Virtual Chief Information Security Officer (vCISO)
On-siteHouston, Texas, United States
Job Summary
Own the customer security program at a strategic level, including security roadmaps, governance cadence, executive reporting, risk prioritization, audit readiness, vendor oversight, and incident response leadership. Brief executive leadership and boards on security posture, material risks, and recommended investment decisions. Lead compliance and audit readiness for frameworks such as HIPAA, SOC 2, NIST CSF, and PCI DSS while coordinating with auditors and legal teams. Oversee security operations, including monitoring, endpoint protection, and identity controls, and direct incident response planning, tabletop exercises, and post-incident reviews. Represent Meriplex in executive meetings and advisory sessions to translate technical security needs into clear business outcomes for assigned customers.
Required Qualifications
- Minimum of 5 years of progressive experience across cybersecurity leadership, risk management, governance, compliance, security operations, or IT advisory roles
- Demonstrated ability to operate as a fractional executive advisor, influence senior leaders, brief boards, and guide cybersecurity decisions in business terms
- Strong working knowledge of security and compliance frameworks including HIPAA, NIST CSF, SOC 2, and PCI DSS
- Experience leading security assessments, audit readiness, incident response planning, tabletop exercises, security roadmaps, and risk remediation programs
- Ability to support customer-facing advisory work, executive presentations, security questionnaires, RFP responses, and pre-sales technical discussions
- Excellent communication, prioritization, consulting, and relationship management skills with the ability to manage multiple customers, competing deadlines, and executive expectations
- Bachelor's degree from an accredited university/college
- Proven experience in client relationship management, executive advisory, governance, audit support, and customer-facing cybersecurity services within an MSP, MSSP, consulting, or managed services environment
Desired Qualifications
- Cybersecurity credentials such as CISSP, CISM, CISA, CRISC, or equivalent
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.