×
Register Here to Apply for Jobs or Post Jobs. X

Fractional CISO – M&A Due Diligence

Job in Boston, Suffolk County, Massachusetts, 02108, USA
Listing for: Saviance
Part Time position
Listed on 2026-08-05
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection, IT Consultant
Job Description & How to Apply Below

Fractional CISO – M&A Due Diligence

Location:

Remote Type:
Contract / Hourly (Part-Time or As-Needed Basis)

Reports To:

Head of M&A / Corporate Development / CISO

Role Overview

We are seeking a seasoned Security Consultant to support cybersecurity due diligence for mergers, acquisitions, and strategic investments. This remote, hourly-paid role involves assessing the security posture of target companies, identifying critical risks, and advising on remediation and post-close integration planning. The ideal candidate is detail-oriented, technically strong, and comfortable working independently with minimal oversight.

Key Responsibilities
  • Perform security due diligence assessments for M&A targets across various industries and maturity levels.
  • Review and evaluate:
    • Security policies, procedures, and governance frameworks
    • Infrastructure and network architecture (cloud/on-prem/hybrid)
    • Application and cloud security posture (AWS, Azure, GCP)
    • Identity and access management (IAM) practices
    • Data protection and encryption strategies
    • Vulnerability management and incident response capabilities
    • Compliance with standards such as ISO 27001, SOC 2, GDPR, HIPAA, PCI-DSS, etc.
  • Analyze provided documentation: network diagrams, risk assessments, audit reports, penetration test results, and security controls inventories.
  • Conduct interviews with key personnel (security, IT, Dev Ops, GRC, etc.) to validate practices and identify risks.
  • Provide concise written deliverables, including:
    • Detailed security diligence reports
    • Risk register with severity ratings and business impact
    • 30/60/90/180-day remediation plans
  • Collaborate with legal, technical, and integration teams to support informed decision-making.
  • Work flexibly based on diligence timelines and deal schedules.
Required Qualifications

15+ years of experience in cybersecurity or information security, with 2+ years in security due diligence or third-party risk assessments. Strong working knowledge of security frameworks: NIST CSF, ISO 27001, CIS Controls, SOC 2. Familiarity with securing cloud-native and SaaS environments. Ability to assess security risk holistically across technical, organizational, and compliance domains. Excellent written communication skills; able to summarize complex findings in an executive-friendly format.

Self-starter comfortable with ambiguity and fast-paced deal environments.

Preferred Qualifications

Experience in a consulting, private equity, venture capital, or corporate M&A environment. Certifications such as CISSP, CISA, CISM, CCSP, or OSCP. Prior work with high-growth startups or tech/SaaS companies. Experience using security assessment tools (e.g., Nessus, Qualys, Burp, Wiz, etc.) is a plus.

To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary