Overview
We are looking for CISO Mentor to join us for several hours per months.
Responsibilities:
- Improve and maintain perimeter and network-layer defenses (WAF, Rate Limiting, Anti-bot ,DDoS mitigation
- Secure product APIs against abuse and anomalous traffic
- Strengthen authentication, authorization, and access control at the product level, including IDOR-class issues
- Run the Vulnerability Management process: identification, prioritization, and remediation tracking
- Coordinate external pentests and drive remediation of findings
- Lead Incident Response for product security incidents
- Build detection and response processes together with the monitoring team
- Contribute to Fraud & Trust and Safety initiatives with relevant teams
- Protect customer data at the product level (access control, encryption, masking)
- Run the Security Champions program to train product teams on secure development
- Manage the Bug Bounty program
Required Qualifications:
- 7+ years in senior Information Security leadership (CISO, VP of Security, or Head of InfoSec), with a proven track record of mentoring or advising emerging security leaders.
- Zero-to-One Experience: Proven experience building, scaling, and managing an Information Security program entirely from scratch for a startup or scaling enterprise.
- High-Compliance Expertise: Deep, practical knowledge of operating in heavily regulated markets (e.g., FinTech, HealthTech, GovTech) and successfully leading organizations through rigorous audits (SOC 2 Type II, ISO 27001, PCI-DSS, HIPAA, or GDPR).
- Highload/Scalability Acumen: Strong architectural understanding of securing high-throughput, highly available, distributed systems and cloud-native environments (AWS/GCP/Azure) without bottlenecking performance.
- Strategic GRC (Governance, Risk, and Compliance): Ability to teach and establish risk management frameworks, compliance roadmaps, and vendor risk management processes.
- Executive Communication: Exceptional ability to translate complex technical risks into business impacts, and experience coaching others on how to present security strategies to C-level executives and the Board of Directors.
- Incident Response Leadership: Experience establishing and commanding an enterprise-grade Incident Response plan, including crisis management and post-breach communications.
- Security Culture Building: Demonstrated ability to foster a security-first culture across engineering, product, and business teams.
- Fluent Russian
- Information Security
- GRC
- Incident Response
- Security Culture
Technologies:
- WAF
- AWS
- GCP
- Azure
Note:
✨ Our intelligent job search engine discovered this job and republished it for your convenience.
Please be aware that the job information may be incorrect or incomplete. The job announcement remains the property of its original publisher. To view the original job and its full details, please visit the job's URL on the owner’s page.
Please clearly mention that you have heard of this job opportunity on https://ijob.am.

