CISO
Listed on 2026-04-20
-
IT/Tech
Cybersecurity, Information Security
Inversion6 is seeking an experienced and credentialed Fractional Chief Information Security Officer to join our growing advisory practice. This is a senior leadership role, not a staff augmentation position. The Fractional CISO embeds directly with client organizations on 12-month engagements, serving as a trusted security executive who owns outcomes and drives measurable program maturity.
The right candidate has been a CISO. Not a near-CISO, not a security director who reported to one — a practicing CISO who has owned the program, managed the team and budget, briefed the board, led the response, and built something that worked. That experience is the foundation from which great advisory work is delivered. Our clients deserve that depth, and they can feel the difference.
The Fractional CISO is responsible for the full spectrum of strategic security leadership: designing and implementing security programs aligned to business goals and recognized frameworks, managing governance, risk, and compliance functions, conducting risk assessments, leading incident response planning, briefing executive leadership and boards, and advancing the client's security posture through both planning and hands‑on execution. This role demands someone who can operate at the board level and in the weeds with engineers — often in the same week.
Success is measured by client outcomes. Inversion6 Fractional CISOs maintain a 95% client renewal rate. That standard is earned through long‑term relationship building, consistent delivery, and the kind of embedded advisory presence that clients renew not because they have to, but because they want to.
Most fractional CISO engagements are transactional. A consultant appears, documents what's wrong, and disappears. That is not what we do. Inversion6 Fractional CISOs embed with clients on structured 12-month engagements, building real relationships and delivering real work — not reports that collect dust.
The right candidate owns outcomes, not just recommendations. This means running GRC and risk review meetings, conducting risk assessments, writing policies and procedures, leading tabletop exercises, managing Microsoft 365 and Azure security configurations, supporting M&A security diligence, scoping SaaS application security assessments, and developing incident response and disaster recovery plans. The work that needs doing is the work this candidate does.
They do not point at problems and wait for someone else to fix them.
We are looking for proven CISOs who want to be part of a team, embed with clients long‑term, and help those clients build sustainable, compliant security programs that actually work.
Inversion6 evaluates its advisory team against three core attributes. These are non‑negotiable.
Humble. Collaborative by nature, low ego by choice. Works well with internal teams, client stakeholders, and fellow advisors. Leads through influence, not authority. Understands that being the smartest person in the room is far less valuable than making the room smarter.
Hungry. Actively supports sales, proactively identifies opportunities within client engagements, and understands that growing the practice is part of the job. Seeks out problems worth solving, not just problems worth reporting.
Smart. Strong emotional intelligence, deep technical fluency, and the ability to translate complex security risk into executive‑level clarity. Delivers results, not just recommendations.
Strategic Security Leadership
- Design and implement comprehensive, business‑aligned cybersecurity strategies tailored to each client's industry, risk profile, and regulatory obligations.
- Serve as the primary security executive for client organizations, attending leadership meetings, steering committees, and board sessions as required.
- Translate technical security risks into business impact language that resonates with executives, boards, and non‑technical stakeholders.
- Develop 12‑month security program roadmaps with measurable milestones, maturity targets, and clear ownership.
- Build and sustain security cultures through workforce awareness programs and executive education.
Governance, Risk, and Compliance (GRC)
- Lead ongoing GRC…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).