
Fractional CISO
Posted 6 days ago

Posted 6 days ago
This is a fully remote position, open to applicants in Pennsylvania.
• Assess and strengthen our Statement of Applicability along with the evidence package (ISO 27001/NIST-mapped) in response to an enterprise customer's Information Security Addendum.
• Act as the named security officer by signing the risk assessment and SoA; serve as the security point of contact for enterprise vendor-risk teams.
• Participate in 2–3 customer security diligence calls alongside the CEO.
• Confirm our attestations against actual practices in collaboration with the CTO.
• Provide guidance on security-exception requests or compensating controls and, if necessary, outline a suitable SOC 2 Type I pathway.
• Plan and oversee our initial external penetration test while managing findings triage with the CTO.
• Conduct quarterly reviews of compliance calendar outputs, including access reviews, risk assessment updates, training, phishing simulations, and BC/DR and restoration tests.
• Support annual re-attestation efforts and be the designated contact for customer audits under contractual audit rights.
• Review our breach notification runbook and advise on whether an incident warrants activation.
• Previous experience as a CISO, vCISO, or security lead at a company that engaged with large enterprises.
• Proficiency in ISO 27001 / NIST CSF control mapping, SOC 2 (from readiness to audit), and practical experience with compensating controls and security exceptions.
• Comfortable being the accountable individual—signing SoAs and risk assessments, responding to customer inquiries, and backing attestations.
• Sufficient technical knowledge to verify controls within an AWS and Cloudflare environment alongside the CTO (IAM, KMS, CloudTrail/logging, network posture).
• Familiarity with HIPAA applicability analysis (maintaining a no-PHI and not-a-business-associate stance that needs defending rather than expanding) and GDPR-related vendor responsibilities.
• Clear and concise communicator, swift in action, and averse to compliance theatrics.
• Bonus: Experience with consumer wellness or health-related data classification; awareness of the EU AI Act; prior engagement with AI-assisted compliance tools.
• NDA required; the work involves references to a Fortune-Global-500-scale counterparty under confidentiality.
Rasmussen University
Weekday (YC W21)
Jobs for Humanity
Teaching Finance
Get handpicked remote jobs straight to your inbox weekly.