Chief Information Security Officer
About the role
The role is a fractional Chief Information Security Officer (CISO) to be the accountable security executive behind our compliance program as we finalize a major enterprise deal.
Responsibilities
- Review and harden our Statement of Applicability + evidence package (ISO 27001/NIST-mapped) responding to an enterprise customer's Information Security Addendum
- Sign the risk assessment and SoA as the named security officer; be the security contact enterprise vendor-risk teams can call
- Sit on 2–3 customer security-diligence calls (enterprise vendor-risk / InfoSec reviewers) alongside the CEO
- Validate what we attest against reality with the CTO (controls verification and gap triage: centralized logging, admin RBAC/audit trail, secrets management)
- Advise on a security-exception / compensating-controls request and, if required, scope a right-sized SOC 2 Type I path (RFQs prepared; you would manage auditor selection and the engagement)
- Scope and manage our first external penetration test (vendor shortlist ready) and own findings triage with the CTO
- Quarterly review of the compliance-calendar output (access reviews, risk-assessment refresh, training, phishing simulations, BC/DR and restore tests)
- Annual re-attestation support; named contact for customer audits under contractual audit rights
- Incident readiness: review our breach-notification runbook (24–72h contractual clocks) and advise if an incident ever triggers it
- Tell us when a new deal's requirements genuinely change our posture — versus when to negotiate them down.
Requirements
Prior CISO / vCISO / security-lead experience at a company that sold to large enterprises — you have personally survived enterprise vendor-risk review (security questionnaires, information-security addenda, right-to-audit clauses) from the vendor side
Hands-on fluency with ISO 27001 / NIST CSF control mapping, SOC 2 (readiness through audit), and pragmatic compensating-controls / security-exception practice
Comfortable being the named, accountable individual — signing SoAs and risk assessments, taking customer calls, standing behind attestations
Technical enough to verify controls in an AWS + Cloudflare stack with the CTO (IAM, KMS, CloudTrail/logging, network posture)
Working knowledge of HIPAA applicability analysis (we maintain a no-PHI / not-a-business-associate posture and need it defended, not expanded)
And GDPR-adjacent vendor obligations (we have EU counsel; you coordinate, not own)
Plain-spoken, fast, allergic to compliance theater. You will be asked "is this actually required, or negotiable?" constantly — we want the honest answer
Qualifications
Note: We've kept the name of the company private. If you'd like to know the company before requesting an intro, just email us at hello [at] fractionaljobs.io
Skills
Technical enough to verify controls in an AWS + Cloudflare stack with the CTO (IAM, KMS, CloudTrail/logging, network posture)
Benefits
Hourly contract (rate DOE) or an equivalent small monthly block. Front-loaded first 60 days (~15–25 hours), then ~5–10 hours per quarter.
Pay
Compensation Range Unknown
Schedule
Contract / fractional ~15–25 hrs in the first 60 days, then ~5–10 hrs per quarter