SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Eon.io is a cloud backup and posture management platform backed by Sequoia, Lightspeed, Greenoaks, BOND, and Elad Gil, with $500M raised and a $4B valuation. The company transforms backup data into searchable, accessible, AI-ready assets across cloud environments.
You will be Eon's first Chief Information Security Officer, owning security end-to-end as the company scales. This is a full-scope executive role reporting to the CEO with direct board visibility.
Key responsibilities include:
**Security Strategy & Program Leadership**: Define Eon's overall security strategy, roadmap, and budget. Build and lead the security function from the ground up, hiring and structuring the team as the company scales. Establish security policies, standards, and risk management frameworks.
**Governance, Risk & Compliance**: Own compliance posture across SOC 2, ISO 27001, NIST, and FedRAMP, including audit management and continuous readiness. Build a formal enterprise risk management program covering third-party and vendor risk. Keep policies and controls current with evolving regulatory and customer requirements.
**Security Engineering & Operations**: Partner with Product and Engineering to embed secure-by-design principles into architecture and SDLC. Own detection, response, vulnerability management, and incident response. Evaluate and implement tooling for a cloud-native, multi-environment platform.
**Customer Trust & Enterprise Growth**: Act as a trusted security advisor to enterprise customers and prospects, supporting security reviews, RFPs, and due diligence. Partner with Sales to unblock strategic deals. Represent Eon's security program externally at customer meetings, industry events, and in the broader security community.
Required: 10+ years in cybersecurity with 5+ years in senior security leadership (CISO, VP Security, or Head of Security) at an enterprise SaaS or cloud company. Track record of building and scaling security programs from the ground up at high-growth startups. Deep hands-on knowledge of cloud, SaaS, infrastructure security, and data protection. Direct ownership of SOC 2, ISO 27001, NIST, and FedRAMP programs. Executive-level communication skills for boards, executives, and enterprise customers. Experience recruiting, managing, and developing security teams. Judgment and pace to operate as a true owner in a fast-moving environment.
Nice to have: Experience with regulated environments and public sector security programs (FedRAMP, StateRAMP). Background in cloud infrastructure, data protection, or backup/recovery products. Relevant certifications (CISSP, CISM, CCSP). Experience scaling through hypergrowth (Series C and beyond).