Fractional Chief Information Security Officer (CISO)
Role details
Job location
Tech stack
Job description
Fractional Chief Information Security Officer, Austco Healthcare is seeking an experienced Fractional CISO to lead enterprise cybersecurity strategy across a growing global organization. This is a strategic, hands-on leadership role, responsible for unifying security across Austco's corporate entity and its acquired subsidiaries, all regions, and any future acquisitions., * Develop and own the enterprise information security strategy aligned to business objectives across Austco and all subsidiaries
- Drive adoption of a centralized, managed IT operating model and advance maturity against the ACSC Essential Eight
- Establish and maintain security policies, standards, and frameworks (NIST CSF, ISO 27001, SOC 2, ACSC Essential Eight)
- Chair or advise the security steering committee; report to the Board on risk posture and maturity progress
- Lead IT roadmap planning and migration of infrastructure to cloud-based environments (AWS and equivalent), establishing a centralized IT operating model
ACQUISITION INTEGRATION & SUBSIDIARY ALIGNMENT
- Engage Austco's subsidiaries to align their IT domains with the enterprise security framework
- Evaluate and integrate future acquisitions from a security and IT perspective - assessing posture, risks, and integration requirements
- Work across all Austco regions (US, Canada, Australia, UK, Singapore, New Zealand) to drive consistent adoption of security objectives
RISK & COMPLIANCE
- Lead risk assessments and manage the organizational risk register
- Ensure compliance with HIPAA, HITECH, and applicable international data privacy regulations (GDPR, Australian Privacy Act, PDPA)
- Oversee third-party and vendor risk, including managed service provider (MSP) relationships
INCIDENT RESPONSE & OPERATIONS
- Own the incident response plan and lead response to significant security events
- Serve as a key escalation point within Austco's Business Continuity Plan (BCP) and Disaster Recovery Plan (DRP)
- Partner with IT teams and the MSP on vulnerability management, security architecture, and operational security
- Drive security awareness training across all global offices
LEADERSHIP & STAKEHOLDER MANAGEMENT
- Manage local IT teams across subsidiaries and regions, providing direction, oversight, and mentorship
- Act as the primary interface with the managed service provider (MSP), ensuring service levels and security standards are met
- Serve as the internal and external-facing security authority for Austco
- Advise on security implications of M&A activity, product development, and infrastructure changes
What Success Looks Like in The First 6 to 12 Months
Within the first year, we expect this engagement to deliver:
- A unified, centralized IT operating model established across the corporate entity and the ANZ subsidiaries
- Measurable progress against the ACSC Essential Eight, to a maturity level agreed with the Board
- Enterprise security policies, standards and a live organizational risk register adopted group wide
- An approved cloud migration roadmap underway
- Incident response, business continuity and disaster recovery plans validated through at least one tabletop exercise
- Security and IT integration plans agreed for each Austco subsidiary
Requirements
- 10+ years in information security, with at least 3 years in a CISO or senior security leadership role
- Demonstrated success leading security transformation in complex, multi-entity or post-acquisition environments.
- Proven ability to drive organizational change, including transitioning decentralized IT environments to centralized/managed models
- Experience building and executing IT roadmaps, including cloud migration (AWS or equivalent)
- Strong knowledge of HIPAA/HITECH, NIST CSF, ISO 27001, SOC 2, and the ACSC Essential Eight
- Experience operating across multiple international jurisdictions
- Strong executive communication and board-level reporting skills
- Availability for on-call incident response; willing to serve as the security escalation point for BCP/DRP events
- Ability to operate autonomously with minimal day-to-day supervision
HIGHLY REGARDED
- CISSP, CISM, or CISA certification
- Experience with IEC 62443 or medical device cybersecurity standards (FDA pre/post-market guidance)
- Background supporting SaaS or cloud-based product companies
- Familiarity with US, Canadian, New Zealand, Australian, UK, and Singapore regulatory environments
Benefits & conditions
This is an initial engagement of approximately two to three days per week, with an expected term of twelve months and scope to extend as the security function matures. Compensation is commensurate with experience and the fractional nature of the role.
Our Commitment to Inclusion
Austco Healthcare is an equal opportunity employer. We welcome applicants of all backgrounds and are committed to a fair and inclusive selection process.