CISO Mentor (part-time basis)
- Role
- Security
- Experience
- C-Level
- Employment
- Part-time1–5h/week
Open to Worldwide. Set where you work from to check your eligibility.
No BS summary
Social Discovery Group (SDG) is seeking a part-time CISO Mentor to join their remote international team for several hours per month. The role involves mentoring emerging security leaders and advising on information security programs.
Core skills
Required skills
Required languages
Social Discovery Group (SDG) is a group of social discovery companies. SDG solves the problems of loneliness, isolation, and disconnection - transforming virtual intimacy into the new normal. SDG’s products redefine the way people interact and connect with one another.
Our portfolio includes social entertainment platforms designed to connect people online across different cultures and regions of the world.
We bring together a team of like-minded people and IT professionals who specialize in creating and developing globally impactful social discovery products. Our international team of digital nomads works remotely from all over the world.
We’re proud to be a two-time “Great Place to Work” winner (USA & Japan, 2024–2025) and a Top-5 Company for Work-From-Anywhere Jobs (FlexJobs, 2025).
We are looking for CISO Mentor to join us for several hours per months.
**Your main tasks will be:
- Improve and maintain perimeter and network-layer defenses (WAF, Rate Limiting, Anti-bot ,DDoS mitigation
- Secure product APIs against abuse and anomalous traffic
- Strengthen authentication, authorization, and access control at the product level, including IDOR-class issues
- Run the Vulnerability Management process: identification, prioritization, and remediation tracking
- Coordinate external pentests and drive remediation of findings
- Lead Incident Response for product security incidents
- Build detection and response processes together with the monitoring team
- Contribute to Fraud & Trust and Safety initiatives with relevant teams
- Protect customer data at the product level (access control, encryption, masking)
- Run the Security Champions program to train product teams on secure development
- Manage the Bug Bounty program
**We expect from you:
- 7+ years in senior Information Security leadership (CISO, VP of Security, or Head of InfoSec), with a proven track record of mentoring or advising emerging security leaders.
- Zero-to-One Experience: Proven experience building, scaling, and managing an Information Security program entirely from scratch for a startup or scaling enterprise.
- High-Compliance Expertise: Deep, practical knowledge of operating in heavily regulated markets (e.g., FinTech, HealthTech, GovTech) and successfully leading organizations through rigorous audits (SOC 2 Type II, ISO 27001, PCI-DSS, HIPAA, or GDPR).
- Highload/Scalability Acumen: Strong architectural understanding of securing high-throughput, highly available, distributed systems and cloud-native environments (AWS/GCP/Azure) without bottlenecking performance.
- Strategic GRC (Governance, Risk, and Compliance): Ability to teach and establish risk management frameworks, compliance roadmaps, and vendor risk management processes.
- Executive Communication: Exceptional ability to translate complex technical risks into business impacts, and experience coaching others on how to present security strategies to C-level executives and the Board of Directors.
- Incident Response Leadership: Experience establishing and commanding an enterprise-grade Incident Response plan, including crisis management and post-breach communications.
- Security Culture Building: Demonstrated ability to foster a "security-first" culture across engineering, product, and business teams.
- Fluent Russian
**Sounds good? Join us now!
- %BUTTON_APPLY_TO_POSITION%
- %BUTTON_APPLY_USING_INDEED%
- %BUTTON_APPLY_USING_LINKED_IN%
What you'll do
- Improve and maintain perimeter and network-layer defenses (WAF, Rate Limiting, Anti-bot ,DDoS mitigation)
- Secure product APIs against abuse and anomalous traffic
- Strengthen authentication, authorization, and access control at the product level
- Run the Vulnerability Management process: identification, prioritization, and remediation tracking
- Coordinate external pentests and drive remediation of findings
What they require
- 7+ years in senior Information Security leadership (CISO, VP of Security, or Head of InfoSec), with a proven track record of mentoring or advising emerging security leaders.
- Zero-to-One Experience: Proven experience building, scaling, and managing an Information Security program entirely from scratch for a startup or scaling enterprise.
- High-Compliance Expertise: Deep, practical knowledge of operating in heavily regulated markets (e.g., FinTech, HealthTech, GovTech) and successfully leading organizations through rigorous audits (SOC 2 Type II, ISO 27001, PCI-DSS, HIPAA, or GDPR).
- Highload/Scalability Acumen: Strong architectural understanding of securing high-throughput, highly available, distributed systems and cloud-native environments (AWS/GCP/Azure) without bottlenecking performance.
- Strategic GRC (Governance, Risk, and Compliance): Ability to teach and establish risk management frameworks, compliance roadmaps, and vendor risk management processes.
Benefits
- two-time “Great Place to Work” winner (USA & Japan, 2024–2025)
- Top-5 Company for Work-From-Anywhere Jobs (FlexJobs, 2025)