits and remediation commitments in [named regimes].
- Run incident response at enterprise scale, including the internal process that feeds any materiality assessment and disclosure decision owned by legal and the disclosure committee.
- Lead and develop managers across security functions, including succession for key roles.
If the company files reports with the US Securities and Exchange Commission, the job description should reflect the SEC's 2023 cybersecurity disclosure rules. According to the SEC's announcement of the rules, registrants must describe their processes for assessing, identifying and managing material risks from cybersecurity threats, the board's oversight of those risks, and "management's role and expertise in assessing and managing material risks." A new Form 8-K item requires disclosure of a cybersecurity incident the company determines to be material, generally within four business days of that determination. The CISO rarely owns the disclosure decision itself, but they own much of the evidence behind it, so state that interface explicitly and have counsel review the wording.
| Dimension | Variant A: first security leader | Variant B: regulated or listed enterprise |
|---|---|---|
| Starting point | Informal practices, no team | Existing team, tools, audits and committees |
| Main audience | CEO, CTO, customers' security reviewers | Executive committee, board committee, regulators, auditors |
| Balance of work | Building and doing | Leading, governing and reporting |
| Incident role | Often incident commander in person | Owns the process; commands through a team |
| Typical first-year proof | A tested baseline and faster, evidence-based customer reviews | Reliable board reporting and closed audit or exam findings |
| Biggest hiring risk | Title inflation for an engineering-heavy job | A strong operator without board-level communication |
CISO responsibilities mapped to the NIST CSF 2.0 functions
Mapping the responsibilities list to a public framework shows candidates that the scope has been thought through, and shows you where the draft has gaps. NIST CSF 2.0 organizes cybersecurity outcomes under six functions: Govern, Identify, Protect, Detect, Respond and Recover. The table shows what a CISO typically owns directly under each function and what they more often verify while others implement. Adjust the split to your organization.
| CSF 2.0 function | What the CISO usually owns | What others often implement, with CISO verification |
|---|---|---|
| Govern | Strategy, risk appetite, policy, roles and authorities, board reporting, supply chain risk approach | Legal review of obligations; procurement follow-through on vendor terms |
| Identify | Risk register, assessment method, prioritization | Asset inventory and data mapping maintained by IT and engineering |
| Protect | Standards for identity, access, data protection and secure development | Engineering and IT deliver the controls and configurations |
| Detect | Monitoring strategy, detection priorities, provider oversight | Security operations team or managed provider runs day-to-day monitoring |
| Respond | Incident plan, command structure, exercises, post-incident review | Engineering fixes; legal and communications handle notifications |
| Recover | Recovery priorities and testing expectations | Infrastructure teams maintain backups and run restore tests |
Two warnings. First, the framework does not tell you how much of this one person can carry; a first security leader in variant A will own the whole table with very little help. Second, a table like this invites a job description that promises everything. Circle the three or four rows that matter most in the first year and say so in the "why we are hiring now" field.

Reporting line options and what each one trades away
Where the CISO reports is the single most consequential line in the job description. It decides whose priorities the CISO hears first and whether they can raise an uncomfortable risk without going around their own manager. There is no universally correct answer, but each option has a predictable strength and a predictable failure mode.
| Reports to | Strength | Failure mode to watch | Make it work by |
|---|---|---|---|
| CEO | Visible authority and direct access to the person who accepts business risk | CEO lacks time; security gets attention only after incidents | A standing monthly risk review with a fixed agenda |
| CTO | Close to engineering, where most technical controls live | Conflict of interest when security slows the CTO's roadmap | Written escalation route to the CEO and board that bypasses the CTO when needed |
| CIO | Natural fit where IT operations and corporate systems dominate the risk | Same conflict of interest with IT delivery; product security can fall between teams | Explicit ownership of product and cloud security in the charter |
| COO, general counsel or chief risk officer | Independence from technology delivery; strong fit with governance and regulation | Distance from engineering; recommendations arrive without implementation muscle | Named engineering counterpart with shared goals and a joint review |
Whichever line you choose, add three safeguards to the job description. Give the CISO scheduled time with the board or its relevant committee. Give them a documented route to escalate a disagreement about risk acceptance above their manager. And record accepted risks with the name of the person who accepted them, so the reporting line cannot quietly absorb risks the CISO objected to.
If the hire will report to a technology leader, check the CTO's own role definition as well. The CTO job description template is a useful reference for aligning the two documents so that responsibilities for platform security, cloud architecture and engineering practices are not claimed by both people, or by neither.
Worked example: turning an exposure into a mandate
This is an invented scenario to show the method; it does not describe a client or a benchmark.
A B2B software company sells to mid-size and large customers. Its sales team reports that most enterprise deals now involve a security questionnaire, and several have stalled waiting for answers. Engineering has been answering the questionnaires in spare time. The company has cloud infrastructure on one major provider, customer data in a single production database, and single sign-on for staff, but no written incident plan and no one who owns security full time.
The first draft of the job description listed fourteen responsibilities, including building a security operations center, achieving three certifications and running a bug bounty. Working through the three questions above changed it. The exposure was commercial: deals stalling on assurance. The decisions the new leader would need were policy ownership, vendor review sign-off, incident command and a small tooling budget. What existed was more than the team assumed: single sign-on, infrastructure-as-code and an engineer who had run incident reviews at a previous job.
The rewritten mandate had four first-year outcomes: an evidence-based answer library for customer reviews, a tested incident plan, a decision on SOC 2 timing based on pipeline data, and a first security hire. The company chose variant A language, set the reporting line to the CTO with a written escalation route to the CEO, and added a line saying that the role would include substantial hands-on work. That last sentence cost it some candidates who wanted a pure executive role, which was the point: those candidates would not have been happy in the job.

90-day outcomes with acceptance evidence
Vague goals such as "improve security posture" cannot be evaluated. Write outcomes that the sponsor can check by looking at a document, a meeting record or a test result. The example below suits variant A; adapt the items for variant B, where the first 90 days usually focus more on validating the inherited program and board reporting.
| Window | Outcome | Acceptance evidence |
|---|---|---|
| Days 1–30 | Current-state assessment | A short written assessment against the chosen framework, reviewed with the sponsor, separating facts from assumptions |
| Days 1–30 | Privileged access review | List of accounts with production or administrative access, owners confirmed, obvious excess removed |
| Days 1–30 | Incident contact path | Named incident roles, an on-call route and legal and communications contacts, shared with the executive team |
| Days 31–60 | Risk register | Top risks with owners, treatment decisions and review dates, approved by the sponsor |
| Days 31–60 | Customer assurance baseline | Answer library and supporting evidence for the most common customer questions, used on at least one live review |
| Days 31–60 | Provider and tooling review | Inventory of security tools and providers with a keep, change or end recommendation for each |
| Days 61–90 | Incident exercise | One tabletop exercise with the executive team, with written findings and assigned fixes |
| Days 61–90 | 12-month roadmap | Prioritized plan with budget, hiring needs and the decisions the CISO needs from leadership |
| Days 61–90 | First leadership report | A concise risk summary suitable for the board or investors, with trends to be tracked from here |
Agree on what the CISO will not do in the first 90 days as well. A new security leader who is also expected to pass an audit, rebuild identity management and hire a team in the first quarter will do each of those badly. Record trade-offs in writing so the first performance review measures the agreed job.

CISO interview scorecard
Decide the criteria before the first interview and give each interviewer a different part of the scorecard. That keeps the panel from asking the same general questions five times and gives you comparable evidence across candidates. Tie every criterion to a line in the job description.
| Criterion | Question or exercise | Strong evidence | Warning signs |
|---|---|---|---|
| Risk judgment | "Here is our current state in one page. What are the three risks you would address first, and what would you leave alone?" | Prioritizes by business consequence; states assumptions; names what they need to verify | Lists tools to buy; treats every gap as equally urgent |
| Incident command | Tabletop: a customer reports seeing another customer's data. Walk through the first four hours | Establishes command and facts, preserves evidence, brings in legal and communications early, avoids premature statements | Jumps to technical fixes only; no role for legal, communications or the executive team |
| Business translation | "Explain to our CEO why we should or should not pursue a SOC 2 report this year" | Frames the choice as cost, time and sales impact with options | Uses jargon; treats certification as self-evidently good |
| Program building | "Tell me about a security program you built or rebuilt. What did you stop doing?" | Specific personal contribution, sequencing, what failed, what they would change | Credits the team vaguely; no failures; describes only tooling |
| Influence without authority | "Describe a time engineering refused a security requirement. What happened?" | Understood the objection; found a workable path; escalated only when needed | Won by escalation every time, or gave up |
| Provider management | "Describe a security vendor you ended or renegotiated with, and why" | Evaluated against defined outcomes; managed the exit | Has never evaluated a provider's actual delivery |
| Board communication | Ask for a sample one-page risk summary for a board, anonymized from past work or written fresh | Clear risk statements, trend, decisions requested, no fear-driven language | Dense technical content with no decision asked of the reader |
Use a four-point scale with written reasons: no evidence, partial evidence, sufficient evidence and strong evidence. Score independently before the debrief. The BLS description of information security analysts notes that analysts may advance to become chief security officers, which is a common path; a candidate from that path may be very strong on incident command and weaker on board communication, so make sure the scorecard catches both.
For reference checks, ask the referee to reconstruct one specific decision: what the situation was, what the candidate recommended, what the business chose and what happened next. General praise tells you little.

When a fractional or virtual CISO fits instead
Many companies write a CISO job description and discover that they need executive security judgment for a few days a month, not a full-time executive. A fractional or virtual CISO holds the risk ownership, sets direction and represents security to customers and the board, while an internal engineer, an IT lead or a managed provider does the daily work. The table below is a starting point for that decision, not a formula.
| Signal | Points toward full-time CISO | Points toward fractional or virtual CISO |
|---|---|---|
| Decision load | Security decisions arise daily across many teams | Decisions cluster around a roadmap, audits and customer reviews |
| Team to lead | A security team exists or will be hired soon | No team yet; engineering and a provider do the work |
| Assurance demand | Continuous regulator, auditor and board engagement | Periodic customer reviews and one attestation cycle |
| Incident exposure | Frequent incidents or a high-profile target | Low incident volume with a tested plan and a provider on call |
| Time to hire | You can wait for a full search | You need an accountable owner within weeks |
| Budget | Can fund an executive salary plus a team | Needs executive judgment within a smaller total budget |
A fractional mandate still needs everything the full-time template contains: a reporting line, decision rights, first-quarter outcomes and a clear account of who implements the work. It also needs two extra fields: reserved capacity, stated as days or hours per month, and availability during an incident outside the scheduled days. Our fractional CISO role profile explains how that engagement works, and the fractional CISO hiring guide covers scoping, pricing logic and the transition to a permanent hire. Some companies use a fractional CISO first to build the baseline and write the permanent job description with evidence behind it.
Salary, level and title: what this template does not settle
This template does not include a salary figure, because a credible range depends on location, company stage, scope and the market at the time you hire. The US Bureau of Labor Statistics groups IT security managers within computer and information systems managers, an occupation whose median annual wage was $175,140 in May 2025. That is a broad occupational figure covering many kinds of technology managers, not a CISO benchmark; use current compensation data for the specific level and market instead, and follow any pay-transparency rules that apply to your posting.
Level the role against the authority you are actually granting. If the person will sit on the executive team, own board reporting and lead managers, the chief title is accurate. If they will report two levels below the CEO, own no budget and have no board access, a head of security or director title describes the job more honestly, and it will attract candidates who want that job.
Review checklist before you publish the job description
Run through this list once the draft is complete. Each item catches a problem that frequently shows up in the first months after a hire.
- The "why we are hiring now" field names a specific exposure, not a general wish to be secure.
- Every major responsibility has matching decision rights, a budget line or a named partner who implements it.
- The reporting line is stated, and the escalation route above it is written down.
- Board or committee access is described with a frequency.
- Reserved decisions, including risk acceptance and incident communications, have named owners.
- Requirements separate what the work needs from preferences; certifications and years of experience are justified or moved to preferred.
- The 90-day outcomes have acceptance evidence that the sponsor can check.
- The interview scorecard has one criterion for each major responsibility.
- If the company is SEC-registered, counsel has reviewed how the role is described relative to the company's cybersecurity disclosures.
- Location, compensation information and application steps match the real role and applicable law.
When the brief is ready, you can compare permanent and fractional candidates against the same outcomes. Fractional CTO Experts is an executive network and matching platform; if a reserved-capacity arrangement fits, you can request a shortlist using the completed mandate and judge each candidate's relevant experience and availability yourself.
The worked example on this page is hypothetical, and the diagrams are schematic illustrations rather than depictions of real organizations. This is an editorial hiring resource, not legal advice or a live job advertisement.
Frequently asked questions
Who should a CISO report to?
There is no single correct line. Reporting to the CEO gives the most independence; reporting to the CTO or CIO keeps security close to engineering but can bury conflicts of interest. Whichever line you choose, give the CISO a scheduled, direct route to the board or its risk committee.
Does a CISO need certifications such as CISSP or CISM?
Certifications show that someone studied a body of knowledge. They do not show that the person has run an incident, built a program or persuaded executives to fund one. Treat a certification as a preference unless a customer contract, regulator or insurer actually requires it, and interview for evidence of the work.
Is a CISO the same as a head of security or security manager?
Titles vary, but a CISO normally owns cybersecurity risk at executive level and reports on it to leadership and the board. A head of security or security manager often runs part of the program under someone else's risk ownership. Decide which of those you need before choosing the title.
Can a startup's first security hire be a CISO?
It can, but check whether the first hire will spend most of the time setting risk direction or doing hands-on engineering. If it is mostly hands-on work, a senior security engineer plus part-time executive oversight may cover the gap more cheaply and honestly than a CISO title.
Is this CISO template a live job posting?
No. It is a reusable hiring resource with bracketed fields for your organization to complete. It does not announce a vacancy at Fractional CTO Experts, and you should have your own HR and legal owners review the finished version.
Sources and further reading