Syndicated · explicitly fractionalFractional CISOUnited Kingdom

Fractional CISO, OdoTrust

FRACTIONAL CISO JOB · COMPUTER AND NETWORK SECURITY SECTOR · UNITED KINGDOM

Engagement
FractionalEmbedded · part-time
Days / week
Not statedTypically 2–3
Day rate
Not statedNot benchmarked
IR35
Not statedClarify at apply

OdoTrust is seeking a fractional compliance/CISO advisor to validate their SOC 2 framework, assess EU AI Act positioning, and open doors to audit firms and compliance-bound customers. No sales quota, no pipeline pressure—pure advisory plus revenue share on introductions. Equity-only compensation model; no stated day rate or hours commitment.

01

The balanced verdict

Why this role stands out
  • Explicitly fractional/advisor structure; titles offered (Lead Auditor, vCISO, Fractional CISO, Head of Compliance, DPO) all suit portfolio careers
  • Clear 90-day deliverables (framework audit, roadmap judgment, audit-firm relationship, five introductions) make scope tangible
  • Revenue-share upside on customer introductions aligns advisor with success; no quota or CRM overhead
  • Early-stage, product-live startup with public pricing and transparent values
Worth checking before you apply
  • Compensation is equity + revenue share only; no stated day rate, monthly retainer, or base salary—suitability depends entirely on financial runway and upside belief
  • Days/week and time commitment left undefined; 90-day sprint language suggests concentrated effort, but flexibility unclear
  • Network-driven success metric ('five qualified introductions') means value depends on your existing compliance-buyer relationships; weak network = weak fit
Fractional-fit score
82/100
02

The posting in full

~/original-posting · verbatimsource: fantastic-jobs

Company Description OdoTrust is a compliance software platform designed to make evidence management transparent, accessible, and fairly priced. The company rejects opaque pricing and lock-in contracts, instead offering published pricing, month-to-month billing, and evidence export in usable formats from day one. The platform provides control frameworks and first-draft policies mapped directly to auditor-tested criteria, while allowing organizations to run their own controls within their existing systems. SOC 2 support is live, and ISO 27001, HIPAA, and EU AI Act capabilities are on the roadmap.

MISSION Make OdoTrust credible across every framework it claims, and introduce it to the companies that need them.

WHAT SUCCESS LOOKS LIKE IN 90 DAYS 1. A written verdict on the control set. Does the SOC2 framework hold up in real fieldwork? A gap list, not an opinion. 2. A judgement on the AI-era roadmap. EU AI Act, AI governance controls and AI risk documentation 3. At least one certification or audit relationship opened. A named firm or body that would accept OdoTrust-produced evidence. 4. Five qualified introductions. Companies facing a compliance requirement in the next two quarters. Warm, not a list.

WHAT YOU WOULD DO Review the SOC2 and any other control framework and say plainly where it would fail, and what to add/ipmrove. Tell us which claims we are allowed to make. Open doors to audit firms and certification bodies who work with startups. Introduce us to companies facing a compliance requirement. Push back on the roadmap when we are building the wrong thing.

You are not being asked to sell. No quota, no pipeline, no CRM. Closing is our responsibility.

WHAT WE ARE LOOKING FOR You work across more than one regime: SOC 2 ISO 27001 GDPR as a working obligation, not a checkbox. EU AI Act familiarity You know what an auditor or certification body accepts as evidence and what gets sent back. You have a network of companies facing a compliance requirement within the year, and you are willing to use it.

Titles this might sit under: Lead Auditor or Lead Implementer, ex-enterprise risk assurance, vCISO, Fractional CISO, Head of Compliance, DPO who also handles security frameworks and other.

WHAT WE OFFER Equity Revenue from every customer you introduce, paid when they convert

WHERE WE ACTUALLY ARE Product MVP built, website live. Pricing public.

HOW TO APPLY Share CV and Reply, 3 things: 1. Which frameworks you know or have actually taken a company through, and in what role. 2. Your read on the EU AI Act as a commercial opportunity for a compliance platform. Real demand, or two years early? 3. Roughly how many companies in your network will face a compliance requirement in the next two quarters?

not quite the right fit?

Tell us what you're actually looking for.

Browse every live UK fractional and interim mandate — day-rate transparent, verified live, and flagged when a role is worth a fractional pitch.

Rate n/a · United Kingdom
Apply ↗
Book a meeting