
Fractional CISO
Posted Aug 27

Posted Aug 27
This is a fully remote position, open to applicants in United States.
• Act as the interim Chief Information Security Officer (CISO) for various client organizations, including SGP, providing strategic security direction and executive support.
• Spearhead cybersecurity and compliance initiatives in accordance with NIST SP 800-171 and 800-53, CMMC Levels 1 and 2, and ISO/IEC 27001 standards.
• Perform security evaluations, gap analyses, and risk assessments.
• Create System Security Plans (SSPs), Plans of Action and Milestones (POA&Ms), policies, and audit documentation.
• Assist clients in navigating certification, audit, and assessment-preparation processes.
• Collaborate with C3PAO and RPO partners as necessary.
• Take ownership of maintaining SGP's internal compliance status.
• Supervise incident response planning, vulnerability management, and security operations alongside IT teams.
• Provide executive-level reporting, security roadmaps, metrics, and presentations suitable for the board.
• Organize security awareness training and tabletop exercises for SGP personnel and clients.
• Evaluate ERP and business intelligence projects for their security and compliance implications.
• Recruit and oversee subcontracted virtual CISOs as the practice expands.
• Collaborate with business development on proposals, project scoping, and client relationship enhancement.
• Develop reusable templates and methodologies to enhance SGP's cybersecurity and GRC practice.
• Maintain and manage the Cyber Security compliance calendar, including security self-assessments and internal audits.
• Keep track of threat intelligence from CISA, FBI, and SOC/NOC sources; escalate issues and inform internal teams and executive leadership.
• Stay updated on ongoing and proposed modifications to major Compliance and Control frameworks.
• Fulfill additional responsibilities as assigned.
• A Bachelor’s degree in cybersecurity, information technology, risk management, or a related field, or a comparable combination of education and relevant experience.
• A minimum of 8 years of experience in information security.
• Proven senior leadership experience as a Security Director, Vice President, CISO, or vCISO.
• Practical knowledge of NIST SP 800-171 and 800-53, CMMC Levels 1 and 2, ISO/IEC 27001, risk assessments, SSPs, POA&Ms, and compliance documentation.
• Capacity to manage multiple client projects at once.
• Proficient communication skills for effective interaction with executives.
• Ability to create compelling technical documentation.
• Skilled in conducting assessments and translating security requirements into actionable business strategies.
• No specific certification is mandatory; however, relevant industry certifications are highly desirable.
• Preference for CISSP, CISM, or Certified CISO (CCISO) certification.
• ISO/IEC 27001 Lead Implementer or Lead Auditor certification is preferred.
• CMMC CCP or CCA certification is preferred.
• CRISC or CISA certification is preferred.
• Experience in consulting, MSP/MSSP, or professional services is preferred.
• Familiarity with CMMI is preferred.
• Prior experience managing subcontractors or a distributed advisory team is preferred.
• Strong executive-level written and verbal communication abilities.
• Excellent organizational and time-management skills across various client engagements.
• Demonstrated sound judgment, discretion, risk-based decision-making, and practical problem-solving skills.
• Ability to handle confidential and regulated information appropriately.
• Capability to work both independently and collaboratively with clients, internal teams, and external assessment partners.
• Must be capable of using a computer and communicating effectively for prolonged periods, with or without reasonable accommodation.
• Opportunity for remote work.
• W-2 employment status.
• Commitment to Equal Opportunity/Affirmative Action principles.
• Availability of disability accommodations.
• Potential for travel, extended hours, or availability outside standard business hours for client support.
Leader Bank
[Bulle & Mensch] – So handeln Profis wirklich.
Mercor
Mercor
Get handpicked remote jobs straight to your inbox weekly.