Rain is the global stablecoin payments platform for enterprises, neobanks, platforms, developers, and AI agents. Our technology allows partners to move, store, and use stablecoins instantly and compliantly through global payment cards, rewards, on/offramps, wallets, and cross-border rails. As both a Visa and Mastercard Principal Member, Rain issues cards that work at more than 175 million merchant locations in over 220 countries and territories. Built natively for stablecoins and trusted by more than 100 organizations worldwide, Rain delivers secure, scalable infrastructure that makes money move freely and instantly around the world. You will have the opportunity to deliver massive impact at a hypergrowth company backed by some of the top investors in fintech, crypto, and SaaS. In January 2026, we closed a $250M Series C led by ICONIQ, valuing Rain at $1.95B, with Sapphire Ventures, Dragonfly, Bessemer Venture Partners, Galaxy Ventures, FirstMark, Lightspeed, Norwest, and Endeavor Catalyst also participating. If you're curious, bold, and excited to help shape a borderless financial future, we'd love to talk. Our Ethos: We believe in an open and flat structure. You will be able to grow into the role that most aligns with your goals. Our team members at all levels have the freedom to explore ideas and to influence our company's roadmap and vision. As CISO, you will own Rain’s security governance, risk, and compliance strategy, with a particular focus on ISO certification and regulatory readiness, while partnering closely with engineering, infrastructure, legal, and operations teams. Own and drive Rain’s information security and compliance strategy, with a primary focus on ISO 27001 (and related standards) readiness, certification, and ongoing maintenance. Serve as the executive owner for security compliance programs (e.g., ISO 27001, SOC 2, vendor risk, customer security reviews). Design, implement, and continuously improve Rain’s security governance framework, including policies, standards, and risk management processes. Partner closely with Engineering, Infrastructure, Product, Legal, and Operations to embed compliance and security requirements into technical and business workflows. Lead and manage external audits, certifications, and assessments, acting as the primary point of contact for auditors and assessors. Translate regulatory, customer, and partner security requirements into practical, scalable controls that align with Rain’s architecture and operating model. Own the risk management lifecycle, including risk identification, assessment, prioritization, and executive reporting. Establish and track security and compliance metrics, reporting posture, progress, and risk to executive leadership and the board as needed. Oversee incident response governance, ensuring policies, playbooks, and escalation paths meet compliance and regulatory expectations.