About us: At Echelon Risk + Cyber, we believe in defending basic human rights to security and privacy. We seek a highly skilled and experienced Cybersecurity Leader with extensive experience serving as Director, vCISO Services to join our dynamic team at Echelon Risk + Cyber, a leading cybersecurity consulting firm. This role blends hands-on client delivery with people leadership: you'll carry your own book of advisory engagements while managing, coaching, and developing a team of vCISO Managers.
Our next team member will be ready to roll up their sleeves and identify opportunities for our clients and for Echelon internally with unquestioned integrity. This team member will be passionate about cybersecurity and ready to use their knowledge to be an Entrepreneurial Problem Solver and work alongside their Echelon team members to build creative solutions.
At Echelon, you will have the opportunity to engage with clients, business partners and systems that are at the cutting edge of technology. We allow our employees to build from the ground up and make an impact across the organization. We look for driven and proactive people that are eager to contribute to a distinct and thriving Cybersecurity services organization, that can adapt to a rapid and changing environment
This is a remote position from anywhere in the USA.
What You Will Do:
People Leadership (Managing vCISO Managers):
- Directly manage a team of vCISO Managers - own their performance management, career development, and day-to-day support.
- Set and monitor utilization, quality, and engagement-health targets across your team's book of business; step in on at-risk accounts.
- Review and approve deliverables (assessments, roadmaps, board decks, policy sets) produced by your managers before they reach clients.
- Serve as the escalation point for complex client situations, scope conflicts, or technical/strategic questions your managers surface.
- Run regular 1:1s, team meetings, and case reviews; build a culture of peer learning and shared frameworks across the team.
- Lead hiring, onboarding, and ramp planning for new vCISO Managers as the team grows.
- Identify skill gaps across the team and build/deliver internal training, playbooks, and templates to close them.
- Own staffing and capacity planning: matching manager bandwidth and expertise to client demand in partnership with delivery leadership.
Client Delivery & Strategic Advisory:
- Carry your own portfolio of vCISO / Managed Security Services engagements, providing expert cybersecurity consulting at the C-suite and board level.
- Advise clients on the development and execution of comprehensive security strategies and roadmaps aligned to business objectives.
- Attend and contribute to senior-level client meetings, including security steering committees and board meetings.
- Facilitate executive workshops and training sessions to promote security awareness.
- Plan, scope, and execute vCISO advisory engagements, including client discovery, assessments, and reporting.
- Develop and maintain cybersecurity policies, procedures, and control frameworks for client organizations.
- Create client-facing presentations, reports, and analytics; communicate results to executive stakeholders.
Governance, Risk & Compliance (GRC):
- Manage risk assessment and mitigation processes for client engagements; align cybersecurity initiatives with client risk management strategies.
- Review and assess security controls against best-practice and regulatory frameworks (e.g., CIS, NIST, ISO, PCI, CMMC, SOC, HIPAA).
- Coordinate audits, compliance assessments, and regulatory reporting (e.g., SEC, NYDFS, CMMC, PCI, HIPAA, FedRAMP, GDPR, SOX) across your team's accounts.
- Ensure consistency and quality of GRC deliverables across your managers' engagements.
Technical Security Oversight:
- Advise on and oversee implementation of security technologies (SIEM, IDS/IPS, endpoint protection, data protection, cloud security tools) across client accounts.
- Provide senior oversight on vulnerability scanning, penetration testing, and security audit engagements led by your team.
- Coordinate incident response planning and threat management initiatives; act as senior escalation during active incidents.
- Provide advisory support on integrating and optimizing security tools and technologies.
- Practice & Business Development
- Partner with sales and practice leadership on scoping, proposals, and pricing for new and expanding vCISO engagements.
- Support account growth: identify opportunities to expand scope within existing clients managed by your team.
- Produce thought leadership content (blogs, webinars, articles) and represent Echelon at industry conferences and events.
- Contribute to the ongoing evolution of Echelon's vCISO methodology, templates, and service offerings.
Your Knowledge, Skills, and Abilities
- 20+ years in professional cybersecurity and technical roles, including senior-level leadership and advisory experience.
- 5+ years as a vCISO, CISO, or senior cybersecurity/technical consultant, preferably in a Managed Services environment.
- 3+ years of direct people management experience - managing consultants, managers, or advisory staff, including performance reviews, coaching, and career development.
- Demonstrated ability to balance a personal billable book of business (60%+ utilization) with team leadership responsibilities.
- Proven ability to manage multiple, simultaneous client engagements across a team and deliver quality results under tight deadlines.
- Experience in GRC planning, development, and management, including Information Security policy and procedure development.
- Experience across a variety of industries - finance, banking, private equity, healthcare, critical infrastructure, technology services, and other regulated environments.
- Proficient in leading cybersecurity frameworks (e.g., CIS, NIST, ISO, SOC2, COBIT, ITIL, PCI, GDPR, HIPAA).
- Experience aligning security strategies with compliance requirements (e.g., SEC, NYDFS, GDPR, CMMC, SOX).
- Knowledge of cloud systems, applications, and security tools (e.g., EDR, MDR, SIEM, CSPM, IAM).
- Familiarity with network security, data security, vulnerability management, incident response, disaster recovery, and third-party risk management.
- Certification: CISSP, CISA, CISM, CRISC, CGRC, CvCISO, CGEIT, or similar.
- Education: Degree in Information Systems, Computer Science, or a related discipline preferred.
- Applicants must have authorization to work in the United States without current or future visa sponsorship.
Preferred Qualifications:
- Prior experience managing a team of vCISOs, security consultants, or client-facing advisory staff at an MSP or MSSP.
- Track record of building or scaling a vCISO/advisory practice - including staffing models, delivery playbooks, and QA processes.
- Experience building security programs from the ground up, including framework adoption and roadmap development (priorities, timelines, budgets).
- Strong executive advisory skills - capable of developing extensive reports and presentations and delivering complex security concepts to non-technical audiences.
- Experience contributing to proposals, pricing, or account growth in a consulting/professional services context.
- Superior attention to detail, with a strong aptitude for both technical and strategic problem-solving.
- Active participation in cybersecurity thought leadership and industry events.
- Intellectual curiosity with a continuous learning mindset.
- Adaptability and versatility in a fast-paced, demanding environment.
Why Echelon?
We are committed to creating an inclusive environment for our team with unquestioned integrity. If you have a special need that requires accommodation, please let your recruiter know. One of our core values is "People with Personality," and we want to allow you the space to bring your full self to work.
We currently offer the following benefits:
- Access to medical, dental, and vision insurance through Cigna, with the majority of the employee cost covered by the employer
- Employer funding to HSA accounts and FSA access
- Access to a 401(k) through Vanguard with a guaranteed employer contribution
- Flexible vacation policy that allows you to manage your schedule and rest and recharge when you need to
- 11 holidays with flexibility based on what is important for you and those you love
- Family-friendly benefits, including weeks off for Maternity leave, weeks off for non-birthing parent leave, employer-paid short-term and long-term disability, employer-paid life insurance, and access to additional life insurance, hospital coverage, accidental coverage, discounted mental health support, and more
- Support for individual development through certifications, continued learning, conferences, and more
We value a diverse workforce and a culture of inclusivity and belonging. All employment decisions shall be made without regard to age, race, creed, color, religion, gender, national origin, ancestry, disability status, veteran status, sexual orientation, gender identity or expression, genetic information, marital status, citizenship status, or any other basis as protected by federal, state, or local law. Echelon Risk + Cyber is an Equal Opportunity Employer.