The RoleWe are looking for a Cyber Security Advisor to join our Cyber Practice and deliver directly to clients. This is not a sales role, not a tools implementation role, and not an internal security role. It is a client-facing advisory position for someone who has already made the transition from practitioner to consultant and is ready to operate with significant autonomy.
You will work with mid-market and enterprise IT and security leaders across a range of engagements: framework-based gap assessments, fractional CISO advisory, security program design and roadmap development, ongoing program management, and structured security technology selections. You will be the person the client calls when they need to understand where they stand, what to do next, and whether their security providers are actually delivering.
This role is approximately 70% advisory and 30% sourcing and vendor selection support.
What You Will Actually DoAdvisory and Program Management (primary):
- Lead framework-based gap assessments (NIST CSF, CIS Controls, SOC 2, and similar) and translate findings into prioritized, executable roadmaps the client can act on with their existing team and budget
- Serve as a fractional CISO for mid-market and enterprise clients: advise CIOs and IT Directors on security program structure, vendor management, and risk prioritization
- Design and manage ongoing security programs: define reporting cadence, track initiative progress, manage relationships with MSP and MSSP providers on the client's behalf, and keep the business accountable to the roadmap
- Help clients communicate security posture and investment decisions to executive stakeholders; ghost-write board presentations, business cases, and risk summaries that non-technical leadership can understand and act on
- Adjust program direction as business needs evolve, without losing momentum or client confidence
Sourcing and Vendor Selection (supporting):
- Participate in structured vendor selection processes for security technologies and managed services including MDR, SOC, MSSP, and adjacent tools, using Resourcive's established selection methodology
- The selection process itself is structured and repeatable; your value in this work is your technical credibility and ability to evaluate vendor claims, ask the right questions, and give the client an informed perspective on tradeoffs
- Support contract and commercial negotiations alongside senior advisors
Practice and Credibility Building:
- Represent the Cyber Practice at industry events and conferences as a subject matter expert
- Contribute to the development of our engagement methodology and internal knowledge base
What We Are Looking For- 5 to 8+ years of cybersecurity experience, with a meaningful portion of that in a client-facing advisory, consulting, or fractional role
- A technical practitioner background (security engineering, incident response, SOC leadership, or similar) that you have already translated into advisory work; you understand how the technology works but your value is no longer in operating it
- Demonstrated ability to manage client relationships at the CIO or Director of IT level: setting expectations, delivering difficult findings, and maintaining trust through a full engagement lifecycle
- Experience designing or managing a security program, not just assessing one; you know what it takes to move an organization from a gap analysis to measurable progress
- Strong written communication skills; the ability to write a clear, credible board summary or executive business case is a meaningful differentiator for this role
- Comfort operating in a small firm environment where you will have significant autonomy and limited administrative support
Helpful but not required:- Familiarity with security technology categories and the vendor landscape (MDR, SIEM, MSSP, endpoint, identity); depth here is a plus, not a gate
- Experience presenting at industry conferences or contributing to public-facing thought leadership
- Relevant certifications (CISSP, CISM, or similar); we care more about demonstrated advisory capability than credential stacking
What This Is NotThis role does not involve hands-on configuration, tool administration, or managed security operations. We place vendors for that work. The advisor's job is to help the client make the right decision, manage the provider relationship, and ensure the outcome matches the intent.
Compensation:Base Range : $110,000 - $130,000 and total compensation range $150,000-$170,000
Actual annual salary offered to a candidate will be based on a number of variables including work experience, education and skills/ achievements, and will be mutually agreed upon at the time of offer.
For non-sales roles and sales roles with a variable component, total compensation reflects both a base salary and variable targets.
While we're committed to providing top-tier solutions, we're just as committed to supporting our own team. Our employees enjoy a variety of comprehensive benefits, including medical/dental/vision coverage, life insurance, and a 401(k) plan with matching provision. Outside of CA, ScanSource grants 128 hours of paid time off (PTO) each calendar year (prorated for date of hire). In the state of CA, employees accrue a set number of hours each pay period equaling the same 128 hours of PTO. ScanSource also celebrates 8 paid company holidays.