Chief Information Security Officer
Listed on 2026-06-26
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Chief Information Security Officer (CISO)
Turbo Vets | Phoenix, AZ (Hybrid) | Reports to CEO & CTO
About Turbo VetsTurbo Vets builds technology for the people who served — service members, veterans, and the federal agencies that support them. We work across federal and commercial product lines, and security and compliance touch everything we do.
The RoleWe're hiring our first CISO. This is a build role — not a steady-state operator role. You'll own the security function end-to-end, partner directly with the CEO and CTO, and set the strategy from the ground up.
We're not looking for a traditional 20-year CISO. We want someone with a strong cybersecurity foundation, a developer's instincts, executive judgment, and the learning velocity to use AI as a real force multiplier.
What You'll Own- Commercial compliance program — frameworks, technical and administrative safeguards, and ongoing assessments (SOC 2 and others as the business scales)
- Cloud security end-to-end: identity, network, data, logging, key management, and incident response
- Overall security strategy across product, infrastructure, corporate IT, and vendor risk
- Incident response leadership — you're the executive on point when something happens
- Security tooling stack — evaluating, selecting, and keeping the portfolio lean
- Federal product line partnership — executive sponsorship alongside the teams managing day-to-day federal work
- Building and growing the security and compliance function — hiring, developing, and training the team
Required:
- Cybersecurity background (vendor, services, or in-house) — credible with engineers, auditors, and customers
- Hands-on experience selecting and deploying security tooling (SIEM, vulnerability management, identity, container security, etc.)
- Software development background — can read code and contribute to automation
- Working knowledge of AWS and modern cloud architecture
- High learning velocity; genuinely uses AI as a knowledge multiplier
Preferred:
- Exposure to HIPAA, SOC 2, FedRAMP, NIST 800-53, CMMC, or ATO processes
- Prior experience at a cybersecurity company or security-adjacent startup
- Familiarity with federal customers (DoD, DHS, USCG, VA)
- CISSP, CISM, CCSP, or HCISPP — nice to have, not required
- 90 days:
Commercial posture assessed, compliance plan drafted, 12-month roadmap in place - 6 months:
Controls operational, cloud baseline hardened, partnership rhythm established across product lines - 12 months:
An auditable, automation-heavy security program across commercial and federal — built with engineering, accelerated by AI
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).