Chief Information Security Officer (CISO)

Ryde Technologies, LLC

Chief Information Security Officer (CISO)

Phoenix, AZ
Full Time
Paid
  • Responsibilities

    Chief Information Security Officer (CISO) / Head of Information Security

     

    ABOUT THE ROLE

    This is not a purely strategic, oversight-level CISO role. The company is looking for a security leader who is genuinely hands-on: someone who can personally architect and troubleshoot cloud security controls, not just direct a team that does. You will set enterprise security strategy and own governance, but you are expected to be the one in the room who can spontaneously whiteboard how to secure an AWS environment end to end, size a VPC, and explain why a given control matters for CJIS audit evidence, not delegate that conversation to an engineer.

    You will also function as a customer-facing, revenue-enabling part of the business. Clients are government agencies and their sponsors, and this role routinely acts as a de facto technical sales resource, presenting security posture directly to prospects and agency stakeholders, not just responding to audits from behind the scenes. Comfort in that kind of client-facing, almost sales-adjacent conversation is a requirement, not a nice-to-have.

    Reporting to the CTO, you will own cybersecurity, data protection, regulatory compliance, and information-security risk management, working closely with product, engineering, DevOps, legal, sales, and client stakeholders to embed security across the organization and protect the trust of the agencies and communities it serves.

     

    WHAT YOU WILL OWN PERSONALLY

    This is a build role before it is a management role. The security function is growing, and in the early stretch the work is yours to execute directly:

    • Sizing and reviewing AWS network design yourself: VPC and subnet layout, routing, security groups and NACLs, gateway placement, multi-AZ architecture, and Flow Logs as forensic and audit evidence
    • Writing and defending the control evidence behind CJIS 6.1 and FedRAMP ConMon, including POA&M items, monthly scan results, and direct questions from 3PAOs and agency sponsors
    • Serving as the security voice on client and prospect calls, walking agency stakeholders through posture, completing security questionnaires, and supporting RFP and RFI responses firsthand
    • Leading live incidents as the decision maker while staying in the technical detail rather than handing the response to an engineer
    • Selecting tooling and standing up what does not exist yet: SIEM and monitoring, AppSec scanning, supply chain controls, and third-party risk process
    • As the program matures, you will build and lead the team that carries this forward. The expectation is that you have done the work yourself first.

    KEY RESPONSIBILITIES

    Security Strategy and Governance

    • Develop and run the enterprise information security strategy, policies, standards, and control requirements across the business
    • Advise the CEO, CTO, executive leadership, and Board directly, with regular briefings on risk, program maturity, and mitigation priorities
    • Define and report on security KPIs, risk indicators, and maturity assessments
    • Evaluate and bring in AI-assisted security tooling where it genuinely improves detection, response, or automation
    • Own the security budget: planning, prioritization, and justifying investment to leadership and the Board

    Compliance and Regulatory Oversight(state-driven, not a single federal-standard-first program)

    • Own compliance with CJIS Security Policy, including the transition to CJIS 6.0 (phishing-resistant MFA, FIPS 140-3 encryption, remote-work controls, updated cloud security requirements)
    • Lead FedRAMP authorization and ongoing Continuous Monitoring, including direct coordination with 3PAOs and federal agency sponsors, monthly vulnerability scanning, POA&M management, and annual assessments
    • Run the SOC 2 Type II program and the ISO 27001 ISMS: audits, management reviews, risk treatment, certification body relationships
    • Tailor CJIS, FedRAMP, SOC 2, and ISO 27001 posture to what each individual client agency actually requires; NIST 800-53 is treated as one input among several rather than a standalone initiative, since only a minority of client states reference it directly
    • Ensure data privacy, residency, sovereignty, and information-lifecycle practices meet public-sector and criminal-justice client requirements
    • Own the cyber insurance program and work with legal on breach response and contractual security obligations
    • Be the primary point of contact for client security assessments, audits, and questionnaires
    • Support sales directly: RFP and RFI responses, proactive relationship-building with client-side security leaders, and hands-on participation in prospect and agency-sponsor conversations as a technical resource for the sales motion

    Incident Response and Threat Management

    • Build, maintain, and stress-test the incident response plan through tabletops and simulations
    • Stand up or oversee SOC capabilities: SIEM, 24/7 monitoring, detection and escalation aligned to FedRAMP ConMon and CJIS requirements
    • Lead the organization through real incidents and breaches as executive decision maker, while staying technically engaged in the response rather than delegating it entirely
    • Own vulnerability management, penetration testing, and threat intelligence
    • Manage external security partners, MSSPs, and law enforcement contacts as needed
    • Ensure breach notification is timely and legally compliant

    Security Architecture and Engineering Partnership(working technical depth required, not vocabulary familiarity)

    • Partner with product, engineering, and DevOps so security-by-design is embedded in the SDLC
    • Personally review and approve security architecture for new products, features, and infrastructure changes, including hands-on evaluation of network design (VPC and subnet layout, routing, security groups, NACLs, NAT and internet gateways, multi-AZ design, VPC Flow Logs as a forensic and audit-evidence control)
    • Own IAM, encryption standards, data classification, and data residency and sovereignty controls for government clients
    • Own AWS security posture end to end, including AWS GovCloud environments, using GuardDuty, Security Hub, CloudTrail, AWS Config, IAM, KMS, and AWS WAF, aligned to the AWS Shared Responsibility Model
    • Manage software supply chain security: SBOM, dependency vulnerability scanning, secure CI/CD pipeline controls, artifact integrity, code signing
    • Own the AppSec program: SAST, DAST, and SCA tooling, secure code review standards, release gates, responsible disclosure process
    • Ensure remote workers handling CJI meet CJIS 6.0 physical security requirements
    • Drive Zero Trust adoption in line with federal guidance (OMB M-22-09)

    Security Awareness and Training

    Design and run a company-wide security awareness program covering role-specific risk, CJIS obligations, and client agreements, including technical training on secure coding, data handling, and safe AI tool use. Track completion and effectiveness, and iterate as the threat landscape changes.

    Business Continuity and Disaster Recovery

    Build, maintain, and test BC/DR plans aligned with CJIS requirements, the FedRAMP Contingency Planning control family, and ISO 27001 Annex A.17, addressing CJI protection, AWS infrastructure resilience, and client SLA commitments.

    Vendor and Third-Party Risk Management

    Stand up and run a third-party risk program covering vendor assessments, due diligence, and ongoing monitoring, and define the contractual security requirements that cloud and technology partners must meet.

    EDUCATION AND CERTIFICATION REQUIREMENTS

    • Bachelor’s degree in computer science, information security, information technology, or related field required; master’s preferred
    • CISSP, CISM, or equivalent required, or obtainable within 12 months of hire
    • CJIS Security Awareness Training required, or obtainable within 90 days of hire
    • Preferred: CCSP, AWS Certified Security - Specialty, CISA, FedRAMP-related training or certification

    REQUIRED KNOWLEDGE, SKILLS, AND EXPERIENCE

    • 10+ years of progressive information security experience, including 3 to 5+ years in a senior leadership role
    • Genuine hands-on fluency in cloud security architecture and networking: can independently size a VPC CIDR range, determine subnetting needs for a multi-tier architecture, explain routing, security groups, and NACLs, and articulate the value of VPC Flow Logs as a forensic and audit-evidence control, not just recognize the terms
    • Deep, implementation-level knowledge of CJIS Security Policy (including v6.0), gained by actually building and running compliant programs, not solely coordinating or overseeing external audits
    • Hands-on experience leading or maintaining a FedRAMP ATO and ConMon program, including direct 3PAO and agency sponsor coordination
    • Proven ownership of a SOC 2 Type II program and, ideally, direct ISO 27001 ISMS implementation or maintenance
    • Working familiarity with NIST CSF, NIST 800-53, and CIS Controls as supporting frameworks, understood in the context of a state-by-state, client-driven compliance posture rather than a NIST- first program
    • Experience building and running incident response programs, including leading live incidents while staying technically hands-on rather than defaulting to pure strategic oversight
    • Comfort operating in a customer-facing, revenue-enabling capacity: presenting security posture to clients and agency sponsors, supporting RFPs, and functioning credibly as a technical resource within the sales process
    • Experience working in or directly with Criminal Justice, Public Safety, or Government sectors strongly preferred; this is foundational to the role, not a nice-to-have
    • Real, current experience securing AWS environments including AWS GovCloud, with working fluency (not passing familiarity) in GuardDuty, Security Hub, IAM, KMS, CloudTrail, Config, and WAF
    • Strong understanding of data privacy, residency, sovereignty, and PII and CJI lifecycle management for government clients
    • Experience with cyber insurance programs and coordinating with legal on breach response and contractual obligations
    • Familiarity with Zero Trust architecture and federal mandates (OMB M-22-09)
    • Demonstrated ability to build and lead security teams while managing external vendors and partners, with the hands-on depth to execute the work directly before that team is in place
    • Executive communication skills, with the ability to translate technical and regulatory risk into business terms for non-technical stakeholders

     

    EEO Compliance:

    Ryde is an Equal Employment Opportunity/Affirmative Action Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, age, sexual orientation, gender identity, national origin, disability, protected veteran status, or any other characteristic protected by law. Ryde will consider qualified applicants with criminal histories in a manner consistent with the requirements of applicable law.