Virtual CISO & Cybersecurity Practice Lead
Core
Senior cybersecurity practitioner and virtual CISO providing outsourced executive-level security leadership to a portfolio of mid-market clients.
Role type
Senior IC Virtual CISO & Cybersecurity Practice Lead
Builds
Security programs, compliance frameworks, and incident response capabilities for mid-market clients.
Domain
Cybersecurity / GRC / Risk Management
Deliverable
client delivery
Required skills
Penetration testing, Incident response, Security architecture, Governance Risk and Compliance (GRC), Risk assessment, Compliance management, Incident response coordination, Business development, Team leadership, Playbook development
Preferred skills
Experience with SOC 2, HIPAA, PCI-DSS, CCPA, NIST CSF, CMMC frameworks, AI-driven security tooling
Technologies
AI-driven security tooling, Vulnerability scanners, Log analysis platforms, Threat detection systems
Responsibilities
Serve as outsourced CISO for 8–12 clients providing executive-level security leadership; Conduct security risk assessments, gap analyses, and penetration testing oversight; Develop and maintain security programs, policies, and incident response plans; Manage compliance frameworks including SOC 2, HIPAA, PCI-DSS, CCPA, NIST CSF, and CMMC; Present security posture and risk exposure to boards of directors and C-suites; Oversee and leverage AI-driven security tooling for vulnerability scanning and threat detection; Quarterback incident response when clients face active threats or breaches; Collaborate with reputation management team for integrated crisis response; Participate in business development to close new cybersecurity retainers; Recruit, manage, and mentor junior analysts; Build standardized methodologies and delivery playbooks to scale the practice.