To support this trajectory, the Security and Privacy Manager will partner closely with a fractional CISO who will provide hands-on mentorship, strategic guidance and development support, enabling the ...
To support this trajectory, the Security and Privacy Manager will partner closely with a fractional CISO who will provide hands-on mentorship, strategic guidance and development support, enabling the ...
Principal Consultant, Cyber Security
Mahwah, NJ · On-site
$185 - $215/hr
Multi‑year vCISO, fractional CISO, or executive‑sponsor program advisory (board reporting, roadmap ownership) for regulated clients. * Hands‑on familiarity with CrowdStrike, Microsoft Defender ...
Principal Consultant, Cyber Security
Mahwah, NJ · On-site
$185 - $215/hr
Multi‑year vCISO, fractional CISO, or executive‑sponsor program advisory (board reporting, roadmap ownership) for regulated clients. * Hands‑on familiarity with CrowdStrike, Microsoft Defender ...
Multi-year vCISO, fractional CISO, or executive-sponsor program advisory (board reporting, roadmap ownership) for regulated clients. * Hands-on familiarity with CrowdStrike, Microsoft Defender ...
Multi-year vCISO, fractional CISO, or executive-sponsor program advisory (board reporting, roadmap ownership) for regulated clients. * Hands-on familiarity with CrowdStrike, Microsoft Defender ...
This role will own the PCI domain in a fractional capacity, including PCI scoping support, evidence ... and CISO/vCISO.Required qualifications8+ years of cybersecurity, GRC, IT audit, compliance ...
Quick apply
This role will own the PCI domain in a fractional capacity, including PCI scoping support, evidence ... and CISO/vCISO.Required qualifications8+ years of cybersecurity, GRC, IT audit, compliance ...
This role will own the PCI domain in a fractional capacity, including PCI scoping support, evidence ... CISO/vCISO. Required qualifications * 8+ years of cybersecurity, GRC, IT audit, compliance ...
This role will own the PCI domain in a fractional capacity, including PCI scoping support, evidence ... CISO/vCISO. Required qualifications * 8+ years of cybersecurity, GRC, IT audit, compliance ...
This role will own the SOC 2 domain in a fractional capacity, including evidence review, control ... CISO/vCISO.Required qualifications8+ years of cybersecurity, GRC, IT audit, compliance, SaaS ...
Quick apply
This role will own the SOC 2 domain in a fractional capacity, including evidence review, control ... CISO/vCISO.Required qualifications8+ years of cybersecurity, GRC, IT audit, compliance, SaaS ...
This role will own the SOC 2 domain in a fractional capacity, including evidence review, control ... manager and CISO/vCISO. Required qualifications * 8+ years of cybersecurity, GRC, IT audit, ...
This role will own the SOC 2 domain in a fractional capacity, including evidence review, control ... manager and CISO/vCISO. Required qualifications * 8+ years of cybersecurity, GRC, IT audit, ...
... fractional share ownership. DriveWealth has evolved into a global platform offering trading of US ... About the Role Reporting directly to the CISO, the Head of Security GRC is responsible for leading ...
... fractional share ownership. DriveWealth has evolved into a global platform offering trading of US ... About the Role Reporting directly to the CISO, the Head of Security GRC is responsible for leading ...
Virtual Chief Information Security Officer (vCISO)
Phoenix, AZ · On-site
$120 - $160/hr
About the Role As a vCISO at cloudIT, you will serve as a fractional security leader for a portfolio of clients who do not have and cannot afford a full‑time CISO. You will work from our Phoenix ...
Virtual Chief Information Security Officer (vCISO)
Phoenix, AZ · On-site
$120 - $160/hr
About the Role As a vCISO at cloudIT, you will serve as a fractional security leader for a portfolio of clients who do not have and cannot afford a full‑time CISO. You will work from our Phoenix ...
About the Role As a vCISO at cloudIT, you will serve as a fractional security leader for a portfolio of clients who do not have and cannot afford a full-time CISO. You will work from our Phoenix ...
Quick apply
About the Role As a vCISO at cloudIT, you will serve as a fractional security leader for a portfolio of clients who do not have and cannot afford a full-time CISO. You will work from our Phoenix ...
Virtual Chief Information Security Officer (vCISO)
Phoenix, AZ · On-site
$120 - $160/hr
About the Role As a vCISO at cloudIT, you will serve as a fractional security leader for a portfolio of clients who do not have and cannot afford a full-time CISO. You will work from our Phoenix ...
Virtual Chief Information Security Officer (vCISO)
Phoenix, AZ · On-site
$120 - $160/hr
About the Role As a vCISO at cloudIT, you will serve as a fractional security leader for a portfolio of clients who do not have and cannot afford a full-time CISO. You will work from our Phoenix ...
Chief Information Security Officer
Manhattan, NY · On-site
$300 - $375/hr
... fractional share ownership. DriveWealth has evolved into a global platform offering trading of U.S ... The CISO will also represent security to senior leadership and the board, ensuring the organization ...
Chief Information Security Officer
Manhattan, NY · On-site
$300 - $375/hr
... fractional share ownership. DriveWealth has evolved into a global platform offering trading of U.S ... The CISO will also represent security to senior leadership and the board, ensuring the organization ...
Chief Information Security Officer
New York, NY · On-site
$300K - $375K/yr
... fractional share ownership. DriveWealth has evolved into a global platform offering trading of US ... The CISO will also represent security to senior leadership and the board, ensuring the organization ...
Chief Information Security Officer
New York, NY · On-site
$300K - $375K/yr
... fractional share ownership. DriveWealth has evolved into a global platform offering trading of US ... The CISO will also represent security to senior leadership and the board, ensuring the organization ...
Fractional Ciso information
See salary details
$59.5K - $72.5K
14% of jobs
$80.3K is the 25th percentile. Wages below this are outliers.
$72.5K - $85.6K
19% of jobs
$85.6K - $98.6K
12% of jobs
The median wage is $103.1K / yr.
$98.6K - $111.7K
17% of jobs
$111.7K - $124.7K
12% of jobs
$127K is the 75th percentile. Wages above this are outliers.
$124.7K - $137.8K
14% of jobs
$137.8K - $150.8K
7% of jobs
$150.8K - $163.9K
3% of jobs
$163.9K - $176.9K
0% of jobs
$176.9K - $190K
1% of jobs
$190K - $203K
2% of jobs
$59.5K
$111.6K
$203K
How much do fractional ciso jobs pay per year?
What challenges do Fractional CISOs face when working with multiple organizations?
Fractional CISOs often navigate the unique challenge of integrating into various company cultures and addressing different levels of cybersecurity maturity across their client base. Balancing time, prioritizing critical risks, and tailoring security strategies to each organization's needs can require swift adaptation and exceptional organizational skills. Additionally, they must quickly build trust with stakeholders, align security initiatives with business goals, and ensure compliance with diverse regulatory requirements. Successfully overcoming these challenges involves continuous learning, effective communication, and the ability to deliver impactful results within limited engagement periods.
What skills and qualifications are needed to thrive as a Fractional CISO?
To thrive as a Fractional CISO, you need deep expertise in information security strategy, risk management, and regulatory compliance, typically backed by leadership experience and a relevant degree. Familiarity with industry standards such as ISO 27001, NIST frameworks, and certifications like CISSP or CISM, along with hands-on use of security tools and governance platforms, is highly valuable. Strong communication, adaptability, and stakeholder management skills set top candidates apart. These competencies enable a Fractional CISO to quickly assess organizational needs, build effective security programs, and foster a culture of cybersecurity across diverse clients.
What is a Fractional CISO?
A Fractional CISO is a part-time or contract Chief Information Security Officer who provides strategic cybersecurity leadership without the commitment of a full-time executive. They help organizations develop security policies, manage risks, ensure compliance, and respond to cyber threats. This role is ideal for small to mid-sized businesses that need expert security guidance but may not have the budget for a full-time CISO. Fractional CISOs bring industry best practices and tailored security strategies to protect sensitive data and systems.

Full-time
Medical, Dental, Vision, Life, Retirement
Re-posted 16 days ago
Job description
EHE Health is the leading national preventive healthcare provider network partnering with mid- and
large-sized employers to help their employees and dependents stay healthy by screening and diagnosing health risks through comprehensive exams, allowing for early intervention. Named by Fortune Magazine and Great Place to Work® as one of the Best Workplaces in healthcare, EHE Health is headquartered in
New York City and has over 200 health clinics and practices across the U.S., staffed by a network of
curated primary care physicians and clinicians.
EHE Health was acquired by Consello Capital, the private equity arm of Consello. This transformative partnership leverages Consello's proven expertise in scaling high-growth ventures and its extensive network of industry leaders. Together, EHE Health and Consello will unlock unprecedented
opportunities to accelerate EHE Health's mission of revolutionizing preventive care.
What we're looking for:
EHE Health is seeking a talented Security and Privacy Manager to lead and evolve our enterprise cybersecurity and privacy program, reducing risk exposure and strengthening our control environment. This role will be responsible for advancing our compliance and certification efforts, while conducting internal audits, risk assessments and ongoing security analyses to ensure our processes and controls remain effective, scalable and aligned with industry best practices.
The ideal candidate is intellectually curious, detail-oriented and proactive with a collaborative mindset and a bias toward continuous improvement rather than maintaining the status quo. This individual will bring both the capability and ambition to grow within the organization. To support this trajectory, the Security and Privacy Manager will partner closely with a fractional CISO who will provide hands-on mentorship, strategic guidance and development support, enabling the individual to build the experience and leadership capabilities required for long-term success.
In this role, you will:
- Conduct comprehensive security and privacy audits across networks, systems, applications, platforms, databases, and operational processes in alignment with established audit standards
- Support and perform enterprise risk assessments to evaluate the design and effectiveness of controls across EHE's technology and business environments
- Manage the third-party risk management program, including due diligence, ongoing monitoring, and enforcement of EHE security and privacy requirements
- Partner with IT and business stakeholders to communicate control requirements, strengthen adoption, and reinforce a robust control environment
- Drive enterprise-wide awareness of cybersecurity and privacy policies through targeted education and engagement initiatives
- Monitor and analyze security event data across computing platforms, networks, and security tools to identify risks, trends, and potential threats
- Develop and deliver regular security metrics, dashboards, and operational reports to inform decision-making and leadership visibility
- Conduct ongoing threat research, including emerging technologies such as artificial intelligence and evolving threat actors, to proactively assess business impact
- Design and implement scalable, measurable, and repeatable security and privacy strategies aligned with organizational objectives
- Lead and manage responses to prospective and existing client security and privacy inquiries, including questionnaires, due diligence requests, and audits
What the role requires:
- Bachelor's degree in Information Security, Computer Science, or a related field
- 3-5 years' experience in information security, cybersecurity, or privacy program operations
- Hands-on experience supporting or operating security and/or privacy programs within ISO27001, ISO27701, SOC2 Type 2 frameworks
- Working knowledge of HIPAA and the HITECH Act, healthcare or regulated industry experience preferred
- Relevant industry certifications (e.g., CISSP, CCSP, CISM) preferred
- Practical experience participating in cybersecurity incident response, either as a respondent or incident manager
- Familiarity with the NIST Cybersecurity Framework (CSF), including its core functions: Govern, Identify, Protect, Detect, Respond and Recover
- Strong written and verbal communication skills, with the ability to clearly convey complex security concepts to both technical and non-technical stakeholders
- Demonstrable experience implementing or auditing identity and access management for on-premise and cloud-based services
- Ability to identify and assess emerging technology risks (e.g. software supply chain and AI)
What we offer:
- Competitive salary
- Medical, dental, vision, life and disability insurance
- Employer-matched 401(k) plan
- Professional development reimbursement
- Employee access to our wellness clinics
- Gym reimbursement/fitness bonus
The salary range for this role is $100,000 - $140,000 and is determined by a number of factors including the candidate's experience, qualifications and skills.
EHE is committed to Equal Employment Opportunity and to attracting and retaining the most qualified employees.
About EHE Health
Sourced by ZipRecruiter
Industry
Fitness and sports centers
Company size
51 - 200 Employees
Headquarters location
New York, NY, US
Year founded
1913