This role will own the PCI domain in a fractional capacity, including PCI scoping support, evidence ... and CISO/vCISO.Required qualifications8+ years of cybersecurity, GRC, IT audit, compliance ...
Quick apply
This role will own the PCI domain in a fractional capacity, including PCI scoping support, evidence ... and CISO/vCISO.Required qualifications8+ years of cybersecurity, GRC, IT audit, compliance ...
Quick apply
This role will own the PCI domain in a fractional capacity, including PCI scoping support, evidence ... and CISO/vCISO.Required qualifications8+ years of cybersecurity, GRC, IT audit, compliance ...
This role will own the PCI domain in a fractional capacity, including PCI scoping support, evidence ... CISO/vCISO. Required qualifications * 8+ years of cybersecurity, GRC, IT audit, compliance ...
This role will own the PCI domain in a fractional capacity, including PCI scoping support, evidence ... CISO/vCISO. Required qualifications * 8+ years of cybersecurity, GRC, IT audit, compliance ...
Silver Spring, MD · On-site
$80 - $100/hr
This role will own the SOC 2 domain in a fractional capacity, including evidence review, control ... manager and CISO/vCISO. Required Qualifications * 8+ years of cybersecurity, GRC, IT audit, ...
Silver Spring, MD · On-site
$80 - $100/hr
This role will own the SOC 2 domain in a fractional capacity, including evidence review, control ... manager and CISO/vCISO. Required Qualifications * 8+ years of cybersecurity, GRC, IT audit, ...
This role will own the SOC 2 domain in a fractional capacity, including evidence review, control ... CISO/vCISO.Required qualifications8+ years of cybersecurity, GRC, IT audit, compliance, SaaS ...
Quick apply
This role will own the SOC 2 domain in a fractional capacity, including evidence review, control ... CISO/vCISO.Required qualifications8+ years of cybersecurity, GRC, IT audit, compliance, SaaS ...
This role will own the SOC 2 domain in a fractional capacity, including evidence review, control ... manager and CISO/vCISO. Required qualifications * 8+ years of cybersecurity, GRC, IT audit, ...
This role will own the SOC 2 domain in a fractional capacity, including evidence review, control ... manager and CISO/vCISO. Required qualifications * 8+ years of cybersecurity, GRC, IT audit, ...
$61.5K - $75K
14% of jobs
$83.1K is the 25th percentile. Wages below this are outliers.
$75K - $88.5K
19% of jobs
$88.5K - $102K
12% of jobs
The median wage is $106.6K / yr.
$102K - $115.5K
17% of jobs
$115.5K - $128.9K
12% of jobs
$131.3K is the 75th percentile. Wages above this are outliers.
$128.9K - $142.4K
14% of jobs
$142.4K - $155.9K
7% of jobs
$155.9K - $169.4K
3% of jobs
$169.4K - $182.9K
0% of jobs
$182.9K - $196.4K
1% of jobs
$196.4K - $209.9K
2% of jobs
$61.5K
$115.4K
$209.9K
A Fractional CISO is a part-time or contract Chief Information Security Officer who provides strategic cybersecurity leadership without the commitment of a full-time executive. They help organizations develop security policies, manage risks, ensure compliance, and respond to cyber threats. This role is ideal for small to mid-sized businesses that need expert security guidance but may not have the budget for a full-time CISO. Fractional CISOs bring industry best practices and tailored security strategies to protect sensitive data and systems.
To thrive as a Fractional CISO, you need deep expertise in information security strategy, risk management, and regulatory compliance, typically backed by leadership experience and a relevant degree. Familiarity with industry standards such as ISO 27001, NIST frameworks, and certifications like CISSP or CISM, along with hands-on use of security tools and governance platforms, is highly valuable. Strong communication, adaptability, and stakeholder management skills set top candidates apart. These competencies enable a Fractional CISO to quickly assess organizational needs, build effective security programs, and foster a culture of cybersecurity across diverse clients.
Fractional CISOs often navigate the unique challenge of integrating into various company cultures and addressing different levels of cybersecurity maturity across their client base. Balancing time, prioritizing critical risks, and tailoring security strategies to each organization's needs can require swift adaptation and exceptional organizational skills. Additionally, they must quickly build trust with stakeholders, align security initiatives with business goals, and ensure compliance with diverse regulatory requirements. Successfully overcoming these challenges involves continuous learning, effective communication, and the ability to deliver impactful results within limited engagement periods.
For Fractional Ciso jobs in Silver Spring, MD, the most frequently searched job titles are:
The top searched job categories for Fractional Ciso jobs in Silver Spring, MD are:
Cities near Silver Spring, MD with the most Fractional Ciso job openings:

Silver Spring, MD • Remote
Full-time
Retirement
Re-posted 11 days ago
FYI - For Your Information, Inc. is an SBA certified, Woman-Owned Small Business and GSA schedule holder that is a premier provider of Human Capital, Training, and Information Technology services. We have won awards for being a Great Place to Work and continue to make ground-breaking advancements. For four years in a row, we have been on Inc. Magazine's 5000 list and were recently named one of Inc.'s 2024 Mid-Atlantic Fastest Growing companies. About the roleFYI is seeking a PCI DSS SAQ D Service Provider Lead to support an active PCI compliance program for a SaaS/cloud/payment-adjacent environment. This role will own the PCI domain in a fractional capacity, including PCI scoping support, evidence sufficiency review, quarterly scan cadence, penetration testing evidence, remediation tracking, and responses to auditors, QSAs, processors, banks, or other requesting entities. The right candidate has done this work before and can drive their lane without constant prompting.Essential responsibilities and dutiesSupport PCI DSS SAQ D Service Provider readiness, scoping, evidence review, and control interpretation.Review PCI scope assumptions, in-scope systems, applications, integrations, service providers, and payment/data-flow considerations.Coordinate and review evidence for quarterly external ASV scans and internal vulnerability scans.Coordinate PCI-relevant penetration testing evidence, including scope, rules of engagement, final report review, remediation, and retest evidence.Review evidence for file integrity monitoring, encryption, MFA, IAM, logging, monitoring, change control, secure development, vulnerability management, and remediation tracking where relevant to PCI DSS.Identify weak, incomplete, stale, unclear, or nonresponsive evidence before submission.Draft or review PCI-related auditor, QSA, processor, or requesting-entity responses.Support tracking of PCI remediation items, exceptions, compensating-control discussions, and risk acceptance needs.Help define and maintain recurring PCI compliance cadence, including quarterly scans and annual validation activities.Provide concise written status updates, blockers, risks, and next actions to the project manager and CISO/vCISO.Required qualifications8+ years of cybersecurity, GRC, IT audit, compliance, security consulting, or related experience.Direct hands-on experience supporting PCI DSS assessments.Direct experience with PCI DSS SAQ D; Service Provider experience is strongly preferred.Experience with SaaS, cloud-hosted, fintech, payment, or payment-adjacent environments.Working knowledge of ASV scanning, internal vulnerability scanning, penetration testing evidence, vulnerability remediation, IAM/MFA, encryption, logging, monitoring, FIM, change control, and secure development requirements.Ability to translate PCI requirements into practical tasks for engineering, IT, security, and business stakeholders.Strong written communication skills and ability to produce audit-ready summaries and responses.Ability to work through ambiguity and distinguish sufficient evidence from weak or incomplete evidence.Nice to havePrior QSA, ISA, or QSA-firm experience.PCI DSS v4.x experience.CISA, CISSP, CISM, Security+, or equivalent certification.Experience with Drata, Vanta, Secureframe, Hyperproof, Jira, Confluence, AWS, Azure, GCP, or similar platforms.SOC 2 familiarity, especially where controls overlap with PCI DSS.Expected deliverablesPCI DSS SAQ D evidence and gap tracker inputs.PCI scope notes, assumptions, and issue summaries.ASV and internal vulnerability scan evidence checklists.Penetration testing evidence checklist and report sufficiency review notes.PCI remediation tracker updates and risk summaries.PCI auditor/requesting-entity response drafts.PCI quarterly and annual compliance calendar inputs.Operating style requiredThis role requires a senior operator who can own the PCI lane in a fractional capacity. The contractor must communicate clearly, document next actions, identify blockers early, and coordinate through the project manager. This is not a casual side task. Responsiveness, ownership, and clean written work product are required.FYI's Benefits/Incentives: What is in it for you?Opportunity to work a hybrid work scheduleA knowledgeable, high-achieving, diverse, experienced, and fun team.The chance to be part of a rapidly growing company and the next success story.A competitive base salary with a loaded benefits package plus 401K.Tuition/education assistance, personal computer allowance, pet insurance.
Sourced by ZipRecruiter
It services
51 - 200 Employees
Beltsville, MD, US
1987