Fractional CISO (vCISO)
Arcanys · Australia, Philippines ·
- Work mode
- Remote
- Category
- Security
- Company size
- 201-500
Arcanys · Australia, Philippines ·
10xteam · The Netherlands
Austco · Irving, US
Cyncly · United States
ArcelorMittal · Maizieres-les-Metz, Grand Est, France
Fractional CISO (vCISO) for Arcanys, a Swiss software development partner with a 300+ person Philippine operation, to drive an enterprise-grade security posture: 12-month security roadmap, mentoring IT/dev leads on secure coding, GDPR/privacy compliance, incident and policy management, and security advisory for its venture portfolio. Core focus areas: SOC 2/ISO 27001, SDLC and CI/CD security, AWS,
Arcanys is a high-growth Swiss software development partner with a 300+ person operation in the Philippines. We are looking for a Fractional CISO (Chief Information Security Officer) to transition our security posture to "enterprise-grade".
Proven experience leading security governance in mid-sized companies (200–500 employees), including SOC 2 or ISO 27001 certification, ideally in outsourcing/software services companies.
Strong technical foundation across SDLC, CI/CD security, and cloud platforms (AWS, Google Workspace).
Effective communicator and mentor, able to explain security concepts to both junior technical staff and non-technical stakeholders.
Experience handling client security audits and vendor assessments.
Experience working with distributed teams (Europe/Asia/Australia) and with early-stage startups is a plus.
Relevant certifications such as CISSP, CISM, or CISA preferred.
Design a 12-month security roadmap that balances "Swiss Quality" expectations with the agility of a software outsourcing firm.
Establish a Risk Register and prioritize remediation based on business impact.
Act as the direct mentor to our IT Manager, transforming technical tasks into security controls.
Establish "Security Office Hours" to train our lead developers on secure coding (OWASP) and DevSecOps.
Ensure all data handling meets the European GDPR, the Philippines Data Privacy Act and the Australian Privacy Act standards, among other regulations.
Standardize our response to client security questionnaires to accelerate the sales cycle.
Draft and implement core policies (Incident Response, Access Control, BCP/DR) that are practical, not just theoretical.
Oversee the selection and implementation of essential security tools (EDR, SIEM, Vulnerability Scanners) without over-complicating the stack.
Define a "Right-Sized" security framework for Arcanys Ventures’ portfolio companies, ensuring they have essential protections without stifling their growth or speed.
Assist the leadership team during the investment process by evaluating the technical security and data privacy risks of potential new ventures.
Act as a fractional advisor for our startups, helping their founders establish basic security policies, data privacy compliance (GDPR/DPA), and a "Security by Design" culture from day one.
Reflexion · Lancaster, PA