Nonprofit security standards body with threat-intel and hardened-image offerings
CIS is a 500+ person nonprofit operating as the custodian of two widely-adopted security frameworks (CIS Controls and CIS Benchmarks) while running operational security services for U.S. government entities. The tech stack reveals infrastructure maturity: Kubernetes, Terraform, Prometheus, and observability tooling (Loki, Tempo) suggest a platform-engineering approach to scaling threat intel and hardened-image delivery. Active hiring in sales (8 roles) and leadership (4 VP/C-level posts) signals a push to grow membership and commercial revenue while tackling legacy system modernization.
Notable leadership hires: Chief Architect, Inside Sales Director
The Center for Internet Security develops and maintains security standards used globally by IT practitioners to secure systems and data. The organization operates three revenue-generating divisions: a standards body (CIS Controls and Benchmarks); MS-ISAC, which provides cyber threat prevention and response services to U.S. State, Local, Tribal, and Territorial government; and EI-ISAC, focused on elections infrastructure security. CIS Hardened Images provide pre-configured, secure cloud environments on AWS and Azure. The organization is based in East Greenbush, New York, and employs 501–1,000 staff across sales, engineering, operations, and security functions.
CIS runs AWS, Azure, Kubernetes, Terraform, Prometheus, Loki, Salesforce, and Workday. They are adopting ArgoCD, Kyverno, Karpenter, and Grafana for container orchestration and observability.
CIS is headquartered in East Greenbush, New York, and currently hiring in the United States only.
Other companies in the same industry, closest in size