Fractional Virtual CISO; vCISO
Job Description & How to Apply Below
About the engagement
This is not a portfolio vCISO role. You will dedicate your hours to a single client — a regional CPA firm of about 350 people — and own their information security program end-to-end. The client's internal IT team handles operations;
Forge Path owns security, and you are the senior face of that program.
The client values continuity and a close advisory relationship with their CISO. We are looking for someone who wants to go deep with one organization rather than rotate across many.
Responsibilities- Own the client's information security strategy, roadmap, governance, and executive reporting
- Maintain and mature the firm's GLBA / FTC Safeguards Rule and HIPAA compliance posture
- Serve as the executive-level security voice to the CIO, CTIO, managing partners, and audit/risk committee
- Lead policy development, risk assessment, third‑party risk, and incident response governance
- Provide principal‑level technical advisory on architecture, tooling, and cloud security decisions — security and adjacent technology
- Partner with Forge Path delivery teams on tactical execution (pentest scoping, VM strategy, security tooling rollouts)
- Brief the client's leadership quarterly and on‑demand for major events
- 7+ years in information security leadership, including 3+ in a CISO, vCISO, or Director of Security capacity
- Direct experience supporting CPA firms or comparable professional services environments
- Working command of GLBA / FTC Safeguards Rule and HIPAA — applied, not just templated
- Strong technical foundation: you can engage substantively on cloud (Microsoft/Azure preferred), endpoint security, network security, and identity
- Executive presence — you can sit across from a managing partner and earn their trust quickly
- Willing and able to act as a principal technology advisor on decisions that extend beyond strict security scope
- Active CISSP, CISM, or CCISO
- Prior in‑house experience inside a public accounting firm's IT or risk organization
- Familiarity with SOC 2 and PCI in adjacent contexts
- $125–$150/hour, 1099 contractor
- Approximately 20 hours per month, with rare months extending toward 40
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×