Fractional CISO
Core
Senior information security and compliance leader acting as an outsourced CISO for client organizations while owning internal security programs.
Role type
Senior IC fractional CISO (GRC & Compliance)
Builds
Scalable cybersecurity and GRC practice, client certification readiness, internal compliance posture
Domain
Cybersecurity, Governance, Risk, and Compliance (GRC)
Deliverable
production ML models | product features | dashboards & analysis | client delivery | infrastructure
Required skills
Strategic security leadership, NIST SP 800-171/800-53 expertise, CMMC Levels 1 & 2 knowledge, ISO/IEC 27001 implementation, risk assessment, SSP/POA&M development, executive reporting, incident response planning, vulnerability management, subcontractor management, business development partnership
Preferred skills
CISSP, CISM, CCISO, ISO/IEC 27001 Lead Implementer/Auditor, CMMC CCP/CCA, CRISC, CISA, consulting/MSP/MSSP experience, CMMI process appraisal
Technologies
NIST SP 800-171, NIST SP 800-53, CMMC, ISO/IEC 27001, ERP systems, business intelligence platforms
Responsibilities
Serve as acting CISO for multiple clients and internally; lead compliance programs aligned with NIST/CMMC/ISO; conduct security assessments and gap analyses; guide clients through certification and audit readiness; oversee incident response and vulnerability management; deliver executive reporting and security roadmaps; recruit and manage a bench of vCISOs; partner on business development proposals; build reusable compliance methodologies.
Seniority
Senior, hands-on IC with strategic scope