CISO Mentor – Part-Time

Posted Aug 31

This is a fully remote position, open to applicants in Serbia.

📋 Description

• Enhance and uphold perimeter and network-layer security measures, which encompass WAF, rate limiting, anti-bot, and DDoS mitigation strategies.

• Safeguard product APIs against misuse and irregular traffic patterns.

• Fortify product-level authentication, authorization, and access management, addressing issues like IDOR.

• Oversee the Vulnerability Management process, including detection, prioritization, and tracking of remediation efforts.

• Facilitate external penetration testing and oversee the resolution of identified vulnerabilities.

• Lead Incident Response efforts for security incidents related to products.

• Collaborate with the monitoring team to establish detection and response protocols.

• Participate in Fraud & Trust and Safety initiatives alongside relevant teams.

• Ensure the protection of customer data at the product level through effective access control, encryption, and masking techniques.

• Manage the Security Champions program to educate product teams on secure development practices.

• Oversee the Bug Bounty program.


⛳️ Requirements

• 7+ years of experience in senior Information Security leadership roles (CISO, VP of Security, or Head of InfoSec).

• Established history of mentoring or advising up-and-coming security leaders.

• Demonstrated experience in building, scaling, and managing an Information Security program from the ground up for a startup or growing enterprise.

• Profound, practical knowledge of operations in highly regulated sectors, such as FinTech, HealthTech, or GovTech.

• Proven track record of guiding organizations through stringent audits, including SOC 2 Type II, ISO 27001, PCI-DSS, HIPAA, or GDPR.

• Strong architectural expertise in securing high-throughput, highly available, distributed systems and cloud-native environments.

• Familiarity with AWS, GCP, or Azure.

• Capability to teach and develop risk management frameworks, compliance roadmaps, and vendor risk management processes.

• Exceptional skill in translating complex technical risks into business consequences.

• Experience in coaching individuals on presenting security strategies to C-level executives and Board of Directors.

• Proven ability to establish and lead an enterprise-grade Incident Response plan, which includes crisis management and post-breach communications.

• Demonstrated capacity to cultivate a security-first culture across engineering, product, and business teams.

• Fluent in Russian.


🏝️ Benefits

• Part-time employment.

• Opportunity for remote work from anywhere globally.

• Flexible Work-From-Anywhere position.

• Recognition as a Great Place to Work (USA & Japan, 2024–2025).

People also viewed

AMDTAug 14

Field CISO, OT/ICS

DE flagGermany OnlyFull-timeCISO
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers