Reflexion
 is hiring a fractional

Chief Information Security Officer

Added 

x

 - Syndicated from 
JazzHR

How Syndicated Job Posts Work

This job was not posted directly to Fractional Jobs. It’s syndicated from another platform
To apply, view the application and follow their guidelines
Please let them know that Fractional Jobs sent you!

This Role is Closed

This company has already made a successful hire.
Fractional jobs get filled quickly. To get alerted when new fractional jobs go live, subscribe to our alerts.

This is a Featured Job

100% guarantee that your intro request will be seen
You’ll receive an update within 14 days
If the company is interested, we’ll intro the two of you directly

Weekly Commitment

2 - 3 hrs

Compensation Range

Unknown

Company Stage

Early-stage VC

Industry

Healthtech

Location

Remote (USA only)
moonlight ok
moonlight ok
convert full-time
convert full-time
equity offered
equity offered
hands-on needed
hands-on needed

Note: We've kept the name of the company private. If you'd like to know the company before requesting an intro, just email us at hello [at] fractionaljobs.io

This is a fully remote (work-from-home) position. Work from anywhere in the United States.

Contract / fractional

  • ~15–25 hrs in the first 60 days, then ~5–10 hrs per quarter

About Reflexion

Reflexion Interactive Technologies builds neuro-cognitive and physiological sensing technology — vision-performance training and respiration-waveform sensing — used by athletes, teams, and now a global consumer-eyewear partner. We are a ~10-person, AWS-hosted company based in Lancaster, PA, closing enterprise partnerships that bring enterprise-grade vendor-security requirements with them.

The role

We are hiring a fractional CISO to be the accountable security executive behind our compliance program as we finalize a major enterprise deal. This is not a build-a-SOC, hire-a-team role: our application-layer security is strong (bcrypt, encrypted sessions, CSRF, parameterized SQL, strict CSP, MFA/RBAC, AES-256 at rest, TLS 1.2+), our compliance calendar and evidence pipeline are run day-to-day by an internal compliance system, and engineering is handled by our CTO. What we need is the credentialed human who signs, validates, and represents.

You will work directly with the CEO (deal owner) and CTO (implementation owner). Our internal compliance agent drafts the documents, tracks the obligations register, and maintains the evidence locker — you review, correct, and put your name on what is true.

What you will do — first 60 days

  • Review and harden our Statement of Applicability + evidence package (ISO 27001/NIST-mapped) responding to an enterprise customer's Information Security Addendum — built largely from an existing, customer-reviewed evidence base
  • Sign the risk assessment and SoA as the named security officer; be the security contact enterprise vendor-risk teams can call
  • Sit on 2–3 customer security-diligence calls (enterprise vendor-risk / InfoSec reviewers) alongside the CEO
  • Validate what we attest against reality with the CTO (controls verification and gap triage: centralized logging, admin RBAC/audit trail, secrets management)
  • Advise on a security-exception / compensating-controls request and, if required, scope a right-sized SOC 2 Type I path (RFQs prepared; you would manage auditor selection and the engagement)
  • Scope and manage our first external penetration test (vendor shortlist ready) and own findings triage with the CTO

Ongoing — a few hours a quarter

  • Quarterly review of the compliance-calendar output (access reviews, risk-assessment refresh, training, phishing simulations, BC/DR and restore tests)
  • Annual re-attestation support; named contact for customer audits under contractual audit rights
  • Incident readiness: review our breach-notification runbook (24–72h contractual clocks) and advise if an incident ever triggers it
  • Tell us when a new deal's requirements genuinely change our posture — versus when to negotiate them down. We optimize for minimum-viable compliance and want a partner who respects that philosophy rather than gold-plating

What we are looking for

  • Prior CISO / vCISO / security-lead experience at a company that sold to large enterprises — you have personally survived enterprise vendor-risk review (security questionnaires, information-security addenda, right-to-audit clauses) from the vendor side
  • Hands-on fluency with ISO 27001 / NIST CSF control mapping, SOC 2 (readiness through audit), and pragmatic compensating-controls / security-exception practice
  • Comfortable being the named, accountable individual — signing SoAs and risk assessments, taking customer calls, standing behind attestations
  • Technical enough to verify controls in an AWS + Cloudflare stack with the CTO (IAM, KMS, CloudTrail/logging, network posture) — you do not implement, but you cannot be bluffed
  • Working knowledge of HIPAA applicability analysis (we maintain a no-PHI / not-a-business-associate posture and need it defended, not expanded) and GDPR-adjacent vendor obligations (we have EU counsel; you coordinate, not own)
  • Plain-spoken, fast, allergic to compliance theater. You will be asked "is this actually required, or negotiable?" constantly — we want the honest answer
  • Bonus: consumer wellness / health-adjacent data classification; EU AI Act awareness; prior work with AI-assisted compliance tooling

What this is not

  • Not full-time, and no conversion pressure — genuinely fractional
  • Not a program-build from zero: policies (v1.0), an evidence base, an obligations register, a DPA/SCC pack, and counsel relationships already exist
  • Not an implementation role: engineering changes belong to the CTO; you verify and advise

Engagement & compensation

Hourly contract (rate DOE) or an equivalent small monthly block. Front-loaded first 60 days (~15–25 hours), then ~5–10 hours per quarter. Direct line to the CEO and CTO. NDA required; the work references a Fortune-Global-500-scale counterparty under confidentiality.

​​

How to Apply

Note: This is a syndicated job post. Fractional Jobs found it on the web, but we are not working with the client directly, so we don't have control over or knowledge of the application process. To apply, click on the "View Application" button and follow the application's instructions. Let us know how it goes!


How to Get in Touch

Hit that "Request Intro" button below. Include any relevant links so we can get to know you better.

Your brief intro note should clearly address:


If we think there's a fit, we'll reach out to schedule an intro call. Looking forward!

x
More
Engineering
Jobs

Cars & Bids

 - 

Senior Data Engineer

 

20 hrs
 | 
$80 - $120 / hr
 | 
Remote
Engineering
Syndicated
July 20, 2026
senior-data-engineer-at-cars-bids
added 

Rare Beauty Brands

 - 

Shopify E-Commerce Lead

 

10 - 20 hrs
 | 
$12K - $14K / mo
 | 
Remote
Engineering
Syndicated
July 20, 2026
shopify-e-commerce-lead-at-rare-beauty-brands
added 

Just A Start

 - 

Chief Technology Officer

 

10 - 20 hrs
 | 
Unknown
 | 
Onsite (Boston only)
Engineering
Syndicated
July 20, 2026
chief-technology-officer-at-just-a-start
added 

Ando

 - 

Chief Technology Officer

 

10 - 20 hrs
 | 
Unknown
 | 
Remote (USA / Canada only)
Engineering
Syndicated
July 6, 2026
chief-technology-officer-at-ando
added 

Sandbar Health

 - 

Software Engineer

 

10 - 20 hrs
 | 
$90 - $160 / hr
 | 
Remote
Engineering
Syndicated
July 6, 2026
software-engineer-at-sandbar-health
added 

SmartVerify

 - 

Expert Cloud Consultant

 

10 - 20 hrs
 | 
Unknown
 | 
On-site (Seattle only)
Engineering
Syndicated
July 6, 2026
expert-cloud-consultant-at-smart-verify
added 

A High Finance AI Startup

 - 

Tech Lead

 

(
)
15 hrs
 | 
$150 - $200 / hr
 | 
Remote (USA / Canada only)
Engineering
Syndicated
June 23, 2026
tech-lead-at-a-high-finance-ai-startup
added 

An Operations Intelligence Startup

 - 

Technical Advisor

 

(
)
15 hrs
 | 
$250 - $350 / hr
 | 
Remote (USA only)
Engineering
Syndicated
June 22, 2026
technical-advisor-at-an-operations-intelligence-startup
added 

Send fractional jobs, 

playbooks, and more to

You’re in! Check your inbox to confirm.
We also post job alerts on
&
Hhmm, try again. That didn’t work.