About The Position

This role is unique as it allows you to work directly with some of the most innovative unicorns as their trusted CISO. You will dive deep into technical security challenges and be the hands-on security expert that fast-growing companies desperately need, putting your fingerprint on rapidly expanding security programs. You will shape security strategies for companies that are disrupting entire industries.

Requirements

  • 10+ years of hands-on information security experience with deep technical expertise, client-facing and/or consulting experience.
  • Proven track record as a CISO or senior security leader at high-growth technology companies.
  • Expertise in cloud security (AWS, Azure, GCP) with the ability to review Terraform/CloudFormation.
  • Hands-on experience with security tools (SIEM, CSPM, vulnerability scanners, etc.).
  • Deep understanding of modern development practices (CI/CD, containerization, Kubernetes).
  • Experience working directly with engineering teams in fast-paced startup environments.
  • Track record of implementing security programs at companies scaling from Series A to IPO.
  • Excellent technical communication skills with the ability to explain complex issues clearly.

Nice To Haves

  • Background in software engineering or DevOps before moving to security.
  • Hands-on experience with security automation and infrastructure-as-code.
  • Active in the security community (bug bounties, research, open source contributions).
  • Professional certifications (CISSP, OSCP, AWS Security) backed by real-world experience.

Responsibilities

  • Embed directly with 7-10 high-growth clients as their fractional CISO, becoming an integral part of their leadership team.
  • Architect security solutions, analyze infrastructure, and configure security tools.
  • Work side-by-side with client engineering teams to implement security controls.
  • Provide immediate security guidance in Slack, customer calls, etc.
  • Collaborate with GTM teams to unblock deals due to security questionnaires.
  • Build deep, trusted relationships with CTOs, VPs of Engineering, and founders.
  • Participate in daily standups, sprint planning, and engineering discussions as needed.
  • Provide real-time security guidance during product development and feature releases.
  • Be available for impromptu security consultations and 'quick questions'.
  • Serve as the calm, knowledgeable voice during security incidents and critical decisions.
  • Guide clients through SOC 2, ISO 27001, and other certifications/compliance frameworks.
  • Write and review policies, create risk registers, and manage third-party risk for clients.
  • Conduct hands-on gap assessments and build remediation roadmaps.
  • Work directly with auditors, answering technical questions and providing evidence.
  • Transform compliance from a checkbox exercise into meaningful security improvements.
  • Review infrastructure-as-code for security best practices.
  • Analyze cloud configurations and recommend hardening measures.
  • Evaluate and implement security tools, often doing the initial setup yourself.
  • Create security runbooks and automation scripts.
  • Provide code-level guidance on secure development practices.
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service