> Markdown version of [/jobs/ext/2383498-chief-information-security-officer](https://www.wearedevelopers.com/jobs/ext/2383498-chief-information-security-officer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Chief Information Security Officer - **Company:** ReadyOp Communications, Inc. - **Location:** Clearwater, FL, United States - **Experience:** Expert - **Salary:** $169,439.0 - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Amazon Web Services, Software System Penetration Testing, Software as a Service, Cloud Computing Security, Cyber Security, Continuous Integration, Phishing, Software Vulnerability Management, Delivery Pipeline, Cloud Integration, Devsecops, Plan of Action and Milestones - **Published:** August 3, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=d37f144061249c28 ## About the Role * Experience: 10+ years of progressive leadership experience in information security, with at least 3+ years in a senior leadership role (CISO, VP of Security, or Director of Security) within a SaaS environment. * FedRAMP Expertise: Proven track record of managing and maintaining a FedRAMP Moderate (or High) Authorized environment and liaising with the FedRAMP PMO / 3PAOs. * SOC 2 Experience: Hands-on experience preparing for, executing, and maintaining SOC 2 Type I and Type II audits. * Technical Mastery: Deep knowledge of cloud security architecture (AWS), NIST 800-53 frameworks, container security, and DevSecOps concepts. * Certifications: Active security certifications required (e.g., CISSP, CISM, CRISC, or CISA). * Clearance/Eligibility: Ability to successfully pass a background check and security screening; US Citizenship and active security clearance (or eligibility to obtain one) required., * CISSP (Preferred) * CISM (Preferred) * CRISC (Preferred) ## Description We are seeking a visionary and hands-on Chief Information Security Officer (CISO) to lead our enterprise security strategy, maintain our strict compliance posture, and safeguard our technology ecosystem., The CISO will serve as the executive authority for all aspects of information security, data privacy, governance, and regulatory compliance across ReadyOp's SaaS infrastructure. You will oversee our FedRAMP Moderate continuous monitoring program, spearhead our ongoing SOC 2 initiatives, and partner with executive leadership to align security initiatives with business growth., * Define, implement, and maintain ReadyOp's global information security strategy, policies, and operational controls. * Serve as the primary subject matter expert on security, risk, and compliance for executive leadership, board members, and external auditors. * Manage security budget allocation, resource planning, and third-party vendor risk assessments. Compliance & Audit Management * Lead and maintain ReadyOp's FedRAMP Moderate Authorization, ensuring continuous monitoring (ConMon), POA&M management, and annual third-party assessment organization (3PAO) audits. * Successfully guide ReadyOp through the current SOC 2 Type I audit and build the operational framework required for ongoing SOC 2 Type II compliance. * Ensure ongoing adherence to relevant standards and frameworks (NIST SP 800-53, ISO 27001, HIPAA, GDPR, etc.). Security Operations & Risk Management * Oversee incident response, threat management, vulnerability management, and penetration testing programs. * Direct security architecture reviews for SaaS application infrastructure, cloud integrations (AWS), and CI/CD development pipelines. * Conduct enterprise risk assessments and develop mitigation strategies to address emerging cyber threats. Culture & Security Awareness * Champion a company-wide culture of security through continuous employee training, phishing simulations, and clear security protocols. * Partner with engineering and product teams to integrate Security-by-Design and DevSecOps principles across the product lifecycle. ## Related Videos - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [Passkeys: Truly Phishing-Resistant? Implementation and Pitfalls](https://www.wearedevelopers.com/videos/100156-passkeys-truly-phishing-resistant-implementation-and-pitfalls) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps: Security in DevOps](https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)