Chief Information Security Officer (CISO)
Ryde Technologies, LLC
Job Description
Job Description
Chief Information Security Officer (CISO) / Head of Information Security
ABOUT THE ROLE
This is not a purely strategic, oversight-level CISO role. The company is looking for a security leader who is genuinely hands-on: someone who can personally architect and troubleshoot cloud security controls, not just direct a team that does. You will set enterprise security strategy and own governance, but you are expected to be the one in the room who can spontaneously whiteboard how to secure an AWS environment end to end, size a VPC, and explain why a given control matters for CJIS audit evidence, not delegate that conversation to an engineer.
You will also function as a customer-facing, revenue-enabling part of the business. Clients are government agencies and their sponsors, and this role routinely acts as a de facto technical sales resource, presenting security posture directly to prospects and agency stakeholders, not just responding to audits from behind the scenes. Comfort in that kind of client-facing, almost sales-adjacent conversation is a requirement, not a nice-to-have.
Reporting to the CTO, you will own cybersecurity, data protection, regulatory compliance, and information-security risk management, working closely with product, engineering, DevOps, legal, sales, and client stakeholders to embed security across the organization and protect the trust of the agencies and communities it serves.
WHAT YOU WILL OWN PERSONALLY
This is a build role before it is a management role. The security function is growing, and in the early stretch the work is yours to execute directly:
- Sizing and reviewing AWS network design yourself: VPC and subnet layout, routing, security groups and NACLs, gateway placement, multi-AZ architecture, and Flow Logs as forensic and audit evidence
- Writing and defending the control evidence behind CJIS 6.1 and FedRAMP ConMon, including POA&M items, monthly scan results, and direct questions from 3PAOs and agency sponsors
- Serving as the security voice on client and prospect calls, walking agency stakeholders through posture, completing security questionnaires, and supporting RFP and RFI responses firsthand
- Leading live incidents as the decision maker while staying in the technical detail rather than handing the response to an engineer
- Selecting tooling and standing up what does not exist yet: SIEM and monitoring, AppSec scanning, supply chain controls, and third-party risk process
- As the program matures, you will build and lead the team that carries this forward. The expectation is that you have done the work yourself first.
KEY RESPONSIBILITIES
Security Strategy and Governance
- Develop and run the enterprise information security strategy, policies, standards, and control requirements across the business
- Advise the CEO, CTO, executive leadership, and Board directly, with regular briefings on risk, program maturity, and mitigation priorities
- Define and report on security KPIs, risk indicators, and maturity assessments
- Evaluate and bring in AI-assisted security tooling where it genuinely improves detection, response, or automation
- Own the security budget: planning, prioritization, and justifying investment to leadership and the Board
Compliance and Regulatory Oversight (state-driven, not a single federal-standard-first program)
- Own compliance with CJIS Security Policy, including the transition to CJIS 6.0 (phishing-resistant MFA, FIPS 140-3 encryption, remote-work controls, updated cloud security requirements)
- Lead FedRAMP authorization and ongoing Continuous Monitoring, including direct coordination with 3PAOs and federal agency sponsors, monthly vulnerability scanning, POA&M management, and annual assessments
- Run the SOC 2 Type II program and the ISO 27001 ISMS: audits, management reviews, risk treatment, certification body relationships
- Tailor CJIS, FedRAMP, SOC 2, and ISO 27001 posture to what each individual client agency actually requires; NIST 800-53 is treated as one input among several rather than a standalone initiative, since only a minority of client states reference it directly
- Ensure data privacy, residency, sovereignty, and information-lifecycle practices meet public-sector and criminal-justice client requirements
- Own the cyber insurance program and work with legal on breach response and contractual security obligations
- Be the primary point of contact for client security assessments, audits, and questionnaires
- Support sales directly: RFP and RFI responses, proactive relationship-building with client-side security leaders, and hands-on participation in prospect and agency-sponsor conversations as a technical resource for the sales motion
Incident Response and Threat Management
- Build, maintain, and stress-test the incident response plan through tabletops and simulations
- Stand up or oversee SOC capabilities: SIEM, 24/7 monitoring, detection and escalation aligned to FedRAMP ConMon and CJIS requirements
- Lead the organization through real incidents and breaches as executive decision maker, while staying technically engaged in the response rather than delegating it entirely
- Own vulnerability management, penetration testing, and threat intelligence
- Manage external security partners, MSSPs, and law enforcement contacts as needed
- Ensure breach notification is timely and legally compliant
Security Architecture and Engineering Partnership (working technical depth required, not vocabulary familiarity)
- Partner with product, engineering, and DevOps so security-by-design is embedded in the SDLC
- Personally review and approve security architecture for new products, features, and infrastructure changes, including hands-on evaluation of network design (VPC and subnet layout, routing, security groups, NACLs, NAT and internet gateways, multi-AZ design, VPC Flow Logs as a forensic and audit-evidence control)
- Own IAM, encryption standards, data classification, and data residency and sovereignty controls for government clients
- Own AWS security posture end to end, including AWS GovCloud environments, using GuardDuty, Security Hub, CloudTrail, AWS Config, IAM, KMS, and AWS WAF, aligned to the AWS Shared Responsibility Model
- Manage software supply chain security: SBOM, dependency vulnerability scanning, secure CI/CD pipeline controls, artifact integrity, code signing
- Own the AppSec program: SAST, DAST, and SCA tooling, secure code review standards, release gates, responsible disclosure process
- Ensure remote workers handling CJI meet CJIS 6.0 physical security requirements
- Drive Zero Trust adoption in line with federal guidance (OMB M-22-09)
Security Awareness and Training
Design and run a company-wide security awareness program covering role-specific risk, CJIS obligations, and client agreements, including technical training on secure coding, data handling, and safe AI tool use. Track completion and effectiveness, and iterate as the threat landscape changes.
Business Continuity and Disaster Recovery
Build, maintain, and test BC/DR plans aligned with CJIS requirements, the FedRAMP Contingency Planning control family, and ISO 27001 Annex A.17, addressing CJI protection, AWS infrastructure resilience, and client SLA commitments.
Vendor and Third-Party Risk Management
Stand up and run a third-party risk program covering vendor assessments, due diligence, and ongoing monitoring, and define the contractual security requirements that cloud and technology partners must meet.
EDUCATION AND CERTIFICATION REQUIREMENTS
- Bachelor's degree in computer science, information security, information technology, or related field required; master's preferred
- CISSP, CISM, or equivalent required, or obtainable within 12 months of hire
- CJIS Security Awareness Training required, or obtainable within 90 days of hire
- Preferred: CCSP, AWS Certified Security - Specialty, CISA, FedRAMP-related training or certification
REQUIRED KNOWLEDGE, SKILLS, AND EXPERIENCE
- 10+ years of progressive information security experience, including 3 to 5+ years in a senior leadership role
- Genuine hands-on fluency in cloud security architecture and networking: can independently size a VPC CIDR range, determine subnetting needs for a multi-tier architecture, explain routing, security groups, and NACLs, and articulate the value of VPC Flow Logs as a forensic and audit-evidence control, not just recognize the terms
- Deep, implementation-level knowledge of CJIS Security Policy (including v6.0), gained by actually building and running compliant programs, not solely coordinating or overseeing external audits
- Hands-on experience leading or maintaining a FedRAMP ATO and ConMon program, including direct 3PAO and agency sponsor coordination
- Proven ownership of a SOC 2 Type II program and, ideally, direct ISO 27001 ISMS implementation or maintenance
- Working familiarity with NIST CSF, NIST 800-53, and CIS Controls as supporting frameworks, understood in the context of a state-by-state, client-driven compliance posture rather than a NIST-first program
- Experience building and running incident response programs, including leading live incidents while staying technically hands-on rather than defaulting to pure strategic oversight
- Comfort operating in a customer-facing, revenue-enabling capacity: presenting security posture to clients and agency sponsors, supporting RFPs, and functioning credibly as a technical resource within the sales process
- Experience working in or directly with Criminal Justice, Public Safety, or Government sectors strongly preferred; this is foundational to the role, not a nice-to-have
- Real, current experience securing AWS environments including AWS GovCloud, with working fluency (not passing familiarity) in GuardDuty, Security Hub, IAM, KMS, CloudTrail, Config, and WAF
- Strong understanding of data privacy, residency, sovereignty, and PII and CJI lifecycle management for government clients
- Experience with cyber insurance programs and coordinating with legal on breach response and contractual obligations
- Familiarity with Zero Trust architecture and federal mandates (OMB M-22-09)
- Demonstrated ability to build and lead security teams while managing external vendors and partners, with the hands-on depth to execute the work directly before that team is in place
- Executive communication skills, with the ability to translate technical and regulatory risk into business terms for non-technical stakeholders
EEO Compliance:
Ryde is an Equal Employment Opportunity/Affirmative Action Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, age, sexual orientation, gender identity, national origin, disability, protected veteran status, or any other characteristic protected by law. Ryde will consider qualified applicants with criminal histories in a manner consistent with the requirements of applicable law.
- ...Chief Information Security Officer (CISO) / Head of Information Security Overview We are seeking an experienced Information Security Leader to define and execute a comprehensive enterprise security strategy. This role is responsible for safeguarding systems, data, and...SuggestedWork at officeRemote work3 days per week
- ...Chief Information Security Officer (CISO) About the Company Large public accounting & advisory firm Industry Accounting Type Privately Held Founded 1986 Employees 1001-5000 Categories Consulting & Professional Services Accounting Accounting...Suggested
- ...Chief Information Security Officer (CISO) About the Company Innovative provider of data safety & recovery solutions Industry Information Technology and Services Type Privately Held Founded 2024 Employees 51-200 Specialties cloud backup...Suggested
- ...Virtual Chief Information Security OfficerPhoenix's small and mid-sized businesses face the same cybersecurity threats as the... ...clients who do not have and cannot afford a full-time CISO. You will work from our Phoenix office, managing multiple client relationships...SuggestedFull timeWork at officeShift work
- ...Chief Information Security Officer (CISO), Information Security & Compliance About the Company Innovative artificial intelligence (AI) & marketing analytics platform Industry Information Technology and Services Type Public Company Founded 2014...Suggested
- ...Deputy Chief Information Security Officer (CISO) About the Company Innovative digital life insurance company Industry Insurance Type Privately Held, VC-backed Founded 2016 Employees 501-1000 Funding $6-$10 million Specialties life insurance...
$50 per hour
...Experienced ProfessionalFT/PT/Casual: FullTimeDepartment: RMS CoreBusiness Unit: RMS CoreShort DescriptionThe Work:This Information System Security Officer (ISSO) position will support the Information System Security Manager (ISSM) in developing, maintaining and overseeing...Full timeTemporary workWork experience placementCasual workFlexible hoursShift workDay shift- ...band, VHF, UHF, 800 MHz base station/repeater 2-way radios; site security alarm and control equipment; site grounding grids, etc.).14.... ...land mobile systems maintained by DPS.gathering technical information for trouble calls from non-technical personnel.maneuvering and...Work experience placementWork at officeLocal areaRemote workFlexible hoursNight shift
- ...ECS is seeking a CISO to work in our Sierra Vista, AZ office. The Chief Information Security Officer will serve as the senior cybersecurity leader and principal security advisor to the Program Manager for The Army Endpoint Security Solution (AESS). This role is responsible...Contract workWork at officeLocal area
- ...Technology Team as a Telecommunications Manager located in various offices.We are seeking a professional who thrives in a fast-paced,... ...guide the firm through technology transitions—with emphasis on security, compliance, and business continuity.Key ResponsibilitiesStrategic...Contract workRemote work
- ...Chief Trust Officer (CTO) About the Company Highly respected wealth management firm with boutique, client-centric service for sophisticated families. Industry Financial Services Type Privately Held About the Role The Company is in search of a Chief...
- ...Head of IT & Security About us: At Fullbay, our mission is simple — to create safer roads for our families and yours. As leaders... ...and Standards Development: Author, maintain, and enforce information security policies, standards, and procedures across the organization...Work experience placementDay shift
$160k - $194k
A Gartner Executive Partner (EP) is an indispensable advisor for every Information Technology and digital leader. Executive Technology Services is an exclusive membership-based organization serving over 7,000 CIOs / CxOs and senior IT leaders across 87 countries. These...Full timeLocal areaRemote workWorldwide- Part-Time Chiropractor - Ownership Track Opportunity NuSpine Chiropractic is a rapidly expanding franchise system redefining modern chiropractic care through clinical excellence, operational precision, affordability, and meaningful patient relationships. Our examinations...Part timeImmediate start
- ...Job Description Job Description Virtual Chief Information Security Officer ● cloudIT ● Phoenix, AZ ● In-Office Phoenix's small and... ...of clients who do not have and cannot afford a full-time CISO. You will work from our Phoenix office, managing multiple...Full timeWork at officeShift work
- Front Page Agency | Arizona Full-Time | In-Person | Paid Training | October 5, 2026 Launch Help Build Our Arizona Team From the Ground Up Front Page Agency is launching its Arizona expansion on October 5, and we’re looking for ambitious individuals who want to...Full timeShift work
- ...protocol addressing. Solid working knowledge of the Microsoft Office suite of applications, including Word, Excel and Outlook. Good... ...agency program staff and agency senior management (25%)Additional Information- "All your information will be kept confidential according to...Contract workWork at officeLocal areaImmediate startFlexible hours
$82.28k - $108.77k
...advantage of tax‑deferred retirement investments. On, or shortly after, your first day of work you will be provided with additional information about the available insurance plans, enrollment instructions, submission deadlines and effective dates. Contact Us: The State of...Temporary workWork experience placement- ...Founded in 2005, WSO2 has offices in Australia, Brazil,... ...are scalable, secure, and follow industry best... ...degree in Computer Science, Information Technology, or a related... ...outcomes for CEOs, CTOs, and CISOs. ~ Strong... ...discussion with a Payer's Chief Medical Officer or CFO....Worldwide
- ...Arsenault is searching for a Chief Information Officer (US) on behalf of our client, the leading publisher of Career and Technical Education... ...will be a key focus, along with customer satisfaction and security. The CIO will support and lead teams in Digital Media and...Work at office
- ...Chief Revenue Officer | Confidential Retained Search | Edge I Data Center I Equity Valor Front has been exclusively retained by a newly launched U.S. colocation and AI inference platform to identify its first Chief Revenue Officer. Our client is a standalone data...Full timeContract workImmediate start
- The Arizona Department of Public Safety seeks a Telecommunications Supervisor to oversee shop and field Telecommunications Technicians and Telecommunications Coordinators responsible for construction, installation, maintenance, and operation of statewide telecommunications...
$120k
...The Information Security Manager leads the design, implementation, and continuous enhancement of the organization's cybersecurity program under the Security Officers guidance. This position ensures that technical and administrative safeguards align with HIPAA, CIS, NIST...Contract workRemote work- Director, Technology & Innovation We are seeking a hands-on technology leader to help modernize systems, improve business workflows, and introduce new technology across the organization. This is a senior individual contributor role for someone who can move between...
- ...Managing Director, Chief Technology Officers Practice, Retained Search About the Company Dynamic executive search firm specializing in... ...responsibilities. The position is pivotal in helping clients make informed leadership decisions and is suited to individuals who...
$123k - $215.25k
...providing world-class customer service, we operate with a strong risk mindset, ensuring we continue to uphold our brand promise of trust, security, and service.As part of Team Amex, you’ll experience our powerful backing with comprehensive support for your holistic well-being...Contract workFor contractors- ...Regional Field Chief Technology Officer (CTO) About the Company Globally recognized provider of automated solutions for securing & managing open source software Industry Computer... ...to translate complex technical information into clear narratives for both technical...
- ...Field Chief Technology Officer (CTO) About the Company Regarded provider of professional technology & software solutions Industry... ...Held Founded 2006 Employees 51-200 Categories Information Technology & Services Technology Services Software...Apprenticeship
- ...out and recruit an experienced IT Director to oversee all IT (Information Technology) functions. The IT Director will oversee a team of... ...Responsibilities Oversee all technology operations (e.g. network security) and evaluate them according to established goals Devise...Work experience placementRelocation
- ...partner to Optiv’s clients. By combining advanced business and security practitioner knowledge, the Principal AI Cybersecurity Advisor... ...at clients by facilitating thought leadership, support, information, and guidance in conjunction with sales partnersMaintain strong...Full timeLocal areaRemote workWork from home
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Chief Information Security Officer (CISO). Be the first to apply!
- chief information security officer ciso Phoenix, AZ
- business information security officer Phoenix, AZ
- information security officer Phoenix, AZ
- ciso Phoenix, AZ
- chief information security officer Phoenix, AZ
- director information security Phoenix, AZ
- information security compliance analyst Phoenix, AZ
- sr information security engineer Phoenix, AZ
- data center security officer Phoenix, AZ
- information technology security engineer Phoenix, AZ



