This page was automatically translated and may contain errors. View in English.
R

Fractional Chief Information Security Officer (CISO)

Reflexion

Remote · Contratto

Sii il primo a candidarti

Esperienza
Qualsiasi
Stipendio
Aperture
1
Pubblicato
2 giorni fa
Modalità di lavoro
Lavoro da casa
Riprendere
È necessario candidarsi

Descrizione del lavoro

Overview

This fully remote contract role allows you to work from anywhere within the United States. You will engage approximately 15–25 hours in the initial 60 days, followed by around 5–10 hours quarterly thereafter.

About Reflexion

Reflexion Interactive Technologies is a company based in Lancaster, PA, specializing in neuro-cognitive and physiological sensing technologies such as vision-performance training and respiration-waveform sensing. Their products serve athletes and a global consumer eyewear partner. The company operates on AWS infrastructure and has a team of around ten people. Reflexion is currently closing enterprise partnerships that impose stringent vendor-security requirements.

Role Summary

We seek a fractional Chief Information Security Officer (CISO) responsible for overseeing our compliance program as we complete a significant enterprise deal. This role is not about building security operations centers or hiring teams; rather, it demands an experienced executive to validate, endorse, and represent our security posture. The technical security measures are robust and managed internally by the CTO, with an established compliance system handling day-to-day activity. Your role is to formally sign, verify, and maintain accountability for security attestations.

Key Responsibilities (First 60 Days)

  • Evaluate and strengthen the Statement of Applicability and evidence packages mapped to ISO 27001 and NIST standards, responding to customer Information Security Addendums.
  • Endorse the risk assessment and SoA as the official security authority; act as the contact for enterprise vendor-risk teams.
  • Participate in 2–3 customer security diligence calls alongside the CEO.
  • Collaborate with the CTO to confirm that attestations accurately reflect the current state of controls, including logging, RBAC, audit trails, and secrets management.
  • Advise on security exceptions and compensating controls; if required, outline and manage a scoped SOC 2 Type I audit process including auditor selection and oversight.
  • Plan and oversee an external penetration test, managing remediation coordination with the CTO.

Ongoing Responsibilities (Quarterly)

  • Conduct quarterly reviews of compliance activities such as access reviews, risk assessments, training, phishing simulations, business continuity, and disaster recovery tests.
  • Support annual re-attestation processes and serve as the named contact for customer audits under contractual rights.
  • Review and advise on breach-notification and incident response procedures aligned with contractual timelines.
  • Evaluate new deal requirements, advising when adjustments or negotiations are warranted to maintain minimum viable compliance without unnecessary overengineering.

Candidate Requirements

  • Previous experience as a CISO, virtual CISO, or security lead at organizations engaging large enterprise customers, with a proven track record in surviving vendor-risk reviews including security questionnaires, information security addenda, and audit clauses.
  • Practical knowledge of ISO 27001 and NIST Cybersecurity Framework control mapping, SOC 2 readiness and audit processes, and managing compensating controls and security exceptions pragmatically.
  • Confidence in assuming accountability as a named security executive who endorses risk assessments and statements of applicability, and can represent the company in customer security discussions.
  • Technical proficiency sufficient to verify control implementations in an AWS and Cloudflare environment, including IAM, KMS, centralized logging, and network posture, working collaboratively with the CTO.
  • Familiarity with HIPAA applicability considerations and the ability to maintain a no-PHI, non-business-associate stance; coordination skills related to GDPR-adjacent vendor compliance with legal counsel.
  • Clear, pragmatic communication style, with an emphasis on practical compliance over unnecessary formalities; consistently able to distinguish between required controls and negotiable items.
  • Desirable: Experience with consumer wellness or health-related data classification, awareness of the EU AI Act, and familiarity with AI-assisted compliance technologies.

Role Clarifications

  • This is not a full-time role and carries no expectation of transition to a permanent position.
  • You will join an established compliance framework including policies, evidence collections, obligation registers, data processing agreements, and legal counsel partnerships.
  • The role focuses on validation and advisory responsibilities rather than technical implementation, which is managed by the CTO.

Engagement and Compensation

The position is an hourly contract paid based on experience or potentially structured as a small monthly retainer. Initial engagement involves approximately 15–25 hours over the first two months, transitioning to about 5–10 hours quarterly. You will report directly to the CEO and CTO. A non-disclosure agreement is required due to the confidential nature of dealings with a Fortune Global 500 client.

Application Instructions

Please submit a brief description addressing two points: (1) an example of guiding a small company through an enterprise vendor-security review, specifying accepted and contested elements; (2) your hourly rate and availability for the coming 60 days. Including a resume or LinkedIn profile is optional; the focus is on your explanatory note.

Lasciate questo messaggio se desiderate una risposta: non lo useremo per nessun altro scopo.

Clicca per navigare, trascina e rilascia, oppure impasto uno screenshot

PNG, JPG, GIF, MP4, WebM, MOV · Dimensione massima 20 MB ciascuno · Fino a 5 file

🤖
Assistenza online tramite intelligenza artificiale immediata