TI
Posted 5 days ago
Chief Information Security Officer
TurboVets, Inc.
๐ Phoenix
Management & Operations, IT & TechnologyHybrid
Job description
<div><h3>Chief Information Security Officer (CISO)</h3>
<p>TurboVets | Phoenix, AZ (Hybrid) | Reports to CEO & CTO</p>
<h3>About TurboVets</h3>
<p>TurboVets builds technology for the people who served โ service members, veterans, and the federal agencies that support them. We work across federal and commercial product lines, and security and compliance touch everything we do.</p>
<h3>The Role</h3>
<p>We're hiring our first CISO. This is a build role โ not a steady-state operator role. You'll own the security function end-to-end, partner directly with the CEO and CTO, and set the strategy from the ground up.</p>
<p>We're not looking for a traditional 20-year CISO. We want someone with a strong cybersecurity foundation, a developer's instincts, executive judgment, and the learning velocity to use AI as a real force multiplier.</p>
<h3>What You'll Own</h3>
<ul>
<li>Commercial compliance program โ frameworks, technical and administrative safeguards, and ongoing assessments (SOC 2 and others as the business scales)</li>
<li>Cloud security end-to-end: identity, network, data, logging, key management, and incident response</li>
<li>Overall security strategy across product, infrastructure, corporate IT, and vendor risk</li>
<li>Incident response leadership โ you're the executive on point when something happens</li>
<li>Security tooling stack โ evaluating, selecting, and keeping the portfolio lean</li>
<li>Federal product line partnership โ executive sponsorship alongside the teams managing day-to-day federal work</li>
<li>Building and growing the security and compliance function โ hiring, developing, and training the team</li>
</ul>
<h3>What We're Looking For</h3>
<p>Required:</p>
<ul>
<li>Cybersecurity background (vendor, services, or in-house) โ credible with engineers, auditors, and customers</li>
<li>Hands-on experience selecting and deploying security tooling (SIEM, vulnerability management, identity, container security, etc.)</li>
<li>Software development background โ can read code and contribute to automation</li>
<li>Working knowledge of AWS and modern cloud architecture</li>
<li>High learning velocity; genuinely uses AI as a knowledge multiplier</li>
</ul>
<p>Preferred:</p>
<ul>
<li>Exposure to HIPAA, SOC 2, FedRAMP, NIST 800-53, CMMC, or ATO processes</li>
<li>Prior experience at a cybersecurity company or security-adjacent startup</li>
<li>Familiarity with federal customers (DoD, DHS, USCG, VA)</li>
<li>CISSP, CISM, CCSP, or HCISPP โ nice to have, not required</li>
</ul>
<h3>What Success Looks Like</h3>
<ul>
<li>90 days: Commercial posture assessed, compliance plan drafted, 12-month roadmap in place</li>
<li>6 months: Controls operational, cloud baseline hardened, partnership rhythm established across product lines</li>
<li>12 months: An auditable, automation-heavy security program across commercial and federal โ built with engineering, accelerated by AI</li></ul></div>
#J-18808-Ljbffr