Fractional CISO @Reflexion
All Others
Salary unspecified
Remote Location
πŸ‡ΊπŸ‡Έ USA Only
Employment Type contract
Posted 3d ago

[Hiring] Fractional CISO @Reflexion

3d ago - Reflexion is hiring a remote Fractional CISO. πŸ’Έ Salary: unspecified πŸ“Location: USA

Role Description

This is a fully remote (work-from-home) position. Work from anywhere in the United States.

Contract / fractional Β· ~15–25 hrs in the first 60 days, then ~5–10 hrs per quarter.

We are hiring a fractional CISO to be the accountable security executive behind our compliance program as we finalize a major enterprise deal. This is not a build-a-SOC, hire-a-team role:

  • Our application-layer security is strong (bcrypt, encrypted sessions, CSRF, parameterized SQL, strict CSP, MFA/RBAC, AES-256 at rest, TLS 1.2+).
  • Our compliance calendar and evidence pipeline are run day-to-day by an internal compliance system.
  • Engineering is handled by our CTO.

You will work directly with the CEO (deal owner) and CTO (implementation owner). Our internal compliance agent drafts the documents, tracks the obligations register, and maintains the evidence locker β€” you review, correct, and put your name on what is true.

What you will do β€” first 60 days

  • Review and harden our Statement of Applicability + evidence package (ISO 27001/NIST-mapped) responding to an enterprise customer's Information Security Addendum.
  • Sign the risk assessment and SoA as the named security officer; be the security contact enterprise vendor-risk teams can call.
  • Sit on 2–3 customer security-diligence calls (enterprise vendor-risk / InfoSec reviewers) alongside the CEO.
  • Validate what we attest against reality with the CTO (controls verification and gap triage: centralized logging, admin RBAC/audit trail, secrets management).
  • Advise on a security-exception / compensating-controls request and, if required, scope a right-sized SOC 2 Type I path.
  • Scope and manage our first external penetration test and own findings triage with the CTO.

Ongoing β€” a few hours a quarter

  • Quarterly review of the compliance-calendar output (access reviews, risk-assessment refresh, training, phishing simulations, BC/DR and restore tests).
  • Annual re-attestation support; named contact for customer audits under contractual audit rights.
  • Incident readiness: review our breach-notification runbook and advise if an incident ever triggers it.
  • Tell us when a new deal's requirements genuinely change our posture β€” versus when to negotiate them down.

Qualifications

  • Prior CISO / vCISO / security-lead experience at a company that sold to large enterprises.
  • Hands-on fluency with ISO 27001 / NIST CSF control mapping, SOC 2 (readiness through audit).
  • Comfortable being the named, accountable individual β€” signing SoAs and risk assessments, taking customer calls.
  • Technical enough to verify controls in an AWS + Cloudflare stack with the CTO.
  • Working knowledge of HIPAA applicability analysis and GDPR-adjacent vendor obligations.
  • Plain-spoken, fast, allergic to compliance theater.

Requirements

  • Bonus: consumer wellness / health-adjacent data classification; EU AI Act awareness; prior work with AI-assisted compliance tooling.

Benefits

  • Hourly contract (rate DOE) or an equivalent small monthly block.
  • Front-loaded first 60 days (~15–25 hours), then ~5–10 hours per quarter.
  • Direct line to the CEO and CTO.
  • NDA required; the work references a Fortune-Global-500-scale counterparty under confidentiality.

How to apply

Send a short note covering:

  • (1) an enterprise vendor-security review you got a small company through β€” what you accepted and what you pushed back on;
  • (2) your hourly rate and availability over the next 60 days.

Resume/LinkedIn welcome; the note matters more.

Before You Apply
️
πŸ‡ΊπŸ‡Έ Be aware of the location restriction for this remote position: USA Only
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Fractional CISO @Reflexion
All Others
Salary unspecified
Remote Location
πŸ‡ΊπŸ‡Έ USA Only
Employment Type contract
Posted 3d ago
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 130,000+ Remote Jobs
️
πŸ‡ΊπŸ‡Έ Be aware of the location restriction for this remote position: USA Only
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 130,000+ Remote Jobs
Γ—

Apply to the best remote jobs
before everyone else

Access 130,000+ vetted remote jobs and get daily alerts.

4.9 β˜…β˜…β˜…β˜…β˜… from 500+ reviews
Unlock All Jobs Now

Maybe later