Compliance Lead / CISO (Part-time)
פורסם לפני 14 ימים · 0 מועמדים
התפקיד במילים פשוטות
התפקיד כולל הובלה וניהול של תוכנית הציות ואבטחת המידע של החברה במשרה חלקית, תוך התמקדות בהשגת הסמכות SOC 2 ו-ISO 27001. העבודה היומיומית כוללת תפעול שוטף של פלטפורמת Vanta, כתיבה ותחזוקה של ספריות מדיניות אבטחה, ומענה על שאלוני אבטחה של לקוחות. בעל התפקיד יעבוד ישירות מול סמנכ"ל הכספים וסמנכ"ל ההנדסה כדי להבטיח מוכנות מתמדת לביקורות.
- Proven experience taking a SaaS / software company through SOC 2 and/or ISO 27001 to certification, leading the effort
- Vanta
- Strong track record in policy creation and deployment within a technology environment
- Working knowledge of the SOC 2 Trust Services Criteria and the ISO 27001 / ISO 27002 control set
- Based in Israel
- Experience supporting enterprise and/or government sales cycles and their security requirements
- Familiarity with privacy frameworks (GDPR / Israeli Privacy Protection Law) and vendor due diligence
- Relevant certifications (CISA, CISM, ISO 27001 Lead Implementer / Lead Auditor, or similar)
- Hebrew
חולץ מתיאור המשרה · מתעדכן אוטומטית
למי זה מתאים
תפקיד זה מתאים לאנשי מקצוע מנוסים ועצמאיים בתחום הציות ואבטחת המידע, אשר הובילו בעבר חברות תוכנה או SaaS לקבלת הסמכות SOC 2 או ISO 27001 ומכירים היטב את מערכת Vanta. הוא פחות יתאים למי שמחפש תפקיד ייעוצי בלבד ללא עבודה מעשית ויומיומית, או למי שאינו מעוניין במשרה חלקית וגמישה.
תיאור המשרה המלא
המשרה המקורית · נשמר לעיוןCompliance Lead / CISO (Part-Time)
Employment Type: Part-time (Contractor or Employee)
Location: Israel (hybrid; Jerusalem / Tel Aviv area preferred)
Hours: Part-time, flexible; increased load around audit windows and evidence cycles
About Vinesight
Vinesight is a narrative intelligence platform that helps organizations understand and respond to emerging narratives before they escalate. We monitor 14+ platforms in 50+ languages, serving Fortune 500 enterprises, government agencies, and strategic institutions. Our clients use Vinesight to progress from reactive damage control to proactive narrative strategy. Vinesight operates where data meets influence. Working alongside a focused team, you'll contribute to how the company earns and keeps the trust of enterprise and government clients, building the security and compliance foundation that lets us grow into environments where diligence and discretion matter.
About the Role
We are looking for an experienced, self-directed compliance professional to lead Vinesight's security compliance program on a part-time basis. This is a build-and-run role: you will own our path to SOC 2 and ISO 27001 certification end to end, own and operate our compliance platform day to day, and maintain the policy library that underpins both frameworks.
You will work directly with the CFO and VP Engineering and serve as the single owner accountable for getting us audit-ready and keeping us there. The ideal candidate has personally driven a software company to certification, is hands-on rather than advisory, and is comfortable running the program independently with minimal oversight. You are taking over and ramping up momentum rather than starting from a blank page: Vanta is already in place and a substantial policy library exists.
Key Responsibilities
1. Certification Program Leadership (SOC 2 & ISO 27001)
• Own the roadmap and execution for SOC 2 (Type I and Type II) and ISO 27001 certification, run in parallel, and drive the program to completion on a defined timeline.
• Run gap assessments against the SOC 2 Trust Services Criteria and the ISO 27001 Annex A control set, then manage remediation through to closure.
• Manage the external auditor relationship and coordinate Stage 1 / Stage 2 and Type II observation windows, including PBC lists and timely evidence delivery.
• Coordinate penetration testing, vulnerability management follow-up, and periodic risk assessment cycles.
2. Compliance Platform Operations (Vanta)
• Operate Vanta day to day: control mapping, continuous monitoring, evidence automation, and remediation of failing tests.
• Maintain and troubleshoot integrations between Vanta and internal systems so monitoring stays accurate and complete.
• Keep the control environment continuously audit-ready between formal audit windows, rather than scrambling ahead of each one.
3. Policy Creation, Deployment & Governance
• Author, review, deploy, and maintain the full policy library (information security, access control, incident response, vendor risk, data handling, acceptable use, and related policies).
• Drive employee attestation and acknowledgment, and keep policies current as the organization and its obligations evolve.
• Own vendor and subprocessor risk management and keep the subprocessor register accurate and current.
• Roll out and track security and compliance training across the organization.
4. Cross-Functional & Customer-Facing Support
• Respond to customer security questionnaires and maintain the trust center and security documentation used in sales cycles.
• Partner with Engineering and the CFO to translate control requirements into practical operational and technical practice.
• Build and run a recurring compliance calendar so the program operates on cadence rather than as a series of fire drills.
Required Skills & Qualifications
• Proven experience taking a SaaS / software company through SOC 2 and/or ISO 27001 to certification, leading the effort and not only supporting it.
• Hands-on Vanta administration experience (Drata or Secureframe is considered if the transition to Vanta is fast).
• Strong track record in policy creation and deployment within a technology environment.
• Working knowledge of the SOC 2 Trust Services Criteria and the ISO 27001 / ISO 27002 control set, and how they map to real engineering and operational practice.
• Comfortable operating independently and owning outcomes with minimal oversight.
• Based in Israel, with fluent English as the working language and strong written communication skills.
• Experience in a software / SaaS company and comfort working in a cloud-native environment (our specific stack will be shared during the interview process).
• High level of discretion and professionalism when handling sensitive security and organizational information.
Preferred Qualifications
• Experience supporting enterprise and/or government sales cycles and their security requirements.
• Familiarity with privacy frameworks (GDPR / Israeli Privacy Protection Law) and vendor due diligence.
• Relevant certifications (CISA, CISM, ISO 27001 Lead Implementer / Lead Auditor, or similar).
• Experience in a company scaling toward or through a fundraise.
• Hebrew in addition to English.
שאלות על המשרה
- המשרה לא ציינה שכר. אנחנו מציגים שכר רק כשהמעסיק מפרסם אותו.
- היברידי
- Proven experience taking a SaaS / software company through SOC 2 and/or ISO 27001 to certification, leading the effort, Vanta, Strong track record in policy creation and deployment within a technology environment, Working knowledge of the SOC 2 Trust Services Criteria and the ISO 27001 / ISO 27002 control set, Based in Israel