Fractional CISO

ReflexionLancaster, PA
Remote

About The Position

Reflexion Interactive Technologies is seeking a Fractional CISO for a fully remote position, allowing work from anywhere in the United States. This role is contract-based and requires approximately 15-25 hours in the first 60 days, then 5-10 hours per quarter. Reflexion, a ~10-person company hosted on AWS, develops neuro-cognitive and physiological sensing technology. As the company finalizes a major enterprise deal, they require an accountable security executive to oversee their compliance program. This is not a role focused on building a Security Operations Center (SOC) or managing a team. The company has strong application-layer security, an internal compliance system for managing their calendar and evidence, and the CTO handles engineering. The primary need is for a credentialed individual to sign, validate, and represent the company's security posture.

Requirements

  • Prior CISO / vCISO / security-lead experience at a company that sold to large enterprises.
  • Personal experience navigating enterprise vendor-risk reviews (security questionnaires, information-security addenda, right-to-audit clauses) from the vendor side.
  • Hands-on fluency with ISO 27001 / NIST CSF control mapping.
  • Experience with SOC 2 (readiness through audit).
  • Proficiency in pragmatic compensating-controls / security-exception practice.
  • Comfort being the named, accountable individual, signing SoAs and risk assessments, taking customer calls, and standing behind attestations.
  • Technical understanding to verify controls in an AWS + Cloudflare stack with the CTO (IAM, KMS, CloudTrail/logging, network posture).
  • Working knowledge of HIPAA applicability analysis and ability to defend a no-PHI / not-a-business-associate posture.
  • Understanding of GDPR-adjacent vendor obligations.
  • Ability to provide plain-spoken, fast answers and avoid compliance theater.
  • Ability to constantly assess if requirements are actually required or negotiable.

Nice To Haves

  • Consumer wellness / health-adjacent data classification experience.
  • EU AI Act awareness.
  • Prior work with AI-assisted compliance tooling.

Responsibilities

  • Review and harden the Statement of Applicability (SoA) and evidence package (ISO 27001/NIST-mapped) in response to an enterprise customer's Information Security Addendum.
  • Sign the risk assessment and SoA as the named security officer.
  • Serve as the security contact for enterprise vendor-risk teams.
  • Participate in customer security-diligence calls with the CEO.
  • Validate attestations against reality with the CTO, including controls verification and gap triage (centralized logging, admin RBAC/audit trail, secrets management).
  • Advise on security-exception / compensating-controls requests.
  • Scope a right-sized SOC 2 Type I path if required.
  • Scope and manage the first external penetration test and own findings triage with the CTO.
  • Perform quarterly reviews of the compliance calendar output (access reviews, risk-assessment refresh, training, phishing simulations, BC/DR and restore tests).
  • Provide support for annual re-attestation and act as the named contact for customer audits.
  • Review the breach-notification runbook and advise on incident response.
  • Identify when new deal requirements genuinely change the company's security posture versus when they are negotiable.

Benefits

  • Fully remote (work-from-home) position.
  • Work from anywhere in the United States.
  • Contract / fractional engagement.
  • Direct line to the CEO and CTO.
  • Hourly contract (rate DOE) or equivalent small monthly block.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service