Strategic Growth Partners Logo

Strategic Growth Partners

Fractional CISO

Posted 29 Days Ago
Remote
Hiring Remotely in USA
150K-180K Annually
Senior level
Remote
Hiring Remotely in USA
150K-180K Annually
Senior level
Serves as an outsourced CISO for multiple clients while leading SGP’s internal cybersecurity and compliance program. Responsibilities include NIST, CMMC, and ISO 27001 alignment; security assessments; risk reviews; SSPs, POA&Ms, audits, incident response, vulnerability management, executive reporting, security training, and compliance monitoring. The role also manages assessment partners, subcontracted vCISOs, client proposals, scalable GRC methodologies, and security reviews for business initiatives.
The summary above was generated by AI

Strategic Growth Partners is committed to upholding our company values and ensuring data confidentiality. We provide robust services to our clients across multiple time zones and foster a collaborative, innovative, and diverse work environment.

Strategic Growth Partners (SGP) is seeking an experienced Fractional CISO who can serve as Strategic Growth Partners' senior information security and compliance leader, acting as an outsourced CISO for client organizations while also owning SGP's internal security and compliance program. This full-time, exempt, remote position reports to the Chief Information Officer and works closely with client executives, internal IT teams, compliance partners, and business development. The role provides strategic cybersecurity leadership, hands-on compliance advisory, and scalable client delivery across SGP's growing cybersecurity and GRC practice.

Workplace Type: Remote.

Compensation: W-2. $150K–$180K per year.

Essential Duties and Responsibilities

  • Serve as acting CISO for multiple client organizations, including SGP, providing strategic security leadership and executive guidance.

  • Lead cybersecurity and compliance programs aligned with NIST SP 800-171 and 800-53, CMMC Levels 1 and 2, and ISO/IEC 27001.

  • Conduct security assessments, gap analyses, and risk reviews; develop System Security Plans (SSPs), Plans of Action and Milestones (POA&Ms), policies, and audit evidence.

  • Guide clients through certification, audit, and assessment-readiness activities, coordinating with C3PAO and RPO partners as needed.

  • Own and maintain SGP's internal compliance posture, applying the same standards delivered to clients.

  • Oversee incident response planning, vulnerability management, and security operations in partnership with IT teams.

  • Deliver executive reporting, security roadmaps, metrics, and board-ready presentations.

  • Coordinate security awareness training and tabletop exercises for SGP staff and clients.

  • Review technology and business initiatives, including ERP and business intelligence projects, for security and compliance impact.

  • Recruit and manage a bench of subcontracted vCISOs as the practice scales, ensuring consistent delivery quality.

  • Partner with business development on proposals, scoping, and client engagement growth.

  • Build reusable templates and methodologies to scale SGP's cybersecurity and GRC practice.

  • Maintain and coordinate Cyber Security compliance calendar activities including security self-assessments and security related internal audit activities.

  • Actively monitors threat information from key sources and partners (CISA, FBI, SOC/NOC) and escalates and educates as appropriate to the internal teams and executive leadership.

  • Monitor ongoing and proposed changes to major Compliance and Control frameworks.

  • Perform other duties as assigned.

Required Qualifications

  • Education: Bachelor's degree in cybersecurity, information technology, risk management, or a related field, or an equivalent combination of education and relevant experience.

  • Experience: At least 8 years of information security experience, including senior leadership experience as a Security Director, Vice President, CISO, or vCISO.

  • Knowledge: Hands-on expertise with NIST SP 800-171 and 800-53, CMMC Levels 1 and 2, ISO/IEC 27001, risk assessments, SSPs, POA&Ms, and compliance documentation.

  • Skills: Proven ability to lead multiple client engagements simultaneously, communicate effectively with executives, produce strong technical documentation, conduct assessments, and translate security requirements into practical business actions.

  • Licenses/Certifications: No certification is required; relevant industry certifications are strongly preferred.

Preferred Qualifications

  • CISSP, CISM, or Certified CISO (CCISO) certification.

  • ISO/IEC 27001 Lead Implementer or Lead Auditor certification.

  • CMMC CCP or CCA certification.

  • CRISC or CISA certification.

  • Consulting, MSP/MSSP, or professional-services experience.

  • CMMI experience, including process appraisal, improvement, or implementation.

  • Experience managing subcontractors or a distributed advisory team.

Core Competencies

  • Executive-level written and verbal communication.

  • Strategic security leadership paired with hands-on compliance execution.

  • Strong organizational and time-management skills across multiple client engagements.

  • Sound judgment, discretion, risk-based decision-making, and practical problem-solving.

  • Ability to maintain confidential and regulated information.

  • Ability to work independently and collaboratively with clients, internal teams, and external assessment partners.

  • Commitment to consistent, professional, and scalable client service.

Working Conditions and Physical Requirements

  • Work is primarily performed in a remote setting using standard computer and collaboration tools.

  • May require travel, extended hours, or availability outside normal business hours to support client assessments, executive meetings, or incident response activities.

  • Must be able to use a computer and communicate effectively for extended periods, with or without reasonable accommodation.

  • The physical requirements listed are representative of those needed to perform the essential functions of the role.

Disclaimer

This job description is intended to describe the general nature and level of work performed by employees in this position. It is not intended to be an exhaustive list of all duties, responsibilities, or qualifications. Duties may be modified or assigned based on organizational needs.

SGP is committed to hiring and retaining a diverse workforce. We are proud to be an Equal Opportunity/Affirmative Action Employer, making decisions without regard to race, color, religion, creed, sex, sexual orientation, gender identity, marital status, national origin, age, veteran status, disability, or any other protected class. We are committed to a collaborative, inclusive environment that encourages authenticity and fosters a sense of belonging. We are also committed to providing accommodations for persons with disabilities.

Similar Jobs

38 Minutes Ago
Remote or Hybrid
United States
135K-185K Annually
Senior level
135K-185K Annually
Senior level
Artificial Intelligence • Cloud • Payments • Software • Business Intelligence • Generative AI • Automation
Lead and grow a global data engineering team while establishing foundational data platforms and engineering standards. Design and oversee GCP-based pipelines, medallion data models, DataOps, monitoring, SLAs, CI/CD, governance, and data quality practices. Drive AI adoption across engineering workflows and build reliable, AI-ready data. Partner with business and technology stakeholders to prioritize roadmaps, deliver scalable solutions, and support data democratization.
Top Skills: Apache AirflowBigQueryCeligoChatgptClaudeCloud ComposerCloud IamCloud StorageCopilotData Policy TagsDataflowDbtGCPInfrastructure As CodeLookerPub/SubPythonSQL
An Hour Ago
Remote or Hybrid
United States
87K-100K Annually
Senior level
87K-100K Annually
Senior level
AdTech • Agency • Artificial Intelligence • Digital Media • Marketing Tech • Social Media • PropTech
Manage strategically complex client relationships and portfolios, owning retention, expansion, and cross-channel digital marketing strategy. Lead quarterly business presentations, deliver data-backed recommendations, coordinate internal teams, and act as a Fiona platform expert. Drive departmental initiatives, process improvements, product feedback, client onboarding, and mentorship for Account Managers and Coordinators. Success is measured through retention, client satisfaction, response times, reporting accuracy, expansion, revenue growth, and team development.
Top Skills: AIDisplay AdvertisingEmail MarketingFionaGeofencingNative AdvertisingOrganic SocialPaid SearchPaid SocialReputation ManagementSeo
An Hour Ago
Remote or Hybrid
United States
79K-89K Annually
Entry level
79K-89K Annually
Entry level
Cloud • Fintech • Information Technology • Machine Learning • Software
Support Xero’s partner sales channel by guiding accounting and bookkeeping practices through onboarding, data migration, software implementation, and activation. Deliver one-on-one and group training on Xero and related products, manage stakeholder expectations, schedule virtual and on-site sessions, maintain Salesforce records, and create self-service resources. The role requires frequent travel to partner practices and strong accounting, communication, presentation, and relationship-building skills.
Top Skills: Advance TrackCloud Accounting PlatformsGmtHubdocJet ConvertMelioSaaSSalesforce CRMSyftXeroXero Payroll

What you need to know about the Colorado Tech Scene

With a business-friendly climate and research universities like CU Boulder and Colorado State, Colorado has made a name for itself as a startup ecosystem. The state boasts a skilled workforce and high quality of life thanks to its affordable housing, vibrant cultural scene and unparalleled opportunities for outdoor recreation. Colorado is also home to the National Renewable Energy Laboratory, helping cement its status as a hub for renewable energy innovation.

Key Facts About Colorado Tech

  • Number of Tech Workers: 260,000; 8.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Lockheed Martin, Century Link, Comcast, BAE Systems, Level 3
  • Key Industries: Software, artificial intelligence, aerospace, e-commerce, fintech, healthtech
  • Funding Landscape: $4.9 billion in VC funding in 2024 (Pitchbook)
  • Notable Investors: Access Venture Partners, Ridgeline Ventures, Techstars, Blackhorn Ventures
  • Research Centers and Universities: Colorado School of Mines, University of Colorado Boulder, University of Denver, Colorado State University, Mesa Laboratory, Space Science Institute, National Center for Atmospheric Research, National Renewable Energy Laboratory, Gottlieb Institute

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account