Chief Information Security Officer (CISO)

United States

As industries race to embrace AI, traditional database solutions fall short of rising demands for versatility, performance, and affordability. Couchbase is leading the way with Capella, the developer data platform for critical applications in our AI world. By uniting transactional, analytical, mobile, and AI workloads into a seamless, fully managed solution, Couchbase empowers developers and enterprises to build and scale applications with unmatched flexibility, performance, and cost-efficiency—from cloud to edge. Trusted by over 30% of the Fortune 100, Couchbase is unlocking innovation, accelerating AI transformation, and redefining customer experiences. Come join our mission.

The Role

We are seeking an experienced and forward-thinking Chief Information Security Officer (CISO) to lead our global security strategy.  The CISO will define, implement, and continuously evolve Couchbase’s enterprise and product security posture to protect our people, data, infrastructure, and customers across a hybrid SaaS and on-prem environment.

The ideal candidate is both a strategic thinker and hands-on leader who thrives in a high-growth, engineering-driven organization and understands the unique challenges of securing distributed database and cloud services at scale.  They work collaboratively across the company to champion a “security is everyone’s job” mindset and ensure that security solutions are robust, adaptable, and enable business growth.   

Key Responsibilities

Enterprise strategic leader responsible for defining and executing Couchbase’s global information and cybersecurity strategy—building trust as the foundation for a database company powering mission-critical applications worldwide. Lead all aspects of security governance, architecture, operations, and incident response to safeguard our data platform, products, and cloud infrastructure.

Champion a “secure-by-design” culture across engineering, cloud, and GTM functions—ensuring that security accelerates, rather than constrains, innovation. Partner with product and R&D teams to embed advanced security capabilities into Couchbase’s database, Capella cloud platform, and AI-driven initiatives. Modernize and simplify our security posture through automation, threat intelligence, and proactive risk management to support Couchbase’s ongoing digital and AI transformation.

Collaborate with technology and business leaders to balance speed, trust, and compliance—integrating security into everything from software development lifecycles and infrastructure provisioning to data governance and vendor ecosystems. The CISO will position Couchbase as one of the most secure, trusted, and innovation-ready data platforms in the world.

Governance, Risk & Compliance

  • Develop, implement, and maintain an enterprise-wide information security strategy and governance framework aligned with organizational goals.
  • Establish and maintain information security policies, standards, and procedures that support business continuity and risk management.  This includes continuing to build and enhance governance, privacy, and security frameworks to encompass AI/ML workloads and data pipelines, ensuring responsible, compliant, and secure adoption of AI technologies across the enterprise.
  • Oversee enterprise-wide security risk management, including assessments, and mitigation plans.
  • Ensure compliance with relevant information security frameworks and standards including but not limited to SOC 2, HIPAA, PCI DSS, ISO.
  • Collaborate with Legal and Compliance on evolving data privacy regulations (GDPR, CCPA, etc.) and integrate privacy by design across systems and products.

Security Operations

  • Direct day-to-day security operations, including monitoring, detection, and response to threats.
  • Lead security incident response planning and execution, acting as the senior point of escalation during security incidents.
  • Serve as the primary advisor to the executive team and Board on cybersecurity strategy, risk posture, and incident readiness.
  • Drive the identification and remediation of security vulnerabilities within defined SLAs.
  • Manage key performance metrics for security maturity,  leveraging automation, analytics, and AI to drive continuous improvement across detection, response, and compliance.
  • Review, refine and mature existing security processes and tools, including but not limited to SIEM, DLP, vulnerability management, email security, end point security, penetration testing, threat hunting, threat analysis, security monitoring, and security incident response.
  • Oversee business continuity and disaster recovery planning, ensuring resilience across cloud and data center operations.

Product Security

  • Perform security software architecture review and integrate threat modeling and abuse cases into the SDLC; Advise and implement secure software architecture patterns.
  • Assess and architect security for SaaS/Cloud applications across AWS, GCP and Azure.
  • Drive the development and implementation of standard security review processes across the company that result in effective methods for reducing security risks before product releases.
  • Integrate application security tools within existing development, build, and deployment processes.
  • Oversee the execution of dynamic & static code scan reviews and run-time tests. 
  • Own and manage the bug bounty program.
  • Assist with the planning and execution of application penetration tests. 
  • Interface and collaborate with Engineering, Cloud, and SOC teams during security incidents.
  • Work with customers as needed, to explain or enhance any security policies or product related engineering.
  • Drive the remediation of security vulnerabilities in the products within defined SLAs.
  • Assist in completing RFP security questionnaires

Qualifications:

  • 15+ years of progressive experience in information security, risk management, or IT leadership, including at least 5 years in a senior security leadership role.
  • Proven track record leading enterprise-wide cybersecurity strategy and operations in a global, cloud-first technology company.
  • Solid understanding of secure coding principles (e.g., OWASP Top10, OWASP SAMM) and Agile software development practices. 
  • Demonstrated experience with security in public cloud platforms (AWS, Azure, GCP), CNAPP (Sysdig, Wiz, etc), SAST, DAST, SCA, Networking (Firewalls, Switches, Access Points, etc.), Operating Systems (Linux, Mac, Windows), Secure Software Development, IAM, Key Management, Encryption, SIEM (Splunk, Rapid 7, Alienvault, etc.), DLP (Netskope, Checkpoint, Proofpoint, Symantec, etc), Email Security (Abnormal Security, Mimecast, etc.), and Endpoint Security (SentinelOne, CrowdStrike, etc.) 
  • Strong background in application and product security, including secure software design, code analysis, penetration testing, and bug bounty management.
  • Must have strong collaborative skills, a growth mindset, and a willingness to make tomorrow better than today.
  • Industry Certifications such as CISSP, CISM, CCISO are preferred
  • Bachelor’s or Master’s degree in Computer Science, Information Security, or related field.
The anticipated starting base pay range for this role is listed below. Base salary is not the only component of our competitive total rewards package - you may also be eligible for bonus, commissions, equity, and other benefits as described below. Actual compensation is influenced by a wide array of factors including but not limited to skill set, level of experience, licenses and certifications, and specific work location.

Base Pay Range

$217,000 - $255,000 USD

At Couchbase, we believe innovation thrives when diverse perspectives are at the table. We actively encourage applications from individuals of all backgrounds—including women, people of color, LGTBQIA+ professionals, veterans, and individuals with disabilities. If you see a role that excites you, but don’t meet every qualification, we still encourage you to apply.

Studies show underrepresented talent is less likely to apply unless they meet all the criteria. We encourage you to apply if you’re excited about the role and can bring strong contributions to our team.

If you require reasonable accommodations during the recruitment process, please let your recruiter know—we’re happy to support you.

We value diverse educational and career backgrounds. If your experience aligns with the role’s goals—even if it doesn’t follow a traditional path—we’d love to hear from you.

 Why Couchbase?
Modern customer experiences need a flexible cloud database platform that can power applications spanning from cloud to edge and everything in between. Couchbase’s mission is to simplify how developers and architects develop, deploy and consume modern applications wherever they are. We have reimagined the database with our fast, flexible and affordable cloud database platform Capella, allowing organizations to quickly build applications that deliver premium experiences to their customers– all with best-in-class price performance. More than 30% of the Fortune 100 trust Couchbase to power their modern applications and build innovative new ones. See our recent awards to learn why Couchbase is a great place to work.We are honored to be a part of the Best Places to Work Award for the Bay Area and the UK. Couchbase offers a total rewards approach to benefits  that recognizes the value you create here, so that you in turn may best serve yourself and your family. Some benefits include:
  • Generous Time Off Program - Flexibility to care for you and your family
  • Wellness Benefits - A variety of world class medical plans to choose from, along with dental, vision, life insurance, and employee assistance programs*
  • Financial Planning - Retirement program* and Business Travel Insurance
  • Career Growth - Be valued, Create value approach
  • Fun Perks - An ergonomic and comfortable in-office / WFH setup. Food & Snacks for in-office employees.
  • And much more!
*Note: some programs are not applicable to all countries. Please discuss with a Couchbase recruiter to learn more.
 
 
Disclaimer:
Couchbase is committed to being an equal opportunity employer.  All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, sexual orientation, gender identity, disability and protected veterans’ status, or any other characteristic protected by law. Join an impact initiative group and experience the amazing feeling of Couchbase can-do culture.
 
By using this website and submitting your information, you acknowledge our Candidate Privacy Notice and understand your personal information may be processed in accordance with our Candidate Privacy Notice following guidelines in your country of application. 

Apply for this job

*

indicates a required field

Phone
Resume/CV*

Accepted file types: pdf, doc, docx, txt, rtf

Cover Letter

Accepted file types: pdf, doc, docx, txt, rtf


Select...
Select...

Voluntary Self-Identification

For government reporting purposes, we ask candidates to respond to the below self-identification survey. Completion of the form is entirely voluntary. Whatever your decision, it will not be considered in the hiring process or thereafter. Any information that you do provide will be recorded and maintained in a confidential file.

As set forth in Couchbase, Inc.’s Equal Employment Opportunity policy, we do not discriminate on the basis of any protected group status under any applicable law.

Select...
Select...
Race & Ethnicity Definitions

If you believe you belong to any of the categories of protected veterans listed below, please indicate by making the appropriate selection. As a government contractor subject to the Vietnam Era Veterans Readjustment Assistance Act (VEVRAA), we request this information in order to measure the effectiveness of the outreach and positive recruitment efforts we undertake pursuant to VEVRAA. Classification of protected categories is as follows:

A "disabled veteran" is one of the following: a veteran of the U.S. military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or a person who was discharged or released from active duty because of a service-connected disability.

A "recently separated veteran" means any veteran during the three-year period beginning on the date of such veteran's discharge or release from active duty in the U.S. military, ground, naval, or air service.

An "active duty wartime or campaign badge veteran" means a veteran who served on active duty in the U.S. military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense.

An "Armed forces service medal veteran" means a veteran who, while serving on active duty in the U.S. military, ground, naval or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985.

Select...

Voluntary Self-Identification of Disability

Form CC-305
Page 1 of 1
OMB Control Number 1250-0005
Expires 04/30/2026

Why are you being asked to complete this form?

We are a federal contractor or subcontractor. The law requires us to provide equal employment opportunity to qualified people with disabilities. We have a goal of having at least 7% of our workers as people with disabilities. The law says we must measure our progress towards this goal. To do this, we must ask applicants and employees if they have a disability or have ever had one. People can become disabled, so we need to ask this question at least every five years.

Completing this form is voluntary, and we hope that you will choose to do so. Your answer is confidential. No one who makes hiring decisions will see it. Your decision to complete the form and your answer will not harm you in any way. If you want to learn more about the law or this form, visit the U.S. Department of Labor’s Office of Federal Contract Compliance Programs (OFCCP) website at www.dol.gov/ofccp.

How do you know if you have a disability?

A disability is a condition that substantially limits one or more of your “major life activities.” If you have or have ever had such a condition, you are a person with a disability. Disabilities include, but are not limited to:

  • Alcohol or other substance use disorder (not currently using drugs illegally)
  • Autoimmune disorder, for example, lupus, fibromyalgia, rheumatoid arthritis, HIV/AIDS
  • Blind or low vision
  • Cancer (past or present)
  • Cardiovascular or heart disease
  • Celiac disease
  • Cerebral palsy
  • Deaf or serious difficulty hearing
  • Diabetes
  • Disfigurement, for example, disfigurement caused by burns, wounds, accidents, or congenital disorders
  • Epilepsy or other seizure disorder
  • Gastrointestinal disorders, for example, Crohn's Disease, irritable bowel syndrome
  • Intellectual or developmental disability
  • Mental health conditions, for example, depression, bipolar disorder, anxiety disorder, schizophrenia, PTSD
  • Missing limbs or partially missing limbs
  • Mobility impairment, benefiting from the use of a wheelchair, scooter, walker, leg brace(s) and/or other supports
  • Nervous system condition, for example, migraine headaches, Parkinson’s disease, multiple sclerosis (MS)
  • Neurodivergence, for example, attention-deficit/hyperactivity disorder (ADHD), autism spectrum disorder, dyslexia, dyspraxia, other learning disabilities
  • Partial or complete paralysis (any cause)
  • Pulmonary or respiratory conditions, for example, tuberculosis, asthma, emphysema
  • Short stature (dwarfism)
  • Traumatic brain injury
Select...

PUBLIC BURDEN STATEMENT: According to the Paperwork Reduction Act of 1995 no persons are required to respond to a collection of information unless such collection displays a valid OMB control number. This survey should take about 5 minutes to complete.