Fractional CISO

Reflexion

United States

Remote

USD 248,000 - 386,000

Part time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Reflexion is seeking a fractional CISO to own the compliance program for an enterprise deal. You will verify attestations, review evidence, and sign SoAs and risk assessments as the accountable security officer.

You will work directly with the CEO and CTO, aligning vendor-risk posture with enterprise expectations. This remote role requires deep security controls knowledge and pragmatic, business-friendly judgment.

Qualifications

  • Must have led enterprise vendor-risk reviews (security questionnaires, addenda, and audits).
  • Hands-on ISO 27001 / NIST CSF mapping and SOC 2 readiness experience.
  • Ability to sign attestations and respond to customer audits; named accountable individual.
  • Familiar with AWS + Cloudflare controls (IAM, KMS, logging).

Responsibilities

  • Review and sign SoA and risk assessments for enterprise deals.
  • Attend 2–3 customer security diligence calls with CEO/CTO.
  • Verify controls and evidence with CTO; gap triage and findings management.
  • Advise on security exceptions and SOC 2 path if needed.
  • Scope and manage first external penetration test and triage findings.

Skills

Vendor risk
ISO 27001
NIST CSF
SOC 2 readiness
HIPAA/GDPR knowledge

Tools

AWS
Cloudflare

Job description

Fractional CISO

This is a fully remote (work-from-home) position. Work from anywhere in the United States.

Contract / fractional · ~15–25 hrs in the first 60 days, then ~5–10 hrs per quarter

About Reflexion

Reflexion Interactive Technologies builds neuro-cognitive and physiological sensing technology — vision-performance training and respiration-waveform sensing — used by athletes, teams, and now a global consumer-eyewear partner. We are a ~10-person, AWS-hosted company based in Lancaster, PA, closing enterprise partnerships that bring enterprise-grade vendor-security requirements with them.

The role

We are hiring a fractional CISO to be the accountable security executive behind our compliance program as we finalize a major enterprise deal. This is not a build-a-SOC, hire-a-team role: our application-layer security is strong (bcrypt, encrypted sessions, CSRF, parameterized SQL, strict CSP, MFA/RBAC, AES-256 at rest, TLS 1.2+), our compliance calendar and evidence pipeline are run day-to-day by an internal compliance system, and engineering is handled by our CTO. What we need is the credentialed human who signs, validates, and represents.

You will work directly with the CEO (deal owner) and CTO (implementation owner). Our internal compliance agent drafts the documents, tracks the obligations register, and maintains the evidence locker — you review, correct, and put your name on what is true.

What you will do — first 60 days
  • Review and harden our Statement of Applicability + evidence package (ISO 27001/NIST-mapped) responding to an enterprise customer’s Information Security Addendum — built largely from an existing, customer-reviewed evidence base.
  • Sign the risk assessment and SoA as the named security officer; be the security contact enterprise vendor-risk teams can call.
  • Sit on 2–3 customer security-diligence calls (enterprise vendor-risk / InfoSec reviewers) alongside the CEO.
  • Validate what we attest against reality with the CTO (controls verification and gap triage: centralized logging, admin RBAC/audit trail, secrets management).
  • Advise on a security-exception / compensating-controls request and, if required, scope a right-sized SOC 2 Type I path (RFQs prepared; you would manage auditor selection and the engagement).
  • Scope and manage our first external penetration test (vendor shortlist ready) and own findings triage with the CTO.
Ongoing — a few hours a quarter
  • Quarterly review of the compliance-calendar output (access reviews, risk-assessment refresh, training, phishing simulations, BC/DR and restore tests).
  • Annual re-attestation support; named contact for customer audits under contractual audit rights.
  • Incident readiness: review our breach-notification runbook (24–72h contractual clocks) and advise if an incident ever triggers it.
  • Tell us when a new deal’s requirements genuinely change our posture — versus when to negotiate them down. We optimize for minimum-viable compliance and want a partner who respects that philosophy rather than gold-plating.
What we are looking for
  • Prior CISO / vCISO / security-lead experience at a company that sold to large enterprises — you have personally survived enterprise vendor-risk review (security questionnaires, information-security addenda, right-to-audit clauses) from the vendor side.
  • Hands-on fluency with ISO 27001 / NIST CSF control mapping, SOC 2 (readiness through audit), and pragmatic compensating-controls / security-exception practice.
  • Comfortable being the named, accountable individual — signing SoAs and risk assessments, taking customer calls, standing behind attestations.
  • Technical enough to verify controls in an AWS + Cloudflare stack with the CTO (IAM, KMS, CloudTrail/logging, network posture) — you do not implement, but you cannot be bluffed.
  • Working knowledge of HIPAA applicability analysis (we maintain a no-PHI / not-a-business-associate posture and need it defended, not expanded) and GDPR-adjacent vendor obligations (we have EU counsel; you coordinate, not own).
  • Plain-spoken, fast, allergic to compliance theater. You will be asked “is this actually required, or negotiable?” constantly — we want the honest answer.
  • Bonus: consumer wellness / health-adjacent data classification; EU AI Act awareness; prior work with AI-assisted compliance tooling.
What this is not
  • Not full-time, and no conversion pressure — genuinely fractional.
  • Not a program-build from zero: policies (v1.0), an evidence base, an obligations register, a DPA/SCC pack, and counsel relationships already exist.
  • Not an implementation role: engineering changes belong to the CTO; you verify and advise.
Engagement & compensation

Hourly contract (rate DOE) or an equivalent small monthly block. Front-loaded first 60 days (~15–25 hours), then ~5–10 hours per quarter. Direct line to the CEO and CTO. NDA required; the work references a Fortune-Global-500-scale counterparty under confidentiality.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Remote Fractional CISO — Enterprise Security & Compliance Lead
Remote Fractional CISO — Enterprise Security & Compliance Lead

Reflexion • Lancaster

On-site
USD 206,640 - 344,400
Remote Fractional CISO — Enterprise Security & Compliance
Remote Fractional CISO — Enterprise Security & Compliance

Reflexion • United States

Remote
USD 248,000 - 386,000
Head of Security Assurance
Head of Security Assurance

Index Industries • United States

Remote
USD 180,000 - 240,000
Fractional Supply Chain Analyst
Fractional Supply Chain Analyst

Gofractional • Austin (TX)

On-site
USD 90,000 - 130,000
Fractional CISO / Solutions Lead
Fractional CISO / Solutions Lead

Gofractional • San Ramon (CA)

On-site
USD 200,000 - 280,000
Visa sponsorship available
Fractional CISO / Solutions Lead
Fractional CISO / Solutions Lead

Sennovate, Inc. • San Ramon (CA)

On-site
USD 180,000 - 260,000
Visa sponsorship
Hybrid work arrangement
Compliance Operations Lead
Compliance Operations Lead

GovSignals • New York (NY)

On-site
USD 140,000 - 190,000
100% employer-paid medical, vision, and dental
Unlimited PTO
Equity in a fast-growing startup
InfoSec & IT Lead
InfoSec & IT Lead

RevOptimal LLC • New Orleans (LA), Northern (KY)

Hybrid
USD 120,000 - 170,000
Field CISO | Grand Rapids, MI or Remote
Field CISO | Grand Rapids, MI or Remote

US-Signal • Grand Rapids (MI)

Remote
USD 140,000 - 190,000
Generous paid time off
Medical/dental/vision benefits
401(k) retirement plan
+4
Field CISO | Grand Rapids, MI or Remote
Field CISO | Grand Rapids, MI or Remote

US Signal Company, L.L.C. • Grand Rapids (MI)

Remote
USD 140,000 - 190,000
PTO + holidays
Medical, dental & vision benefits
401(k) retirement plan
+4