At a Glance
- Tasks: Lead security strategy and ensure compliance while preparing for SOC 2 readiness.
- Company: Dynamic fintech company focused on European expansion and innovation.
- Benefits: Flexible working arrangements, competitive salary, and opportunities for professional growth.
- Why this job: Make a significant impact on security practices in a rapidly growing organisation.
- Qualifications: 8+ years in information security with strong cloud security experience.
- Other info: Join a collaborative team and foster a security-first culture.
The predicted salary is between 36000 - 60000 ÂŁ per year.
We are seeking an experienced Fractional CISO to provide hands‑on security leadership as we evolve our security function to support continued growth and European expansion. This is a permanent fractional engagement reporting directly to the CTO. You will own our information security strategy, maintain our ISO 27001 certification, build our security roadmap, and prepare the organisation for SOC 2 readiness in 2026‑2027. This role requires someone who can operate both strategically and tactically — developing policy one day and reviewing cloud configurations the next.
Key Responsibilities
- Strategy & Governance
- Develop and own the Information Security strategy aligned with ApprovalMax's business objectives and European expansion plans
- Maintain and continuously improve the Information Security Management System (ISMS)
- Create, review, and maintain core security policies, standards, and procedures
- Establish and chair a cross‑functional Security Working Group (Engineering, Architecture, IT, HR)
- Build and present a multi‑year security roadmap with clear milestones, resource requirements, and priorities
- Serve as the central authority on risk assessment, risk treatment, and risk acceptance decisions
- Assess and provide guidance on secure AI adoption across the organisation, including AI‑powered product features and internal AI tooling
- Compliance & Certification
- Maintain ISO 27001 certification and prepare for the 2027 recertification audit
- Lead SOC 2 Type II readiness programme (target: 2026‑2027), including gap analysis and control mapping
- Ensure compliance with GDPR and data protection requirements across EU/UK/US/AU/NZ/CA/ZA jurisdictions
- Collaborate with external DPO support provider on privacy‑related matters and customer security questionnaires as needed
- Cloud & Technical Security
- Provide security oversight across Azure, AWS, and Google Workspace environments
- Conduct access reviews and advise on identity and access management best practices
- Evaluate and guide implementation of security tooling (SIEM, vulnerability management, endpoint protection)
- Oversee VMware Workspace ONE MDM deployment and device security policies
- Advise engineering teams on secure SDLC practices, DevSecOps integration, and application security principles
- Operational Security
- Develop and maintain incident response plans and procedures
- Lead incident response tabletop exercises and post‑incident reviews
- Provide guidance on business continuity and disaster recovery planning
- Advise on vendor security assessments and third‑party risk management
- Awareness & Culture
- Design and deliver company‑wide security awareness training programmes
- Mentor and upskill internal staff on security best practices
- Foster a security‑first culture across all departments
- Act as a trusted advisor to leadership on emerging threats and security trends
- Stakeholder Engagement
- Report regularly to the CTO on security posture, risks, and programme progress
- Prepare board‑level security presentations as required (infrequent)
- Support commercial teams by contributing to customer security discussions when escalated
Qualifications
- 8+ years of progressive experience in information security, with at least 3 years in a CISO, Head of Security, or senior security leadership role
- Demonstrated experience in B2B SaaS environments, ideally in fintech, finance software, or similarly regulated industries
- Proven track record of achieving and maintaining ISO 27001 certification
- Experience preparing organisations for SOC 2 Type II certification
- Hands‑on experience securing cloud environments (Azure and/or AWS required; GCP a plus)
- Experience with Google Workspace security configuration and administration
- Background working with distributed, remote‑first engineering teams
Technical Knowledge
- Strong understanding of cloud security architecture, identity management, and zero‑trust principles
- Familiarity with secure software development lifecycle (SDLC) and DevSecOps practices
- Knowledge of MDM solutions (VMware Workspace ONE experience preferred)
- Understanding of API security and integration risk management
- Practical experience with security tooling: SIEM, vulnerability scanners, endpoint protection, etc.
- Awareness of AI/ML security risks, including secure AI adoption practices and emerging AI governance frameworks (desirable)
Compliance & Regulatory
- Deep knowledge of ISO 27001:2022 requirements and audit processes
- Familiarity with SOC 2 Trust Service Criteria (Security, Availability, Confidentiality, Privacy)
- Understanding of GDPR, UK Data Protection Act, and international data protection regulations
Fractional Chief Information Security Officer employer: Gofractional
Contact Detail:
Gofractional Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Fractional Chief Information Security Officer
✨Tip Number 1
Network like a pro! Get out there and connect with folks in the industry. Attend meetups, webinars, or even just grab a coffee with someone who’s already in the role you want. You never know who might have the inside scoop on job openings!
✨Tip Number 2
Show off your skills! If you’ve got a portfolio or any projects that highlight your expertise in information security, make sure to share them during interviews. It’s a great way to demonstrate your hands-on experience and strategic thinking.
✨Tip Number 3
Prepare for those tricky interview questions! Think about how you’d tackle real-world scenarios related to security strategy and compliance. Practising your responses can help you feel more confident and ready to impress.
✨Tip Number 4
Don’t forget to apply through our website! We’re always on the lookout for talented individuals like you. Plus, it’s a straightforward way to ensure your application gets seen by the right people.
We think you need these skills to ace Fractional Chief Information Security Officer
Some tips for your application 🫡
Tailor Your Application: Make sure to customise your CV and cover letter to highlight your experience in information security, especially in relation to ISO 27001 and SOC 2. We want to see how your skills align with our needs, so don’t hold back on showcasing your relevant achievements!
Showcase Your Strategic and Tactical Skills: Since this role requires both strategic thinking and hands-on execution, give us examples of when you've successfully balanced these two aspects. Whether it’s developing a security policy or diving into cloud configurations, we want to know how you’ve done it!
Highlight Your Compliance Experience: We’re keen on candidates who have a solid grasp of compliance frameworks like GDPR and ISO 27001. Share specific instances where you’ve maintained certifications or led readiness programmes, as this will really make your application stand out to us.
Apply Through Our Website: Don’t forget to submit your application through our website! It’s the best way for us to receive your details and ensures you’re considered for the role. Plus, it shows you’re serious about joining our team at StudySmarter!
How to prepare for a job interview at Gofractional
✨Know Your Stuff
Make sure you brush up on your knowledge of ISO 27001 and SOC 2 requirements. Be ready to discuss how you've maintained certifications in the past and any specific challenges you've faced. This role is all about security strategy, so showing that you can navigate these frameworks will impress the interviewers.
✨Show Your Hands-On Experience
Since this position requires both strategic and tactical skills, be prepared to share examples of when you've developed policies and also rolled up your sleeves to review cloud configurations. Highlight your experience with Azure and AWS, as well as any tools you've implemented for security oversight.
✨Engage with the Team
This role involves collaboration across various departments, so demonstrate your ability to work with cross-functional teams. Share experiences where you've chaired meetings or led discussions on security policies. Showing that you can foster a security-first culture will resonate well with the interviewers.
✨Prepare for Scenario Questions
Expect to face scenario-based questions that test your incident response and risk management skills. Think of specific incidents you've managed and how you approached them. Being able to articulate your thought process and decision-making will showcase your expertise and readiness for the role.