Fractional CISO and Cybersecurity Architect
Worldwide
Fractional CISO and Cybersecurity Architect AI-Native SaaS, Microsoft Azure and SOC 2 Independent Contractor Engagement through Upwork Ziing AI is building an advanced, AI-native supply chain platform designed to transform how enterprise logistics operations are planned, orchestrated, and executed. As we scale the platform, onboard enterprise customers, expand our AI capabilities, and progress through our SOC 2 program, cybersecurity must become a strategic differentiator rather than a compliance exercise. We are seeking a senior cybersecurity professional who can operate as a fractional CISO and hands-on security architect. This individual will help establish the security foundation required for an enterprise-grade, multi-tenant AI platform. This is not a policy-writing or audit-checklist engagement. We need someone who can assess technical risk, challenge architecture, work directly with engineering, guide remediation, and ensure our controls are defensible with customers, auditors, partners, and investors. The Mandate The contractor will help us: Advance our SOC 2 readiness and examination program Establish a scalable cybersecurity strategy and operating model Assess and strengthen our Microsoft Azure security posture Review identity, privileged access, APIs, data, and multi-tenant architecture Strengthen DevSecOps and software supply-chain security Establish security standards for AI-enabled and agentic systems Improve incident response, ransomware resilience, backup, and recovery Build audit-ready controls and evidence into our engineering processes Prepare the platform for enterprise customer security requirements Develop a roadmap for future standards such as ISO/IEC 27001 Initial Outcomes The initial engagement should produce: An assessment of our current cybersecurity posture A prioritized register of material risks and control gaps A review of SOC 2 control design, implementation, and evidence A technical assessment of Azure, identity, application, API, DevSecOps, and recovery controls A 90-day remediation plan A 12-month cybersecurity roadmap Clear recommendations for executive leadership Hands-on support implementing the highest-priority controls We are looking for practical outcomes, not generic reports or policy templates. Required Experience Applicants should have: 8 or more years of cybersecurity, cloud security, security architecture, or technology-risk experience Direct experience leading SOC 2 Type I or Type II readiness programs Strong hands-on Microsoft Azure security experience Experience securing enterprise SaaS or multi-tenant platforms Strong knowledge of identity, privileged access, service principals, secrets, and non-human identities Experience with application, API, and DevSecOps security Experience working directly with engineering and product teams Experience with incident response, ransomware resilience, and recovery planning Ability to communicate material cybersecurity risks to executive leadership Ability to move from assessment to implementation Preferred Experience The following would be highly valuable: AI, generative AI, or agentic-system security Microsoft Entra ID, Defender for Cloud, Sentinel, Azure DevOps, and AKS ISO/IEC 27001 readiness or implementation NIST Cybersecurity Framework NIST Secure Software Development Framework OWASP API and AI security guidance Infrastructure-as-code and Terraform security Software supply-chain security Enterprise customer security reviews Supply chain, logistics, transportation, healthcare, or other complex enterprise environments Relevant certifications such as CISSP, CCSP, CISM, CISA, CRISC, or ISO 27001 Lead Implementer are beneficial. Demonstrated outcomes and technical judgment are more important than certifications alone. Technology Environment Our platform includes technologies such as: Microsoft Azure Microsoft Entra ID Azure Kubernetes Service Azure Functions Azure API Management Azure Service Bus and Event Grid Azure SQL and Cosmos DB Azure Key Vault Microsoft Defender for Cloud Microsoft Sentinel Azure DevOps Terraform .NET and C# Angular Flutter REST APIs Microservices AI-enabled workflows and automation Proposal Requirements Please include: A summary of your cybersecurity leadership and architecture experience Two SOC 2 engagements you personally led or materially supported Examples of Azure or SaaS security programs you have implemented Your experience securing AI-enabled or agentic systems Your proposed priorities for the first 30 days Your hourly rate Weekly availability Earliest start date Confirmation that you will personally perform the work Please begin your proposal with the words “Security must be engineered” so we know you have read the full posting. Contractor Engagement This opportunity is strictly for an independent contractor engaged through Upwork. The engagement does not create an employer-employee relationship. The contractor is responsible for their own taxes, insurance, equipment, work environment, and statutory obligations. Work will be organized through defined deliverables, milestones, and agreed outcomes. The contractor may provide services to other clients and will retain discretion over how the services are performed, subject to security requirements, timelines, and acceptance criteria. All work product created specifically for the engagement will be owned by the client in accordance with the applicable Upwork contract and intellectual-property provisions. Final Note We are not looking for someone who will merely help us pass an audit. We are looking for a senior cybersecurity leader who can help make Ziing AI: Enterprise-ready Secure by design Resilient against emerging threats Credible with sophisticated customers Prepared for future certifications Defensible through technical evidence Ready to scale as an AI-native technology company Applicants seeking permanent employment should not apply.
- Less than 30 hrs/weekHourly
- 6+ monthsDuration
- IntermediateExperience Level
$30.00
-
$50.00
Hourly- Remote Job
- Complex projectProject Type
Skills and Expertise
Activity on this job
- Proposals:20 to 50
- Interviewing:0
- Invites sent:0
- Unanswered invites:0
About the client
- CanadaCalgary4:36 PM
- $2.7M total spent111 hires, 29 active
- 84,998 hours
Explore similar jobs on Upwork
How it works
Create your free profileHighlight your skills and experience, show your portfolio, and set your ideal pay rate.
Work the way you wantApply for jobs, create easy-to-by projects, or access exclusive opportunities that come to you.
Get paid securelyFrom contract to payment, we help you work safely and get paid securely.
About Upwork
- 4.9/5(Average rating of clients by professionals)
- G2 2021#1 freelance platform
- 49,000+Signed contract every week
- $2.3BFreelancers earned on Upwork in 2020
Find the best freelance jobs
Growing your career is as easy as creating a free profile and finding work like this that fits your skills.
Trusted by