20+ years in professional cybersecurity roles with senior leadership experience
5+ years as a vCISO, CISO, or senior cybersecurity consultant
3+ years of direct management experience
Ability to manage a personal billable book while leading a team
Experience in GRC planning and compliance alignment
Knowledge of various cybersecurity frameworks and technologies
Industry experience in sectors like finance, healthcare, and critical infrastructure
Responsibilities
Manage a team of vCISO Managers, focusing on performance and development
Set targets for utilization and quality among team members
Review and approve client deliverables before issuance
Serve as the escalation point for complex client issues
Conduct regular 1:1s and team meetings to foster a learning culture
Lead hiring and onboarding initiatives for the growing team
Identify and address skill gaps through internal training
Benefits
Comprehensive medical, dental, and vision insurance with high employer contribution
Employer funding for HSA accounts and access to FSA
401(k) with guaranteed employer contribution
Flexible vacation policy for work-life balance
11 paid holidays with personalization options
Robust family-friendly benefits including maternity and parental leave
Support for professional development through certifications and conferences
Full Job Description
This is a remote position from anywhere in the USA.
What You Will Do:
People Leadership (Managing vCISO Managers):
Directly manage a team of vCISO Managers - own their performance management, career development, and day-to-day support.
Set and monitor utilization, quality, and engagement-health targets across your team's book of business; step in on at-risk accounts.
Review and approve deliverables (assessments, roadmaps, board decks, policy sets) produced by your managers before they reach clients.
Serve as the escalation point for complex client situations, scope conflicts, or technical/strategic questions your managers surface.
Run regular 1:1s, team meetings, and case reviews; build a culture of peer learning and shared frameworks across the team.
Lead hiring, onboarding, and ramp planning for new vCISO Managers as the team grows.
Identify skill gaps across the team and build/deliver internal training, playbooks, and templates to close them.
Own staffing and capacity planning: matching manager bandwidth and expertise to client demand in partnership with delivery leadership.
Client Delivery & Strategic Advisory:
Carry your own portfolio of vCISO / Managed Security Services engagements, providing expert cybersecurity consulting at the C-suite and board level.
Advise clients on the development and execution of comprehensive security strategies and roadmaps aligned to business objectives.
Attend and contribute to senior-level client meetings, including security steering committees and board meetings.
Facilitate executive workshops and training sessions to promote security awareness.
Plan, scope, and execute vCISO advisory engagements, including client discovery, assessments, and reporting.
Develop and maintain cybersecurity policies, procedures, and control frameworks for client organizations.
Create client-facing presentations, reports, and analytics; communicate results to executive stakeholders.
Governance, Risk & Compliance (GRC):
Manage risk assessment and mitigation processes for client engagements; align cybersecurity initiatives with client risk management strategies.
Review and assess security controls against best-practice and regulatory frameworks (e.g., CIS, NIST, ISO, PCI, CMMC, SOC, HIPAA).
Coordinate audits, compliance assessments, and regulatory reporting (e.g., SEC, NYDFS, CMMC, PCI, HIPAA, FedRAMP, GDPR, SOX) across your team's accounts.
Ensure consistency and quality of GRC deliverables across your managers' engagements.
Technical Security Oversight:
Advise on and oversee implementation of security technologies (SIEM, IDS/IPS, endpoint protection, data protection, cloud security tools) across client accounts.
Provide senior oversight on vulnerability scanning, penetration testing, and security audit engagements led by your team.
Coordinate incident response planning and threat management initiatives; act as senior escalation during active incidents.
Provide advisory support on integrating and optimizing security tools and technologies.
Practice & Business Development
Partner with sales and practice leadership on scoping, proposals, and pricing for new and expanding vCISO engagements.
Support account growth: identify opportunities to expand scope within existing clients managed by your team.
Produce thought leadership content (blogs, webinars, articles) and represent Echelon at industry conferences and events.
Contribute to the ongoing evolution of Echelon's vCISO methodology, templates, and service offerings.
Your Knowledge, Skills, and Abilities
20+ years in professional cybersecurity and technical roles, including senior-level leadership and advisory experience.
5+ years as a vCISO, CISO, or senior cybersecurity/technical consultant, preferably in a Managed Services environment.
3+ years of direct people management experience - managing consultants, managers, or advisory staff, including performance reviews, coaching, and career development.
Demonstrated ability to balance a personal billable book of business (60%+ utilization) with team leadership responsibilities.
Proven ability to manage multiple, simultaneous client engagements across a team and deliver quality results under tight deadlines.
Experience in GRC planning, development, and management, including Information Security policy and procedure development.
Experience across a variety of industries - finance, banking, private equity, healthcare, critical infrastructure, technology services, and other regulated environments.
Proficient in leading cybersecurity frameworks (e.g., CIS, NIST, ISO, SOC2, COBIT, ITIL, PCI, GDPR, HIPAA).
Knowledge of cloud systems, applications, and security tools (e.g., EDR, MDR, SIEM, CSPM, IAM).
Familiarity with network security, data security, vulnerability management, incident response, disaster recovery, and third-party risk management.
Certification: CISSP, CISA, CISM, CRISC, CGRC, CvCISO, CGEIT, or similar.
Education: Degree in Information Systems, Computer Science, or a related discipline preferred.
Applicants must have authorization to work in the United States without current or future visa sponsorship.
Preferred Qualifications:
Prior experience managing a team of vCISOs, security consultants, or client-facing advisory staff at an MSP or MSSP.
Track record of building or scaling a vCISO/advisory practice - including staffing models, delivery playbooks, and QA processes.
Experience building security programs from the ground up, including framework adoption and roadmap development (priorities, timelines, budgets).
Strong executive advisory skills - capable of developing extensive reports and presentations and delivering complex security concepts to non-technical audiences.
Experience contributing to proposals, pricing, or account growth in a consulting/professional services context.
Superior attention to detail, with a strong aptitude for both technical and strategic problem-solving.
Active participation in cybersecurity thought leadership and industry events.
Intellectual curiosity with a continuous learning mindset.
Adaptability and versatility in a fast-paced, demanding environment.
We currently offer the following benefits:
Access to medical, dental, and vision insurance through Cigna, with the majority of the employee cost covered by the employer
Employer funding to HSA accounts and FSA access
Access to a 401(k) through Vanguard with a guaranteed employer contribution
Flexible vacation policy that allows you to manage your schedule and rest and recharge when you need to
11 holidays with flexibility based on what is important for you and those you love
Family-friendly benefits, including weeks off for Maternity leave, weeks off for non-birthing parent leave, employer-paid short-term and long-term disability, employer-paid life insurance, and access to additional life insurance, hospital coverage, accidental coverage, discounted mental health support, and more
Support for individual development through certifications, continued learning, conferences, and more