layiq
worthy; deserving; fitting; suitable.
A role, opportunity, or path that merits attention, time, and pursuit.
Loading LAYIQ…Job opportunity
Strategic Growth Partners
United States
Source: Strategic Growth Partners careers · View original posting
From Strategic Growth Partners's posting. “We” and “our” refer to the employer.
Strategic Growth Partners is committed to upholding our company values and ensuring data confidentiality. We provide robust services to our clients across multiple time zones and foster a collaborative, innovative, and diverse work environment.
Strategic Growth Partners (SGP) is seeking an experienced Fractional CISO who can serve as Strategic Growth Partners' senior information security and compliance leader, acting as an outsourced CISO for client organizations while also owning SGP's internal security and compliance program. This full-time, exempt, remote position reports to the Chief Information Officer and works closely with client executives, internal IT teams, compliance partners, and business development.
The role provides strategic cybersecurity leadership, hands-on compliance advisory, and scalable client delivery across SGP's growing cybersecurity and GRC practice.
Remote.
Compensation
W-2. $150K–$180K per year.
Essential Duties and Responsibilities
Serve as acting CISO for multiple client organizations, including SGP, providing strategic security leadership and executive guidance.
Lead cybersecurity and compliance programs aligned with NIST SP 800-171 and 800-53, CMMC Levels 1 and 2, and ISO/IEC 27001.
Conduct security assessments, gap analyses, and risk reviews; develop System Security Plans (SSPs), Plans of Action and Milestones (POA&Ms), policies, and audit evidence.
Guide clients through certification, audit, and assessment-readiness activities, coordinating with C3PAO and RPO partners as needed.
Own and maintain SGP's internal compliance posture, applying the same standards delivered to clients.
Oversee incident response planning, vulnerability management, and security operations in partnership with IT teams.
Deliver executive reporting, security roadmaps, metrics, and board-ready presentations.
Coordinate security awareness training and tabletop exercises for SGP staff and clients.
Review technology and business initiatives, including ERP and business intelligence projects, for security and compliance impact.
Recruit and manage a bench of subcontracted vCISOs as the practice scales, ensuring consistent delivery quality.
Partner with business development on proposals, scoping, and client engagement growth.
Build reusable templates and methodologies to scale SGP's cybersecurity and GRC practice.
Maintain and coordinate Cyber Security compliance calendar activities including security self-assessments and security related internal audit activities.
Actively monitors threat information from key sources and partners (CISA, FBI, SOC/NOC) and escalates and educates as appropriate to the internal teams and executive leadership.
Monitor ongoing and proposed changes to major Compliance and Control frameworks.
Perform other duties as assigned.
Required Qualifications
Bachelor's degree in cybersecurity, information technology, risk management, or a related field, or an equivalent combination of education and relevant experience.
At least 8 years of information security experience, including senior leadership experience as a Security Director, Vice President, CISO, or vCISO.
Hands-on expertise with NIST SP 800-171 and 800-53, CMMC Levels 1 and 2, ISO/IEC 27001, risk assessments, SSPs, POA&Ms, and compliance documentation.
Proven ability to lead multiple client engagements simultaneously, communicate effectively with executives, produce strong technical documentation, conduct assessments, and translate security requirements into practical business actions.
No certification is required; relevant industry certifications are strongly preferred.
LAYIQ is an independent job-discovery service. This listing does not imply a partnership with or endorsement by the employer. Review the original posting for current details and availability.
Employer posted: