By Sean Cleary, Partner and Cybersecurity Practice Lead
3 Takeaways
1. The market favors you right now. Strong security leaders are running multiple processes and finishing with several offers. That leverage is worth spending on scope and structure, not only compensation.
2. Do reverse diligence before you accept. The reporting line, the mandate, the bench, the board’s real commitment, and your personal liability protection decide whether a role holds at the 18-month mark. Interview them as hard as they interview you.
3. “Life after CISO” is a widening set of paths. Field CISO, board and advisory work, fractional and vCISO engagements, and emerging seats like Chief Trust Officer give experienced security leaders more options than the role has ever offered.
I spend a lot of my week on the phone with security leaders thinking about their next move, and the conversation has changed. A few years ago the question was mostly “what’s out there.” Today it’s “which of these should I take,” because the strongest candidates are choosing among offers. If you’re a CISO weighing your next step, or wondering what comes after the seat, here’s how I’d think it through.
You Have Leverage. Spend It on the Right Things.
The security-leadership market has returned to candidate-driven dynamics, more so than at any point since the pandemic. Demand is the highest we’ve seen in years, several categories of company that sat out the hiring cycle are all in the market at once, and top candidates routinely close with multiple offers in hand.
That leverage is easy to spend entirely on compensation, and comp matters. The more durable use is scope. What separates a role you’ll still want in three years from one you’ll be quietly exiting in eighteen months is authority, proximity to decision-makers, and the ability to influence the business. A bigger number attached to a buried, under-resourced mandate is a worse deal than it looks. Use the leverage to fix the structure before you sign, because you’ll have far less of it once you’re an employee.
Reverse Diligence: Interview Them as Hard as They Interview You
Hiring teams run diligence on candidates. Fewer candidates run the inverse, and it’s one of the most useful things you can do before accepting. Here’s what I’d press on.
The reporting line. A CISO buried several layers down inherits accountability without access. Ask who you report to, how often you’ll sit with the CEO, and how regularly you’ll be in front of the board. A credible answer includes meeting the executive team monthly and the board quarterly. Vagueness here is a signal.
The mandate. Ask what specific problems you’re expected to own in year one, and whether the answer is a clear priority (IPO readiness, regulated-market expansion, product-security build, AI risk) or a generic security wishlist. A mandate no one can articulate before you start rarely gets clearer after.
The bench. Ask who sits beneath the seat and what the plan is to build the layer. A CISO with no qualified leaders for security engineering or GRC ends up running incident response by hand and loses the room at the board level. When the bench doesn’t exist yet, get a commitment to build it in writing, with headcount and timing.
The board’s real posture. Ask how the board currently engages on cyber, and what changed to make them open this role. You’re trying to learn whether security is a genuine priority or a box they’re checking after a scare. The compensation structure tells you something here too: a well-built offer with thoughtful equity signals the company values security, while a below-market package signals a cost center regardless of the job description.
Your personal protection. Individual liability turned real when the SEC charged the SolarWinds CISO personally in 2023. A court dismissed that case in 2025, and the concern it raised hasn’t left; in one industry survey, two-thirds of security chiefs said they would not take a role without directors-and-officers (D&O) protection for the position. Before you sign, confirm the company names the CISO on its D&O policy, get a written indemnification agreement, and settle who signs security disclosures and control attestations. A board that treats these as reasonable asks is telling you something. A board that resists is telling you more.
The question behind all of it: will this still be a good decision at month 18? That’s the mark where mis-set expectations surface, and the diligence you do now is what protects you from it.
Reading the Compensation Signal
Compensation carries information beyond the dollar figure. If your internal reference point for what the role pays is more than 18 months old, it’s stale; the market has moved up fast on AI governance pressure, SEC disclosure rules, and a backlog of delayed hires. Two things worth understanding as you compare offers:
- Equity design matters as much as cash. Late-stage private companies have grown aggressive, using private-company RSU structures that pay like a public company without the liquidity. An options grant and an RSU grant with the same headline value are not the same instrument. Understand the mechanics before you weigh them.
- The structure is a tell. A stretched, well-structured offer signals the company treats security as a priority. Weigh that signal alongside the number when two opportunities look close on paper.
Life After the CISO Seat
The other conversation I have often is with leaders who’ve done the CISO job at a high level and are asking what’s next. The set of paths has widened, and most of them draw directly on the operating experience you already have.
- Field CISO. Security vendors, especially AI-native companies selling into regulated enterprises, are hiring former practitioners to engage buyers as peers. If you like the customer-facing part of the job, translating security for buyers who need convincing, this is a fast-growing option that rewards exactly that skill.
- Board and advisory work. SEC disclosure rules pushed cyber oversight onto boards, and boards need directors who can actually read risk. Boards increasingly recruit sitting and former CISOs for audit and risk committees, and advisory roles are a natural bridge.
- Fractional and vCISO engagements. Companies that aren’t ready for a full-time CISO still need senior judgment. Fractional work suits leaders who want portfolio variety and control over their time.
- Adjacent executive seats. The role is expanding into new titles: Chief Risk Officer, where cyber risk merges with enterprise risk; Chief Trust Officer, owning security, privacy, and ethics as a customer-facing function; and the Business Information Security Officer, embedding security into specific business units. Each rewards the business fluency a modern CISO already had to build.
The common thread: the market now values the translation skill, the ability to turn deep security judgment into business decisions and customer trust, as highly as the technical foundation. That’s the skill to build on, whichever direction you go.
A Practical Next Step
If you’re actively weighing a move, do three things before you start talking to companies. Write down the mandate you actually want to own next, so you can test whether a role matches it. Get a current read on compensation for your target company type, so you’re not anchored to a stale number. And prepare your reverse-diligence questions in advance, so you ask them in the room rather than after you’ve accepted. The leaders who move deliberately, rather than reacting to whoever calls them, are the ones who land in roles that still fit years later.
Frequently Asked Questions
Is 2026 a good time for a CISO to change roles?
The market favors experienced security leaders right now. Demand is the highest in years, multiple categories of company are hiring at once, and strong candidates frequently close with several offers. Spend that leverage on scope and structure, including reporting line, mandate, and the team beneath the role, more than on compensation alone.
What should a CISO evaluate before accepting a new role?
Run reverse diligence on four things: the reporting line and access to the CEO and board, the clarity of the year-one mandate, the plan to build the leadership bench beneath the seat, and whether the board treats security as a genuine priority. The compensation structure is also a signal, since a well-built offer reflects how seriously the organization takes the function. The test to keep in mind is whether the role still looks like a good decision at the 18-month mark.
Should a CISO negotiate personal liability protection before accepting a role?
Yes. Individual liability became a live concern after the SEC charged the SolarWinds CISO personally in 2023, and it remains one even though a court dismissed that case in 2025. A majority of security leaders now say they will not take a role without D&O protection for the position. Before signing, confirm you are named on the company’s D&O policy, secure a written indemnification agreement, and settle who is accountable for signing security disclosures and control attestations.
What career paths exist after being a CISO?
Options have widened beyond the next CISO seat. They include the Field CISO role at security vendors, board and advisory work (especially audit and risk committees), fractional or virtual CISO engagements, and adjacent executive seats such as Chief Risk Officer, Chief Trust Officer, and Business Information Security Officer. Each draws on the business-translation skill a modern CISO already develops.
Related: The CISO Mandate Isn’t One-Size-Fits-All: How the Role Changes Across VC, PE, and Public Companies
Related: CISO and Cyber Leader Compensation in 2026: What the Market Is Paying
Sean Cleary leads the cybersecurity executive search practice at Riviera Partners. Connect on LinkedIn.
About Riviera Partners
Riviera Partners is a global executive search firm focused exclusively on technical leadership, including product, engineering, IT, AI/ML/Data, and cybersecurity.