Chief Information Security Officer (CISO)
Ryde Technologies, LLC
Job Description
Job Description
Chief Information Security Officer (CISO) / Head of Information Security
ABOUT THE ROLE
This is not a purely strategic, oversight-level CISO role. The company is looking for a security leader who is genuinely hands-on: someone who can personally architect and troubleshoot cloud security controls, not just direct a team that does. You will set enterprise security strategy and own governance, but you are expected to be the one in the room who can spontaneously whiteboard how to secure an AWS environment end to end, size a VPC, and explain why a given control matters for CJIS audit evidence, not delegate that conversation to an engineer.
You will also function as a customer-facing, revenue-enabling part of the business. Clients are government agencies and their sponsors, and this role routinely acts as a de facto technical sales resource, presenting security posture directly to prospects and agency stakeholders, not just responding to audits from behind the scenes. Comfort in that kind of client-facing, almost sales-adjacent conversation is a requirement, not a nice-to-have.
Reporting to the CTO, you will own cybersecurity, data protection, regulatory compliance, and information-security risk management, working closely with product, engineering, DevOps, legal, sales, and client stakeholders to embed security across the organization and protect the trust of the agencies and communities it serves.
WHAT YOU WILL OWN PERSONALLY
This is a build role before it is a management role. The security function is growing, and in the early stretch the work is yours to execute directly:
- Sizing and reviewing AWS network design yourself: VPC and subnet layout, routing, security groups and NACLs, gateway placement, multi-AZ architecture, and Flow Logs as forensic and audit evidence
- Writing and defending the control evidence behind CJIS 6.1 and FedRAMP ConMon, including POA&M items, monthly scan results, and direct questions from 3PAOs and agency sponsors
- Serving as the security voice on client and prospect calls, walking agency stakeholders through posture, completing security questionnaires, and supporting RFP and RFI responses firsthand
- Leading live incidents as the decision maker while staying in the technical detail rather than handing the response to an engineer
- Selecting tooling and standing up what does not exist yet: SIEM and monitoring, AppSec scanning, supply chain controls, and third-party risk process
- As the program matures, you will build and lead the team that carries this forward. The expectation is that you have done the work yourself first.
KEY RESPONSIBILITIES
Security Strategy and Governance
- Develop and run the enterprise information security strategy, policies, standards, and control requirements across the business
- Advise the CEO, CTO, executive leadership, and Board directly, with regular briefings on risk, program maturity, and mitigation priorities
- Define and report on security KPIs, risk indicators, and maturity assessments
- Evaluate and bring in AI-assisted security tooling where it genuinely improves detection, response, or automation
- Own the security budget: planning, prioritization, and justifying investment to leadership and the Board
Compliance and Regulatory Oversight (state-driven, not a single federal-standard-first program)
- Own compliance with CJIS Security Policy, including the transition to CJIS 6.0 (phishing-resistant MFA, FIPS 140-3 encryption, remote-work controls, updated cloud security requirements)
- Lead FedRAMP authorization and ongoing Continuous Monitoring, including direct coordination with 3PAOs and federal agency sponsors, monthly vulnerability scanning, POA&M management, and annual assessments
- Run the SOC 2 Type II program and the ISO 27001 ISMS: audits, management reviews, risk treatment, certification body relationships
- Tailor CJIS, FedRAMP, SOC 2, and ISO 27001 posture to what each individual client agency actually requires; NIST 800-53 is treated as one input among several rather than a standalone initiative, since only a minority of client states reference it directly
- Ensure data privacy, residency, sovereignty, and information-lifecycle practices meet public-sector and criminal-justice client requirements
- Own the cyber insurance program and work with legal on breach response and contractual security obligations
- Be the primary point of contact for client security assessments, audits, and questionnaires
- Support sales directly: RFP and RFI responses, proactive relationship-building with client-side security leaders, and hands-on participation in prospect and agency-sponsor conversations as a technical resource for the sales motion
Incident Response and Threat Management
- Build, maintain, and stress-test the incident response plan through tabletops and simulations
- Stand up or oversee SOC capabilities: SIEM, 24/7 monitoring, detection and escalation aligned to FedRAMP ConMon and CJIS requirements
- Lead the organization through real incidents and breaches as executive decision maker, while staying technically engaged in the response rather than delegating it entirely
- Own vulnerability management, penetration testing, and threat intelligence
- Manage external security partners, MSSPs, and law enforcement contacts as needed
- Ensure breach notification is timely and legally compliant
Security Architecture and Engineering Partnership (working technical depth required, not vocabulary familiarity)
- Partner with product, engineering, and DevOps so security-by-design is embedded in the SDLC
- Personally review and approve security architecture for new products, features, and infrastructure changes, including hands-on evaluation of network design (VPC and subnet layout, routing, security groups, NACLs, NAT and internet gateways, multi-AZ design, VPC Flow Logs as a forensic and audit-evidence control)
- Own IAM, encryption standards, data classification, and data residency and sovereignty controls for government clients
- Own AWS security posture end to end, including AWS GovCloud environments, using GuardDuty, Security Hub, CloudTrail, AWS Config, IAM, KMS, and AWS WAF, aligned to the AWS Shared Responsibility Model
- Manage software supply chain security: SBOM, dependency vulnerability scanning, secure CI/CD pipeline controls, artifact integrity, code signing
- Own the AppSec program: SAST, DAST, and SCA tooling, secure code review standards, release gates, responsible disclosure process
- Ensure remote workers handling CJI meet CJIS 6.0 physical security requirements
- Drive Zero Trust adoption in line with federal guidance (OMB M-22-09)
Security Awareness and Training
Design and run a company-wide security awareness program covering role-specific risk, CJIS obligations, and client agreements, including technical training on secure coding, data handling, and safe AI tool use. Track completion and effectiveness, and iterate as the threat landscape changes.
Business Continuity and Disaster Recovery
Build, maintain, and test BC/DR plans aligned with CJIS requirements, the FedRAMP Contingency Planning control family, and ISO 27001 Annex A.17, addressing CJI protection, AWS infrastructure resilience, and client SLA commitments.
Vendor and Third-Party Risk Management
Stand up and run a third-party risk program covering vendor assessments, due diligence, and ongoing monitoring, and define the contractual security requirements that cloud and technology partners must meet.
EDUCATION AND CERTIFICATION REQUIREMENTS
- Bachelor's degree in computer science, information security, information technology, or related field required; master's preferred
- CISSP, CISM, or equivalent required, or obtainable within 12 months of hire
- CJIS Security Awareness Training required, or obtainable within 90 days of hire
- Preferred: CCSP, AWS Certified Security - Specialty, CISA, FedRAMP-related training or certification
REQUIRED KNOWLEDGE, SKILLS, AND EXPERIENCE
- 10+ years of progressive information security experience, including 3 to 5+ years in a senior leadership role
- Genuine hands-on fluency in cloud security architecture and networking: can independently size a VPC CIDR range, determine subnetting needs for a multi-tier architecture, explain routing, security groups, and NACLs, and articulate the value of VPC Flow Logs as a forensic and audit-evidence control, not just recognize the terms
- Deep, implementation-level knowledge of CJIS Security Policy (including v6.0), gained by actually building and running compliant programs, not solely coordinating or overseeing external audits
- Hands-on experience leading or maintaining a FedRAMP ATO and ConMon program, including direct 3PAO and agency sponsor coordination
- Proven ownership of a SOC 2 Type II program and, ideally, direct ISO 27001 ISMS implementation or maintenance
- Working familiarity with NIST CSF, NIST 800-53, and CIS Controls as supporting frameworks, understood in the context of a state-by-state, client-driven compliance posture rather than a NIST-first program
- Experience building and running incident response programs, including leading live incidents while staying technically hands-on rather than defaulting to pure strategic oversight
- Comfort operating in a customer-facing, revenue-enabling capacity: presenting security posture to clients and agency sponsors, supporting RFPs, and functioning credibly as a technical resource within the sales process
- Experience working in or directly with Criminal Justice, Public Safety, or Government sectors strongly preferred; this is foundational to the role, not a nice-to-have
- Real, current experience securing AWS environments including AWS GovCloud, with working fluency (not passing familiarity) in GuardDuty, Security Hub, IAM, KMS, CloudTrail, Config, and WAF
- Strong understanding of data privacy, residency, sovereignty, and PII and CJI lifecycle management for government clients
- Experience with cyber insurance programs and coordinating with legal on breach response and contractual obligations
- Familiarity with Zero Trust architecture and federal mandates (OMB M-22-09)
- Demonstrated ability to build and lead security teams while managing external vendors and partners, with the hands-on depth to execute the work directly before that team is in place
- Executive communication skills, with the ability to translate technical and regulatory risk into business terms for non-technical stakeholders
EEO Compliance:
Ryde is an Equal Employment Opportunity/Affirmative Action Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, age, sexual orientation, gender identity, national origin, disability, protected veteran status, or any other characteristic protected by law. Ryde will consider qualified applicants with criminal histories in a manner consistent with the requirements of applicable law.
- ...Chief Information Security Officer (CISO)The Chief Information Security Officer (CISO) is the executive leader responsible for all cybersecurity and data protection needs across HOPCo. This leader is tasked with proactively ensuring all systems, networks, methods of storing...SuggestedWork at office
- ...Chief Information Security Officer (CISO) About the Company Innovative provider of data safety & recovery solutions Industry Information Technology and Services Type Privately Held Founded 2024 Employees 51-200 Specialties cloud backup...Suggested
- Chief Information Security Officer (CISO) / Head of Information Security Overview We are seeking an experienced Information Security Leader to define and execute a comprehensive enterprise security strategy. This role is responsible for safeguarding systems, data, and...SuggestedWork at officeRemote work3 days per week
$275k - $305k
...resolution services business, and over $11Bn in personal and home loans originations via our banking‑as‑a‑service partner. Chief Information Security Officer (CISO) is responsible for establishing and executing the enterprise cybersecurity strategy for a high‑growth, private...SuggestedContract workRemote workWork from homeShift work- ...Chief Information Security Officer (CISO), Information Security & Compliance About the Company Innovative artificial intelligence (AI) & marketing analytics platform Industry Information Technology and Services Type Public Company Founded 2014...Suggested
- ...Deputy Chief Information Security Officer (CISO), Security Technology About the Company Popular provider of revenue cycle management solutions Industry Hospital & Health Care Type Privately Held, Private Equity-backed Founded 2003 Employees...
- ...Job Description Job Description Virtual Chief Information Security Officer ● cloudIT ● Phoenix, AZ ● In-Office Phoenix's small and... ...of clients who do not have and cannot afford a full-time CISO. You will work from our Phoenix office, managing multiple...Full timeWork at officeShift work
- ...Field Chief Information Security Officer (CISO) About the Company Industry leading provider of security & compliance solutions Industry Outsourcing/Offshoring Type Privately Held Founded 2020 Employees 501-1000 Funding $200+ million Categories...Remote work
- ...Technology Team as a Telecommunications Manager located in various offices.We are seeking a professional who thrives in a fast-paced,... ...guide the firm through technology transitions—with emphasis on security, compliance, and business continuity.Key ResponsibilitiesStrategic...Full timeContract workRemote work
- ...band, VHF, UHF, 800 MHz base station/repeater 2-way radios; site security alarm and control equipment; site grounding grids, etc.).14.... ...land mobile systems maintained by DPS.gathering technical information for trouble calls from non-technical personnel.maneuvering and...Work experience placementWork at officeLocal areaRemote workFlexible hoursNight shift
- ...Chief Information Officer (CIO) and Chief Technology Officer (CTO) About the Company Expanding company in the payments & neo banking sectors... ...tasked with overseeing the development and maintenance of secure, scalable, and efficient payment solutions, and ensuring compliance...Remote work
- ...Chief Trust Officer (CTO) About the Company Highly respected wealth management firm with boutique, client-centric service for sophisticated families. Industry Financial Services Type Privately Held About the Role The Company is in search of a Chief...
- Welcome to the future of cloud networking and security! Cato Networks is the first company to converge enterprise networking and security... ...leader - don’t miss it! We are looking for an exceptional Field CISO to join Cato’s strategy organization. This is a senior executive...Worldwide
- ...protocol addressing. Solid working knowledge of the Microsoft Office suite of applications, including Word, Excel and Outlook. Good... ...agency program staff and agency senior management (25%)Additional Information- "All your information will be kept confidential according to...Contract workWork at officeLocal areaImmediate startFlexible hours
$82.28k - $108.77k
...advantage of tax‑deferred retirement investments. On, or shortly after, your first day of work you will be provided with additional information about the available insurance plans, enrollment instructions, submission deadlines and effective dates. Contact Us: The State of...Temporary workWork experience placement- Part-Time Chiropractor - Ownership Track Opportunity NuSpine Chiropractic is a rapidly expanding franchise system redefining modern chiropractic care through clinical excellence, operational precision, affordability, and meaningful patient relationships. Our examinations...Part timeImmediate start
$80k
...benefit programs, which may vary. Ready to Join the Movement? Apply today and start moving your career in the direction you want. For more information, visit or follow the brand on Facebook ( , Instagram ( , Twitter ( , YouTube ( and LinkedIn ( . Powered by JazzHR...Full timeImmediate startWeekend work$80k
Chiropractor – Full TimeThe Joint Chiropractic is seeking a dedicated and motivated Chiropractor to join our growing team. This full-time role focuses on delivering exceptional patient care in a supportive, streamlined environment, allowing you to focus on what you do ...Full timeWeekend work- ...Arsenault is searching for a Chief Information Officer (US) on behalf of our client, the leading publisher of Career and Technical Education... ...will be a key focus, along with customer satisfaction and security. The CIO will support and lead teams in Digital Media and...Work at office
$135k - $175k
...Arizona | Scottsdale, ArizonaCompany: DEPCOM PowerCareer Field: Information Systems & TechnologyJob Number: 190311Eligible for remote:... ...FERC standardsExperience with Fortinet and Cisco networking and security platforms, including FortiGate firewalls, FortiManager, and Cisco...Contract workFor subcontractorRemote workFlexible hours- FM Industries in Phoenix, AZ is seeking an IT System Administrator / Cyber Security Analyst to design, implement, and maintain enterprise IT infrastructure while proactively managing the organization’s security posture. You will administer Windows and Linux servers, AD...
- ...Managing Director, Chief Technology Officers Practice, Retained Search About the Company Dynamic executive search firm specializing in... ...responsibilities. The position is pivotal in helping clients make informed leadership decisions and is suited to individuals who...
- The City of Peoria is seeking a DFU Detective for the Police Department. Responsibilities include recovering and analyzing electronic evidence, maintaining chain of custody, and supporting patrol as needed. Qualified applicants will have at least three years in DFU roles...
- ...recommend scalable solutions Ensure reliability, performance, security, and efficiency of business systems and client-facing services... ...Preferred Qualifications Bachelor’s degree in Information Technology, Computer Science, Business, or related field; equivalent...
- ...Regional Field Chief Technology Officer (CTO) About the Company Globally recognized provider of automated solutions for securing & managing open source software Industry Computer... ...to translate complex technical information into clear narratives for both technical...
$80k
Chiropractor Position at LifeClinic At LifeClinic, our mission is to restore, maintain, and optimize human function and performance. As a chiropractor here, you'll provide adjustments, soft tissue work, and rehab exercises inside Life Time facilities. We're already ...Temporary workRelocationDay shift- ...partner to Optiv’s clients. By combining sales skills and broad security practitioner knowledge, the SA designs security solutions for... ...at clients by facilitating thought leadership, support, information, and guidance in conjunction with sales partners. Maintain strong...Full timeWork experience placementLocal areaRemote workWork from home
- ...Cisco enterprise networking and network security and helps clients translate business requirements... ...architecture recommendations.Advise CISOs, CIOs, network leaders, security leaders... ...40 and over, marital status, genetic information, national origin, status as an...Full timeLocal areaRemote workWork from home
- ...partner to Optiv’s clients. By combining advanced business and security practitioner knowledge, the Principal AI Cybersecurity Advisor... ...at clients by facilitating thought leadership, support, information, and guidance in conjunction with sales partnersMaintain strong...Full timeLocal areaRemote workWork from home
- ...Chief Technology Officer (CTO) About the Company Global talent marketplace connecting businesses with top freelance professionals in various... ...010 Employees 1001-5000 Categories Technology Information Technology & Services Internet Business Services...FreelanceRemote work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Chief Information Security Officer (CISO). Be the first to apply!
- chief information security officer ciso Phoenix, AZ
- ciso Phoenix, AZ
- information security officer Phoenix, AZ
- business information security officer Phoenix, AZ
- chief information security officer Phoenix, AZ
- entry level information security analyst Phoenix, AZ
- data center security officer Phoenix, AZ
- information security compliance analyst Phoenix, AZ
- director information security Phoenix, AZ
- information security analyst Phoenix, AZ



