This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a CISO Mentor (part-time basis) based in Poland.
As a CISO Mentor, you will advise and support the development of a mature, scalable Information Security function within a fast-growing, globally distributed technology environment. This part-time role is designed for an experienced security executive who can provide strategic guidance while helping emerging security leaders navigate complex challenges. You will contribute expertise across product security, governance, risk and compliance, incident response, cloud security, and security culture. Your guidance will help strengthen defenses, improve security processes, and establish scalable practices without compromising product performance or business agility. You will work closely with security, engineering, product, monitoring, and business teams, sharing practical knowledge and executive-level perspective. This is an opportunity to make meaningful impact through focused mentorship and strategic advisory support while working only several hours per month.
Accountabilities
- Mentor and advise security leaders on building, scaling, and continuously improving an Information Security program.
- Provide strategic guidance on perimeter and network-layer defenses, including WAF, rate limiting, anti-bot protections, and DDoS mitigation.
- Advise on securing product APIs against abuse, anomalous traffic, and other application-level threats.
- Strengthen authentication, authorization, access controls, and protections against vulnerabilities such as IDOR.
- Guide the Vulnerability Management process, including vulnerability identification, prioritization, remediation, and tracking.
- Advise on external penetration testing programs and support effective remediation of identified findings.
- Provide leadership and guidance for product security Incident Response, including crisis management and post-incident activities.
- Help establish effective detection and response processes in collaboration with monitoring and security teams.
- Contribute security expertise to Fraud, Trust & Safety, and related cross-functional initiatives.
- Advise on customer data protection through access controls, encryption, masking, and other appropriate safeguards.
- Mentor teams responsible for the Security Champions program and promote secure development practices across product and engineering.
- Provide strategic oversight and guidance for the Bug Bounty program.
- Help establish risk management frameworks, compliance roadmaps, and vendor risk management practices.
- 7+ years of experience in senior Information Security leadership roles such as CISO, VP of Security, or Head of Information Security, with a strong track record of mentoring or advising emerging security leaders.
- Proven zero-to-one experience building, scaling, and managing an Information Security program from the ground up within a startup or scaling organization.
- Deep practical experience operating in highly regulated environments such as FinTech, HealthTech, or GovTech, including successfully navigating rigorous audits and frameworks such as SOC 2 Type II, ISO 27001, PCI-DSS, HIPAA, or GDPR.
- Strong architectural knowledge of securing high-throughput, highly available, distributed systems and cloud-native environments across AWS, GCP, or Azure, while maintaining performance and scalability.
- Strong understanding of strategic Governance, Risk, and Compliance, with the ability to establish risk management, compliance, and vendor risk processes and coach others in applying them.
- Exceptional executive communication skills, including the ability to translate complex technical risks into clear business impacts and mentor security leaders in communicating with C-level executives and Boards.
- Demonstrated experience designing and leading enterprise-grade Incident Response programs, including crisis management and post-breach communications.
- Proven ability to build and promote a security-first culture across engineering, product, and business functions.
- Strong mentoring, coaching, stakeholder management, and strategic problem-solving abilities.
- Fluent Russian.
- Part-time engagement requiring only several hours per month.
- Remote-first working environment with the flexibility to work from Poland.
- Opportunity to advise and mentor security leadership while having a meaningful strategic impact.
- Collaboration with an international, distributed team of technology and security professionals.
- Exposure to complex, globally distributed, high-scale digital products and security challenges.
- Flexible engagement designed to fit alongside other professional commitments.

