12 дней назад
Fractional CISO (Contract / Project Based)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Fractional CISO (Contract / Project Based) (Cybersecurity): Defining an independent security strategy, risk framework, certification direction, and incident response model for an education technology company with an accent on assurance, governance, and board-level reporting. Focus on designing costed security roadmaps, reviewing internal controls, assessing ISO 27001 readiness, and maturing client assurance evidence.
Location: Remote
Company
is an education technology company that helps corporate and government organisations build data transformation skills for the AI era.
What you will do
- Define a costed security strategy and sequenced improvement roadmap aligned with the company’s estate, threat landscape, and risk appetite.
- Architect a security risk register and conduct independent reviews of controls operated by the internal IT team.
- Deliver periodic board-level reporting on organisational risk.
- Provide an evidence-based recommendation on pursuing ISO 27001 or maintaining Cyber Essentials Plus with a documented ISMS.
- Design incident response frameworks, testing plans, escalation pathways, and playbooks.
- Mature the reusable security assurance evidence library for complex client due diligence.
Requirements
- Senior, independent information security leadership experience suitable for a fractional CISO engagement.
- Ability to provide strategic judgment and assurance without managing staff or taking on day-to-day operational execution.
- Experience with security strategy, risk registers, control assurance, board reporting, and incident response planning.
- Ability to assess ISO 27001 and Cyber Essentials Plus certification direction.
- Ability to work with the Head of Engineering, acting SIRO, as the primary internal contact.
Culture & Benefits
- Remote, external advisory engagement with full autonomy over delivery methods.
- Deliverable-focused model rather than a fixed weekly schedule.
- Internal IT retains responsibility for patching, endpoint hardening, configuration, and incident first response.
- Initial setup phase of approximately 1.5 days per week for the first three months.
- Transition to approximately 2 days per month in months 4–6, followed by a 1–2 day per month retainer.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
13 дней назад
Cloud Security Engineer
75 - 80$
13 дней назад
Cloud Engineer (Cloud Security)
12 дней назад
Chief Information Security Officer (AI Security)
7 дней назад
Chief Information Security Officer (Fintech)
13 дней назад
Global Chief Information Security Officer (CISO) (Fintech)
Ping Identity
14 дней назад