Full Job Description
The Security Architect / vCISO is a client-facing, dual-capacity role that combines deep technical security architecture expertise with strategic, executive-level security advisory services. In the vCISO capacity, this individual serves as an outsourced Chief Information Security Officer for multiple client organizations, developing security strategies, managing risk and compliance posture, and acting as a trusted security advisor to client leadership and boards.
In the Security Architect capacity, this role designs, evaluates, and validates the technical solutions required to bring security strategies to life. The ideal candidate can seamlessly transition between executive-level risk discussions and hands-on security architecture reviews while supporting multiple clients with varying security maturity levels.
Key Responsibilities
vCISO / Advisory
- Serve as the virtual CISO for a portfolio of client accounts, acting as a primary strategic security advisor.
- Develop and present security strategies, roadmaps, and risk registers aligned with each client's business objectives, industry requirements, and risk tolerance.
- Lead and present during client executive and board-level meetings, translating technical security risks into clear business impacts.
- Own and support client compliance programs (SOC 2, ISO 27001, HIPAA, PCI DSS, NIST CSF, etc.), including gap assessments, remediation planning, and audit support.
- Conduct enterprise security risk assessments and maintain client risk registers, prioritizing findings based on business impact.
- Serve as the client's security incident response advisor and leader during security events, coordinating internal teams and external resources as needed.
- Build strong relationships with client stakeholders, serving as a trusted long-term security partner.
- Support pre-sales activities, including scoping vCISO engagements, security assessments, and proposal development.
Security Architecture
- Design secure network, cloud, application, and identity architectures for client environments across a variety of industries and security maturity levels.
- Design and validate identity security architectures, including identity governance, access management, privileged access controls, authentication strategies, and Zero Trust implementations.
- Evaluate identity-related risks and recommend improvements across Active Directory, Entra ID, IAM/PAM platforms, and cloud identity environments.
- Perform architecture reviews and control gap assessments against security frameworks and client-specific requirements.
- Lead threat modeling and security design reviews for client projects, migrations, and new technology deployments.
- Recommend and help implement security tooling and technical controls (SIEM, EDR, IAM, PAM, DLP, cloud security posture management, etc.).
- Develop client-specific security policies, standards, and technical documentation.
- Collaborate with internal delivery teams (SOC, engineering, GRC) to ensure security solutions are implemented according to design.
- Stay current on emerging threats, security technologies, and industry trends to continuously improve client security strategies and architectures.
Required Qualifications
- 7-10+ years of experience in information security, including both hands-on technical architecture and strategic security advisory responsibilities.
- Prior experience as a CISO, vCISO, security consultant, or senior security architect, preferably in a client-facing or multi-client environment.
- Strong working knowledge of security frameworks including NIST CSF, ISO 27001, CIS Controls, SOC 2, PCI DSS, and HIPAA as applicable.
- Demonstrated experience designing cloud and enterprise security architectures across AWS, Azure, and/or GCP environments.
- Experience designing and evaluating identity security solutions, including IAM, PAM, authentication, authorization, and Zero Trust strategies.
- Proven ability to communicate security risks, recommendations, and strategy to executives, boards, and non-technical stakeholders.
- Experience managing multiple concurrent client relationships or business units with strong prioritization and time-management skills.
- Excellent presentation, documentation, consulting, and communication skills.
- Ability to travel to client sites as needed.
Preferred Qualifications
- Relevant certifications: CISSP, CISM, CCISO, SABSA, CRISC, CCSP.
- Prior experience working for an MSSP, consulting firm, or vCISO services organization.
- Experience with GRC platforms and risk quantification methodologies (such as FAIR).
- Industry-specific compliance experience (healthcare, financial services, government/CMMC, etc.).
- Experience contributing to security service line growth through pre-sales, proposals, and client retention activities.