The CISO Mentor will provide strategic guidance on improving network-layer defenses, managing vulnerability processes, and leading incident response efforts. They will also contribute to security culture by training product teams and overseeing compliance and fraud initiatives.
Social Discovery Group (SDG) is a group of social discovery companies. SDG solves the problems of loneliness, isolation, and disconnection - transforming virtual intimacy into the new normal. SDG’s products redefine the way people interact and connect with one another.
Our portfolio includes social entertainment platforms designed to connect people online across different cultures and regions of the world.
We bring together a team of like-minded people and IT professionals who specialize in creating and developing globally impactful social discovery products. Our international team of digital nomads works remotely from all over the world.
We’re proud to be a two-time “Great Place to Work” winner (USA & Japan, 2024–2025) and a Top-5 Company for Work-From-Anywhere Jobs (FlexJobs, 2025).
We are looking for CISO Mentor to join us for several hours per months.
Your main tasks will be:
Improve and maintain perimeter and network-layer defenses (WAF, Rate Limiting, Anti-bot ,DDoS mitigation
Secure product APIs against abuse and anomalous traffic
Strengthen authentication, authorization, and access control at the product level, including IDOR-class issues
Run the Vulnerability Management process: identification, prioritization, and remediation tracking
Coordinate external pentests and drive remediation of findings
Lead Incident Response for product security incidents
Build detection and response processes together with the monitoring team
Contribute to Fraud & Trust and Safety initiatives with relevant teams
Protect customer data at the product level (access control, encryption, masking)
Run the Security Champions program to train product teams on secure development
Manage the Bug Bounty program
We expect from you:
7+ years in senior Information Security leadership (CISO, VP of Security, or Head of InfoSec), with a proven track record of mentoring or advising emerging security leaders.
Zero-to-One Experience: Proven experience building, scaling, and managing an Information Security program entirely from scratch for a startup or scaling enterprise.
High-Compliance Expertise: Deep, practical knowledge of operating in heavily regulated markets (e.g., FinTech, HealthTech, GovTech) and successfully leading organizations through rigorous audits (SOC 2 Type II, ISO 27001, PCI-DSS, HIPAA, or GDPR).
Highload/Scalability Acumen: Strong architectural understanding of securing high-throughput, highly available, distributed systems and cloud-native environments (AWS/GCP/Azure) without bottlenecking performance.
Strategic GRC (Governance, Risk, and Compliance): Ability to teach and establish risk management frameworks, compliance roadmaps, and vendor risk management processes.
Executive Communication: Exceptional ability to translate complex technical risks into business impacts, and experience coaching others on how to present security strategies to C-level executives and the Board of Directors.
Incident Response Leadership: Experience establishing and commanding an enterprise-grade Incident Response plan, including crisis management and post-breach communications.
Security Culture Building: Demonstrated ability to foster a "security-first" culture across engineering, product, and business teams.
“I was the first applicant for a remote marketing position that got listed on the company website the same day I applied. Had an interview within 48 hours!”