Remote Fractional CISO — Enterprise Security & Compliance Lead

Reflexion

Lancaster (Lancaster County)

On-site

USD 206,640 - 344,400

Part time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Reflexion is seeking a fractional CISO to guide our compliance program as we close a major enterprise deal. You will sign attestations, validate controls, and coordinate with the CEO and CTO.

This role is fully remote in the United States, with an hourly contracting structure and light first-phase engagement. You will review the SoA, help manage the evidence package, and participate in security-diligence calls.

Qualifications

  • Experience signing SoAs and risk assessments for enterprise customers.
  • Ability to map controls to ISO 27001 / NIST CSF and support SOC 2 readiness.
  • Hands-on scrutiny of AWS+Cloudflare stack controls (IAM, KMS, logging, posture).
  • Familiarity with HIPAA applicability analyses and GDPR vendor obligations.

Responsibilities

  • Review and harden SoA and evidence packages; sign attestations.
  • Lead security-diligence calls with executive stakeholders.
  • Coordinate with CTO on controls, gaps, and evidence responses.
  • Scope and manage external penetration testing; triage findings with CTO.

Skills

CISO experience
Vendor risk
ISO27001 mapping
SOC2 readiness
AWS security

Tools

AWS
Cloudflare
KMS
CloudTrail

Job description

Reflexion is seeking a fractional CISO to guide our compliance program as we close a major enterprise deal. You will sign attestations, validate controls, and coordinate with the CEO and CTO.

This role is fully remote in the United States, with an hourly contracting structure and light first-phase engagement. You will review the SoA, help manage the evidence package, and participate in security-diligence calls.

Get your free, confidential resume review.
or drag and drop your file here.