Reflexion Capital identifies and invests in high-potential B2B SaaS companies willing to embrace high growth profile & reaching profitability soon. Join our investors’ club today.
About the role
We are hiring a fractional CISO to be the accountable security executive behind our compliance program as we finalize a major enterprise deal. This is not a build-a-SOC, hire-a-team role: our application-layer security is strong (bcrypt, encrypted sessions, CSRF, parameterized SQL, strict CSP, MFA/RBAC, AES-256 at rest, TLS 1.2+), our compliance calendar and evidence pipeline are run day-to-day by an internal compliance system, and engineering is handled by our CTO.
What they're looking for
- Hands-on fluency with ISO 27001 / NIST CSF control mapping, SOC 2 (readiness through audit), and pragmatic compensating-controls / security-exception practice
- Comfortable being the named, accountable individual — signing SoAs and risk assessments, taking customer calls, standing behind attestations
- Technical enough to verify controls in an AWS + Cloudflare stack with the CTO (IAM, KMS, CloudTrail/logging, network posture) — you do not implement, but you cannot be bluffed
- Plain-spoken, fast, allergic to compliance theater. You will be asked "is this actually required, or negotiable?" constantly — we want the honest answer
- Bonus: consumer wellness / health-adjacent data classification, EU AI Act awareness, prior work with AI-assisted compliance tooling
More about this role
This is a fully remote (work-from-home) position. Work from anywhere in the United States.
Contract / fractional · ~15–25 hrs in the first 60 days, then ~5–10 hrs per quarter
Reflexion Interactive Technologies builds neuro-cognitive and physiological sensing technology — vision-performance training and respiration-waveform sensing — used by athletes, teams, and now a global consumer-eyewear partner. We are a ~10-person, AWS-hosted company based in Lancaster, PA, closing enterprise partnerships that bring enterprise-grade vendor-security requirements with them.
We are hiring a fractional CISO to be the accountable security executive behind our compliance program as we finalize a major enterprise deal. This is not a build-a-SOC, hire-a-team role: our application-layer security is strong (bcrypt, encrypted sessions, CSRF, parameterized SQL, strict CSP, MFA/RBAC, AES-256 at rest, TLS 1.2+), our compliance calendar and evidence pipeline are run day-to-day by an internal compliance system, and engineering is handled by our CTO. What we need is the credentialed human who signs, validates, and represents.
You will work directly with the CEO (deal owner) and CTO (implementation owner). Our...
Browse similar: Venture capital jobs · Remote jobs