Job Details:
Job Title: Virtual Chief Information Security Officer (vCISO) – Part time
Location: Denver, CO (Hybrid - 2 Days onsite per week for 4 Hours)
Duration: 3 Months Contract for about 80 Hours per Month
Description:
Two days a week of senior outside help while the security program gets built out, and an independent read on where we stand rather than only the internal view. The work starts with an honest assessment of our posture against a control framework, which tells us what we're missing and in what order it matters. From there, standing up the risk register, getting the core policy set reviewed, and putting a real reporting rhythm in place for the audit and the exec team. A significant piece of this is incident response. We need a written IR plan that names who does what, when we escalate, when we bring in outside counsel and forensics, and how we make a materiality call. Then a tabletop with the leadership team to find out where the plan breaks before a real incident does. Tied to that is the question of whether our controls cover everything we own. We are chronically over our vulnerability scanning license limit, which suggests we do not have a reliable asset count, and anything outside the inventory is outside our monitoring, patching, and backup coverage too. Comes out as a gap assessment, a twelve-month roadmap with rough costs, the risk register, an approved policy set, an IR plan tested in a tabletop, an asset coverage gap analysis, and the first proper Board security briefing.