1

Virtual Ciso Jobs (NOW HIRING)

Cyber Security Strategy Lead

Charlotte, NC · On-site

$108.40K - $146.50K/yr

Supporting or operating as a virtual CISO for mid-market clients, providing consistent leadership and oversight of their cybersecurity programs. * Mentoring and influencing others both internally and ...

... with Virtual CISO services. • Support export-controlled and classified environments by implementing appropriate controls and safeguards. • Identify, assess, and mitigate IT risks across ...

Cyber Security Strategy Lead

Charlotte, NC

$108.40K - $146.50K/yr

Supporting or operating as a virtual CISO for mid-market clients, providing consistent leadership and oversight of their cybersecurity programs. * Mentoring and influencing others both internally and ...

... with Virtual CISO services. • Support export-controlled and classified environments by implementing appropriate controls and safeguards. • Identify, assess, and mitigate IT risks across ...

Our virtual workspace platform enables users to access enterprise apps and data from any mobile ... CISO / Deputy CISO / CSO * VP / Head of Security Engineering & Architecture * VP / Head of Endpoint ...

The 1st Line CISO has operational responsibilities and reports to the CIO. The 2nd Line Chief Tech ... At least 3 years of experience implementing next-generation endpoint platforms such as virtual ...

The 1st Line CISO has operational responsibilities and reports to the CIO. The 2nd Line Chief Tech ... At least 3 years of experience implementing next-generation endpoint platforms such as virtual ...

next page

Showing results 1-20

Virtual Ciso information

See salary details

$11

$24

$33

How much do virtual ciso jobs pay per hour?

As of May 30, 2026, the average hourly pay for virtual ciso in the United States is $24.40, according to ZipRecruiter salary data. Most workers in this role earn between $20.43 and $27.40 per hour, depending on experience, location, and employer.

What Does a Virtual CISO Do?

A virtual chief information security officer (vCISO) is a position that allows you to work from home while handling the responsibilities of data organization and protection. In this role, you manage a company’s cybersecurity and ensure compliance with industry regulations. Your duties include reviewing the strategy and business design of an organization, performing threat analysis, providing risk assessment and management, and testing company systems. You may also forecast future security challenges, collaborate with engineering teams, identify and treat any breaches or incidents within the system, and provide service for end-users. You may work in a staff role for a company or contract with clients in a freelance position.

What are the key skills and qualifications needed to thrive as a Virtual CISO, and why are they important?

To thrive as a Virtual CISO, you need deep expertise in information security frameworks, risk management, and regulatory compliance, typically backed by a degree in cybersecurity or IT and certifications like CISSP or CISM. Familiarity with security assessment tools, SIEM systems, and governance platforms is essential. Outstanding communication, leadership, and strategic thinking set top performers apart in this remote advisory role. These skills and qualities are vital to effectively protect organizations, align security initiatives with business goals, and build trust with stakeholders.

How does a Virtual CISO typically collaborate with internal IT teams and executive leadership?

A Virtual CISO (vCISO) works closely with internal IT staff to assess current security protocols, identify gaps, and implement best practices. They also serve as a bridge between technical teams and executive leadership by translating complex security risks into clear business terms and providing strategic recommendations. Regular meetings, clear reporting structures, and tailored security training sessions are common ways vCISOs ensure that both technical and non-technical stakeholders are aligned on cybersecurity priorities. This collaborative approach helps organizations integrate security into business decisions and maintain regulatory compliance.

What is a Virtual CISO?

A Virtual Chief Information Security Officer (Virtual CISO or vCISO) is an experienced cybersecurity professional who provides leadership and strategic guidance on information security, but works for an organization on a part-time, contract, or as-needed basis. This allows companies to benefit from high-level security expertise without the cost of hiring a full-time executive. vCISOs help businesses assess risks, develop security policies, ensure regulatory compliance, and respond to cybersecurity incidents. They are particularly valuable for small to mid-sized organizations that may not have the resources for a dedicated CISO.

What is the difference between Virtual Ciso vs Security Analyst?

AspectVirtual CisoSecurity Analyst
CertificationsCISSP, CISM, CISACompTIA Security+, CISSP (preferred), GIAC
Work EnvironmentStrategic, executive-level, remote or onsiteOperational, technical, primarily onsite or remote
Employer & Industry UsageOrganizations seeking cybersecurity leadershipOrganizations monitoring security threats and incidents

The Virtual Ciso focuses on strategic cybersecurity leadership, policy development, and risk management at an executive level. In contrast, a Security Analyst handles technical security monitoring, threat detection, and incident response. While both roles require cybersecurity certifications, the Virtual Ciso operates at a higher strategic level, often working remotely for multiple clients or organizations, whereas Security Analysts are more hands-on with daily security operations.

What cities are hiring for Virtual Ciso jobs? Cities with the most Virtual Ciso job openings:
What are the most commonly searched types of Ciso jobs? The most popular types of Ciso jobs are:
Who are the top companies hiring for Virtual Ciso jobs? The top employers for Virtual Ciso jobs are:
What states have the most Virtual Ciso jobs? States with the most job openings for Virtual Ciso jobs include:
Infographic showing various Virtual Ciso job openings in the United States as of May 2026, with employment types broken down into 1% As Needed, 85% Full Time, 11% Part Time, and 3% Contract. Highlights an 53% Physical, and 47% Remote job distribution, with an average salary of $50,749 per year, or $24.4 per hour.

Virtual Chief Information Security Officer (vCISO)

iCorps

Woburn, MA • Hybrid

Full-time

Posted 29 days ago


Job description

Virtual Chief Information Security Officer (vCISO)

Woburn/Hybrid

About iCorps and the Role

iCorps Technologies has delivered IT consulting and managed services to mid-market clients since 1994. We specialize in cloud computing, cybersecurity, IT governance, and outsourced IT support. We are a Microsoft Solutions Partner and Cloud Service Provider, and a Microsoft US Partner Award Winner for Security and Compliance.

The virtual Chief Information Security Officer is a client-facing role. You are the security leader iCorps puts in front of its clients, bringing the experience and operational discipline of a seasoned CISO to organizations that cannot retain one full time. We expect security to be treated as an operational discipline, with clear priorities, measurable outcomes, realistic sequencing, and honest conversations when something is not working.

Scope of the Role

The work spans three connected responsibilities, and a successful vCISO moves between them across a single engagement and across a portfolio.

1. Active Security Advisor. Provide hands-on advisory guidance on day-to-day security decisions: architecture choices, control implementation, vendor selection, configuration questions, incident calls, and the steady stream of judgment calls a maturing program generates. This pillar covers identity-first security and zero trust adoption, cloud posture across Microsoft 365, Azure, AWS, and Google Cloud, endpoint and detection strategy, MDR and XDR partnerships, ransomware resilience and tested recovery, third-party and supply chain risk, and the secure adoption of generative AI.

2. vCISO Alignment of Business, Governance, and Technical Control. Set and run the security program so the client is aligned to the frameworks that apply: NIST CSF 2.0, ISO 27001:2022, CMMC 2.0 (meaningful given our DoD-adjacent client base), SOC 2, HIPAA, PCI DSS 4.0, US state privacy laws led by CCPA, SEC cyber disclosure where applicable, and cyber insurance attestations. Translate executive intent into governance structure, governance into policy, policy into control, and control state into board-ready reporting. Stand up and run a recurring security committee at each client. Own AI governance specifically: the policies, review processes, and committee structure that let a client adopt AI tooling without losing control of their data.

3. Gap Analysis and Assessment. Run baseline assessments at engagement kickoff, periodic reassessments on an agreed cadence, and targeted assessments tied to events such as acquisitions, regulatory change, new product lines, or CMMC certification cycles. Produce remediation roadmaps with sequencing, ownership, and effort the client can fund and execute. Run post-incident assessments to verify whether controls performed the way the program described.

What You Will Do
  • Own the security program for each assigned client, with a written strategy, roadmap, and reporting cadence with the executive sponsor and, where applicable, the board or audit committee.
  • Lead identity-first security: conditional access, PIM and PAM, least privilege, identity threat detection, and joiner-mover-leaver discipline.
  • Drive cloud posture across Microsoft 365, Azure, AWS, and Google Cloud, including CSPM and SSPM findings, hybrid work controls, and SaaS-to-SaaS risk.
  • Set the direction for detection and response, treating incident readiness (tabletops, runbooks, escalation paths, retainer relationships) with the same weight as incident response itself.
  • Guide ransomware resilience: immutable backups, tested recovery objectives, recovery drills, and tabletop cadence at the executive level.
  • Own third-party and supply chain risk, including vendor due diligence, SBOM awareness, and fourth-party exposure.
  • Lead AI governance and the secure adoption of AI tooling across policy, technical configuration, and ongoing monitoring for shadow AI.
  • Guide incident response when an event occurs, coordinating with legal, forensics, insurance, and law enforcement, and lead the post-incident review so lessons land in policy and controls.
  • Partner with iCorps delivery teams so recommendations are implementable in the environments we manage.
What You Bring
  • At least ten years in information security, with meaningful time in a leadership role. Prior CISO or deputy CISO experience is strongly preferred.
  • Demonstrated experience running gap analyses against more than one major framework and translating findings into roadmaps clients funded and executed.
  • Direct experience aligning a business to NIST CSF, ISO 27001, SOC 2, HIPAA, or CMMC, with enough range to pick up the others. CMMC 2.0 working knowledge is a meaningful advantage.
  • A point of view on AI governance and the secure adoption of generative AI in a business setting.
  • Fluency with modern identity, endpoint, cloud, and detection tooling, with enough depth to tell a good implementation from a bad one.
  • Judgment on where to invest, where to defer, and where to accept risk, and the communication skills to explain that judgment to a CFO, general counsel, or board member.
  • A bachelor’s degree in computer science, information systems, cybersecurity, or a related field, or equivalent experience.
Certifications

Required at hire or within a reasonable onboarding window: CISSP or CISM.

Preferred: CCSP for cloud-heavy engagements, CRISC for governance and risk, CISA for audit, CMMC CCP or CCA for clients pursuing CMMC certification, and relevant GIAC certifications (GSLC, GCIH, GPCS) where they match the engagement focus.

Certifications are useful shorthand for baseline knowledge, not a substitute for the operational judgment the role demands.

How the Role Runs

Client-facing advisory work delivered as a service. You manage a portfolio of clients with different risk profiles, maturity levels, and budgets. Cadence per client typically runs monthly operating reviews, quarterly executive reviews, and annual strategy refreshes, with formal gap analyses at kickoff and at least annually thereafter. Travel is occasional. Most work is remote, with onsite presence when it materially improves the engagement. The vCISO is part of iCorps’ managed security practice, with peer review on major client deliverables and a consistent point of view across the practice.

If you want to do real security work with clients who need it, in an environment that takes the craft seriously, we would like to hear from you.