About the job
About Us
At Rain, we are pioneering the future of global payment solutions. As a dynamic team of innovative builders and experienced founders, we are dedicated to making stablecoins practical for everyday use. Our advanced infrastructure supports a variety of transactions, including card payments, cross-border transactions, B2B purchases, and remittances. We collaborate with fintechs, neobanks, and institutions to launch inclusive and efficient solutions worldwide. Join us to make a significant impact at a rapidly growing company backed by leading investors in fintech, crypto, and SaaS, such as Sapphire Ventures, Norwest, Galaxy Ventures, Lightspeed, Khosla, and more. If you are driven, inquisitive, and eager to contribute to a borderless financial future, we want to hear from you!
Our Culture
We promote a culture of openness and accessibility, allowing employees to flourish in roles that align with their aspirations. Every team member has the autonomy to share ideas and influence the strategic direction of our company.
Your Role
As our Chief Information Security Officer (CISO), you will spearhead Rain’s security governance, risk, and compliance framework, with a strong emphasis on ISO certification and regulatory preparedness. You will work collaboratively with our engineering, infrastructure, legal, and operations teams.
Lead and drive Rain’s information security and compliance strategy, focusing on ISO 27001 readiness, certification, and continuous improvement.
Act as the executive lead for security compliance initiatives, including ISO 27001, SOC 2, vendor risk assessments, and customer security evaluations.
Design, implement, and enhance Rain’s security governance framework, including policies, standards, and risk management practices.
Collaborate closely with Engineering, Infrastructure, Product, Legal, and Operations to integrate compliance and security standards into technical and business processes.
Oversee external audits, certifications, and assessments, serving as the main contact for auditors and evaluators.
Convert regulatory, customer, and partner security requirements into actionable, scalable controls that align with Rain’s operational framework.
Manage the risk management lifecycle, including risk identification, assessment, prioritization, and executive-level reporting.
Establish and monitor security and compliance metrics, providing updates to executive leadership and the board.

