1

Ciso Global Jobs (NOW HIRING)

Fractional CISO This is a fully remote (work-from-home) position. Work from anywhere in the United ... and now a global consumer-eyewear partner. We are a ~10-person, AWS-hosted company based in ...

CISO Opportunity at Rain Rain makes the next generation of payments possible across the globe. We ... We partner with fintechs, neobanks, and institutions to help them launch solutions that are global ...

Head of Security Compliance - CISO - Director of GRC Logical Intelligence is building next ... As our Head of Security Compliance / Head of GRC , you will design, implement, and scale our global ...

CISO

New York, NY · On-site

$250K - $325K/yr

About the Company Rain is the global stablecoin payments platform for enterprises, neobanks ... What You'll Do As CISO, you will own Rain's security governance, risk, and compliance strategy ...

About the Company Rain is the global stablecoin payments platform for enterprises, neobanks ... What You'll Do As CISO, you will own Rain's security governance, risk, and compliance strategy ...

Showing results 41-60

Ciso Global information

See salary details

$70K

$148.7K

$232.5K

How much do ciso global jobs pay per year?

As of Aug 23, 2026, the average yearly pay for ciso global in the United States is $148,746.00, according to ZipRecruiter salary data. Most workers in this role earn between $118,000.00 and $167,500.00 per year, depending on experience, location, and employer.

What is a CISO Global?

A CISO Global, or Chief Information Security Officer at a global level, is an executive responsible for overseeing and managing information security across an entire multinational organization. They develop and implement strategies to protect the organization's digital assets, data, and IT infrastructure from cyber threats. The CISO Global leads teams, sets security policies, ensures compliance with international regulations, and responds to security incidents. Their role also involves communicating risks and strategies to executive leadership and coordinating with global stakeholders to maintain a strong security posture.

What are the key skills and qualifications needed to thrive as a Chief Information Security Officer (CISO)?

To thrive as a Chief Information Security Officer (CISO), you need deep expertise in information security, risk management, and regulatory compliance, typically supported by a degree in computer science or a related field and relevant certifications like CISSP or CISM. Familiarity with security frameworks (e.g., NIST, ISO 27001), incident response tools, and threat intelligence platforms is crucial. Strong leadership, strategic thinking, and effective communication skills help a CISO engage stakeholders and lead security teams. These abilities are essential for protecting organizational assets, ensuring regulatory compliance, and fostering a culture of security across the organization.

What are some common challenges a CISO faces when implementing security initiatives across global teams?

A CISO working at a global level often encounters challenges such as coordinating security policies across diverse regulatory environments, navigating cultural differences, and ensuring consistent security standards across multiple regions. Communication is key, as CISOs must collaborate closely with regional IT leaders, business units, and compliance teams to adapt security measures to local requirements while maintaining overall corporate security objectives. Flexibility, strong stakeholder management, and an understanding of international data privacy laws are essential to successfully lead global cybersecurity initiatives.

What is the difference between Ciso Global vs Security Manager?

AspectCiso GlobalSecurity Manager
CertificationsISO 27001 Lead Implementer, CISSP, CISMCISSP, CISM, Security+
Work EnvironmentGlobal organizations, strategic planning, executive communicationCorporate or organizational security teams, operational focus
Industry UsageUsed across industries with international presenceCommon in specific companies or sectors
Search & Comparison IntentUnderstanding strategic cybersecurity leadership rolesOperational security management roles

The Ciso Global typically holds a strategic, executive-level role overseeing cybersecurity across multiple regions or globally, requiring advanced certifications and a focus on policy and risk management. Security Managers tend to focus on day-to-day security operations within a single organization. While both roles require similar certifications, the scope and responsibilities differ significantly, with the Ciso Global playing a more strategic, high-level role.

More about Ciso Global jobs

What cities are hiring for Ciso Global jobs?

Cities with the most Ciso Global job openings:

What states have the most Ciso Global jobs?

States with the most job openings for Ciso Global jobs include:

Infographic showing various Ciso Global job openings in the United States as of August 2026, with employment types broken down into 100% Full Time. Highlights an 67% In-person, and 33% Remote job distribution, with an average salary of $148,746 per year, or $71.5 per hour.

Fractional CISO

Reflexion

Lancaster, PA • On-site, Remote

Contractor

Re-posted 8 days ago


Job description

Fractional CISO
This is a fully remote (work-from-home) position. Work from anywhere in the United States.
Contract / fractional • ~15-25 hrs in the first 60 days, then ~5-10 hrs per quarter
About Reflexion
Reflexion Interactive Technologies builds neuro-cognitive and physiological sensing technology - vision-performance training and respiration-waveform sensing - used by athletes, teams, and now a global consumer-eyewear partner. We are a ~10-person, AWS-hosted company based in Lancaster, PA, closing enterprise partnerships that bring enterprise-grade vendor-security requirements with them.
The role
We are hiring a fractional CISO to be the accountable security executive behind our compliance program as we finalize a major enterprise deal. This is not a build-a-SOC, hire-a-team role: our application-layer security is strong (bcrypt, encrypted sessions, CSRF, parameterized SQL, strict CSP, MFA/RBAC, AES-256 at rest, TLS 1.2+), our compliance calendar and evidence pipeline are run day-to-day by an internal compliance system, and engineering is handled by our CTO. What we need is the credentialed human who signs, validates, and represents.
You will work directly with the CEO (deal owner) and CTO (implementation owner). Our internal compliance agent drafts the documents, tracks the obligations register, and maintains the evidence locker - you review, correct, and put your name on what is true.
What you will do - first 60 days
  • Review and harden our Statement of Applicability + evidence package (ISO 27001/NIST-mapped) responding to an enterprise customer's Information Security Addendum - built largely from an existing, customer-reviewed evidence base.
  • Sign the risk assessment and SoA as the named security officer; be the security contact enterprise vendor-risk teams can call.
  • Sit on 2-3 customer security-diligence calls (enterprise vendor-risk / InfoSec reviewers) alongside the CEO.
  • Validate what we attest against reality with the CTO (controls verification and gap triage: centralized logging, admin RBAC/audit trail, secrets management).
  • Advise on a security-exception / compensating-controls request and, if required, scope a right-sized SOC 2 Type I path (RFQs prepared; you would manage auditor selection and the engagement).
  • Scope and manage our first external penetration test (vendor shortlist ready) and own findings triage with the CTO.
Ongoing - a few hours a quarter
  • Quarterly review of the compliance-calendar output (access reviews, risk-assessment refresh, training, phishing simulations, BC/DR and restore tests).
  • Annual re-attestation support; named contact for customer audits under contractual audit rights.
  • Incident readiness: review our breach-notification runbook (24-72h contractual clocks) and advise if an incident ever triggers it.
  • Tell us when a new deal's requirements genuinely change our posture - versus when to negotiate them down. We optimize for minimum-viable compliance and want a partner who respects that philosophy rather than gold-plating.
What we are looking for
  • Prior CISO / vCISO / security-lead experience at a company that sold to large enterprises - you have personally survived enterprise vendor-risk review (security questionnaires, information-security addenda, right-to-audit clauses) from the vendor side.
  • Hands-on fluency with ISO 27001 / NIST CSF control mapping, SOC 2 (readiness through audit), and pragmatic compensating-controls / security-exception practice.
  • Comfortable being the named, accountable individual - signing SoAs and risk assessments, taking customer calls, standing behind attestations.
  • Technical enough to verify controls in an AWS + Cloudflare stack with the CTO (IAM, KMS, CloudTrail/logging, network posture) - you do not implement, but you cannot be bluffed.
  • Working knowledge of HIPAA applicability analysis (we maintain a no-PHI / not-a-business-associate posture and need it defended, not expanded) and GDPR-adjacent vendor obligations (we have EU counsel; you coordinate, not own).
  • Plain-spoken, fast, allergic to compliance theater. You will be asked "is this actually required, or negotiable?" constantly - we want the honest answer.
  • Bonus: consumer wellness / health-adjacent data classification; EU AI Act awareness; prior work with AI-assisted compliance tooling.
What this is not
  • Not full-time, and no conversion pressure - genuinely fractional.
  • Not a program-build from zero: policies (v1.0), an evidence base, an obligations register, a DPA/SCC pack, and counsel relationships already exist.
  • Not an implementation role: engineering changes belong to the CTO; you verify and advise.
Engagement & compensation
Hourly contract (rate DOE) or an equivalent small monthly block. Front-loaded first 60 days (~15-25 hours), then ~5-10 hours per quarter. Direct line to the CEO and CTO. NDA required; the work references a Fortune-Global-500-scale counterparty under confidentiality.
How to apply
Send a short note covering: (1) an enterprise vendor-security review you got a small company through - what you accepted and what you pushed back on; (2) your hourly rate and availability over the next 60 days. Resume/LinkedIn welcome; the note matters more.