> Markdown version of [/jobs/ext/1345564-fractional-chief-information-security-officer-ciso](https://www.wearedevelopers.com/jobs/ext/1345564-fractional-chief-information-security-officer-ciso). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Fractional Chief Information Security Officer (CISO) - **Company:** AUSTCO, INC. - **Location:** Irving, TX, United States - **Experience:** Expert - **Contract:** Temporary contract - **Skills:** Amazon Web Services, Software as a Service, Cloud Computing, Cyber Security, Systems Integration, Software Vulnerability Management - **Published:** July 19, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=06106b9b19fd6190 ## About the Role * 10+ years in information security, with at least 3 years in a CISO or senior security leadership role * Demonstrated success leading security transformation in complex, multi-entity or post-acquisition environments. * Proven ability to drive organizational change, including transitioning decentralized IT environments to centralized/managed models * Experience building and executing IT roadmaps, including cloud migration (AWS or equivalent) * Strong knowledge of HIPAA/HITECH, NIST CSF, ISO 27001, SOC 2, and the ACSC Essential Eight * Experience operating across multiple international jurisdictions * Strong executive communication and board-level reporting skills * Availability for on-call incident response; willing to serve as the security escalation point for BCP/DRP events * Ability to operate autonomously with minimal day-to-day supervision HIGHLY REGARDED * CISSP, CISM, or CISA certification * Experience with IEC 62443 or medical device cybersecurity standards (FDA pre/post-market guidance) * Background supporting SaaS or cloud-based product companies * Familiarity with US, Canadian, New Zealand, Australian, UK, and Singapore regulatory environments ## Description Fractional Chief Information Security Officer, Austco Healthcare is seeking an experienced Fractional CISO to lead enterprise cybersecurity strategy across a growing global organization. This is a strategic, hands-on leadership role, responsible for unifying security across Austco's corporate entity and its acquired subsidiaries, all regions, and any future acquisitions., * Develop and own the enterprise information security strategy aligned to business objectives across Austco and all subsidiaries * Drive adoption of a centralized, managed IT operating model and advance maturity against the ACSC Essential Eight * Establish and maintain security policies, standards, and frameworks (NIST CSF, ISO 27001, SOC 2, ACSC Essential Eight) * Chair or advise the security steering committee; report to the Board on risk posture and maturity progress * Lead IT roadmap planning and migration of infrastructure to cloud-based environments (AWS and equivalent), establishing a centralized IT operating model ACQUISITION INTEGRATION & SUBSIDIARY ALIGNMENT * Engage Austco's subsidiaries to align their IT domains with the enterprise security framework * Evaluate and integrate future acquisitions from a security and IT perspective - assessing posture, risks, and integration requirements * Work across all Austco regions (US, Canada, Australia, UK, Singapore, New Zealand) to drive consistent adoption of security objectives RISK & COMPLIANCE * Lead risk assessments and manage the organizational risk register * Ensure compliance with HIPAA, HITECH, and applicable international data privacy regulations (GDPR, Australian Privacy Act, PDPA) * Oversee third-party and vendor risk, including managed service provider (MSP) relationships INCIDENT RESPONSE & OPERATIONS * Own the incident response plan and lead response to significant security events * Serve as a key escalation point within Austco's Business Continuity Plan (BCP) and Disaster Recovery Plan (DRP) * Partner with IT teams and the MSP on vulnerability management, security architecture, and operational security * Drive security awareness training across all global offices LEADERSHIP & STAKEHOLDER MANAGEMENT * Manage local IT teams across subsidiaries and regions, providing direction, oversight, and mentorship * Act as the primary interface with the managed service provider (MSP), ensuring service levels and security standards are met * Serve as the internal and external-facing security authority for Austco * Advise on security implications of M&A activity, product development, and infrastructure changes What Success Looks Like in The First 6 to 12 Months Within the first year, we expect this engagement to deliver: * A unified, centralized IT operating model established across the corporate entity and the ANZ subsidiaries * Measurable progress against the ACSC Essential Eight, to a maturity level agreed with the Board * Enterprise security policies, standards and a live organizational risk register adopted group wide * An approved cloud migration roadmap underway * Incident response, business continuity and disaster recovery plans validated through at least one tabletop exercise * Security and IT integration plans agreed for each Austco subsidiary ## Related Videos - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Green Cloud Computing](https://www.wearedevelopers.com/videos/592-green-cloud-computing) - [Containers in the cloud - State of the Art in 2022](https://www.wearedevelopers.com/videos/410-containers-in-the-cloud-state-of-the-art-in-2022) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Best US AI Conferences for CTOs in 2026: Build vs. Buy, Vendor Evaluation, and Peer Intelligence](https://www.wearedevelopers.com/magazine/736-best-us-ai-conferences-for-ctos-in-2026-build-vs-buy-vendor-evaluation-and-peer-intelligence) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Trustworthy AI Starts at Deployment: 5 Checks Before You Ship](https://www.wearedevelopers.com/magazine/753-trustworthy-ai-starts-at-deployment-5-checks-before-you-ship) - [7 Cloud Computing Trends Coming in 2025 for Developers](https://www.wearedevelopers.com/magazine/412-7-cloud-computing-trends-coming-in-2025-for-developers) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking)