Chief Information Security Officer
Listed on 2026-06-11
-
IT/Tech
Cybersecurity, Information Security, Data Security
About the Dalio Family Office
The Dalio Family Office (DFO) supports Barbara and Ray Dalio and their family in their ventures, investments, and philanthropic efforts under Dalio Philanthropies, which includes Ocean
X, Dalio Education, Endless Network, and the Beijing Dalio Foundation. The core of the DFO’s culture is built around meaningful work and meaningful relationships and the family’s commitment to giving back. The office is headquartered in Westport, CT with regional offices in New York City, Singapore, and Abu Dhabi.
The Chief Information Security Officer is a senior executive responsible for designing, implementing, and operating enterprise-wide information security, cybersecurity, AI governance and resilience programs commensurate with a highly complex, global family office and investment functions. This role has materially expanded beyond traditional family office CISO due to operational complexity of securing an internal trade execution pipeline, increasing reliance on cloud-native platforms, CI/CD-driven engineering workflows, and AI-enabled systems.
This position reports to the Chief Risk and Security Officer and will serve as a strategic partner to senior leadership across Investment, Trading, Technology, Compliance, Legal, and Operations, ensuring that information & cyber security enable the business while protecting sensitive financial, personal, and intellectual assets. The role requires deep financial-sector expertise, hands‑on understanding of modern software delivery (SDLC/CI‑CD), and strong leadership in AI governance, risk management, business continuity and security.
Responsibilities
- Enterprise & Financial Security Leadership
- Own the enterprise information security & cybersecurity strategy across Dalio Family Office entities, including offices and personneloperatingin the US,Singaporeand Abu Dhabi.
- Design andoperateinformation security controls aligned with financial-sectorexpectations for confidentiality, integrity, availability, and market integrity.
- Provide oversight and assurance for systems supporting trading, portfolio management, research, treasury, and middle/back‑office functions.
- Advise senior leadership and principals on cybersecurity, operational risk,monitoring and systemic risk exposures relevant to investment activities.
- Lead security architecture and control design for the DFO trade execution pipeline, including integration with OMS, prime brokerage, custodians, and middle/back‑office platforms.
- Ensure appropriate preventative, detective,monitoring and responsive controls across the full trade lifecycle and proactively working with the Insider Risk & Investigations team.
- Partner closely with Trading, Investment Engineering, Finance, Data Protection Officer and Compliance to align security with regulatory, audit, and operational requirements.
- Establish controls for privileged access, segregation of duties, data lineage, logging, monitoring and incident response in trading workflows.
- Own application security andDev Sec Opsstrategy across cloud and on‑prem environments.
- Embed security & AI controls into SDLC and CI/CD pipelines, including code scanning, dependency management,secretsmanagement,environmentisolation, and release governance.
- Partner with Engineering leaders to balance delivery velocity with robust security outcomes.
- Oversee vulnerability management, penetration testing, and remediation programs aligned to business risk.
- Establish and lead AI governance frameworks covering internal and third‑party AI systems.
- Assess and manage AI‑related risks including data leakage, model misuse, IP exposure, bias, explainability, and regulatory compliance.
- Approve
AI use cases involving sensitive data, financial information, or decision‑making processes. - Partner with Legal, Compliance, and Risk to ensure AI controls are defensible, auditable, and aligned with emerging regulations and industry standards.
- Cyber, Insider & Third‑Party Risk Management
- Own enterprisecyberrisk management and third‑party risk due diligence & oversight in close coordination with the procurement team.
- Manage and govern all critical security vendors, including MDR, MSSPs, and other…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).