Virtual Chief Information Security Officer (vCISO)

Meriplex

Houston (TX)

On-site

USD 150,000 - 190,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Meriplex is seeking a vCISO to serve as a trusted executive advisor and security leader for selected customers. You will own strategic security programs, roadmaps, governance cadences, and risk prioritization while guiding incident response and vendor oversight.

You will engage in executive meetings, assist with security questionnaires and RFP responses, and translate technical security needs into clear business outcomes for clients and Meriplex.)

Qualifications

  • Minimum 5 years of leadership in cybersecurity, risk, governance or advisory roles.
  • Ability to translate security needs into business outcomes and executive-level reports.
  • Experience with HIPAA, SOC 2, NIST CSF, PCI DSS or similar frameworks.

Responsibilities

  • Serve as fractional executive security leader for assigned customers, directing strategy and governance.
  • Lead compliance and audit readiness, risk assessment, evidence collection, and executive reporting.
  • Oversee security operations including monitoring, identity controls, vulnerability management and incident response.
  • Collaborate with sales, delivery, and customer teams to translate governance into operational practices.

Skills

Cybersecurity leadership
Executive advisory
Risk management
Governance
Compliance frameworks
Security operations
Stakeholder communication

Education

Bachelor's degree

Job description

Position Summary: The vCISO functions as a trusted executive advisor and named security leader for assigned customers. This position owns the customer security program at a strategic level, including security roadmaps, governance cadence, executive reporting, risk prioritization, audit readiness, vendor oversight, and incident response leadership. The vCISO also supports Meriplex customer engagement by participating in executive meetings, assisting with security questionnaires and RFP responses, advising on pre-sales opportunities, and translating technical security needs into clear business outcomes.


Job Details

Description

Position Summary: The vCISO functions as a trusted executive advisor and named security leader for assigned customers. This position owns the customer security program at a strategic level, including security roadmaps, governance cadence, executive reporting, risk prioritization, audit readiness, vendor oversight, and incident response leadership. The vCISO also supports Meriplex customer engagement by participating in executive meetings, assisting with security questionnaires and RFP responses, advising on pre-sales opportunities, and translating technical security needs into clear business outcomes.



Key Responsibilities/ Duties


Leadership and Strategy


  • Serve as the fractional executive security leader for assigned customers, owning security strategy, program direction, governance cadence, and executive-level risk communication.

  • Develop and maintain cybersecurity roadmaps aligned to customer business objectives, regulatory drivers, risk appetite, maturity level, and budget priorities.

  • Brief executive leadership, boards, and key stakeholders on security posture, material risks, program progress, incident readiness, and recommended investment decisions.

  • Establish security governance models, steering committees, decision logs, metrics, and accountability structures that allow customers to manage cybersecurity as a business function.



Compliance and Risk Management


  • Lead compliance and audit readiness efforts for frameworks and regulations such as HIPAA, SOC 2, NIST CSF, PCI DSS, and other customer-specific requirements.

  • Own risk assessment activities, risk registers, remediation plans, evidence collection oversight, and executive reporting on residual risk and control gaps.

  • Coordinate with auditors, regulators, cyber insurance providers, legal teams, and customer leadership to support assessments, attestations, security questionnaires, and remediation commitments.

  • Translate compliance requirements into practical control improvements, prioritized workstreams, and business-ready recommendations that customers can fund and execute.



Security Operations


  • Oversee the effectiveness of customer security operations, including monitoring capabilities, endpoint protection, identity controls, vulnerability management, backup readiness, and response processes.

  • Direct incident response planning and execution, including tabletop exercises, escalation paths, executive communications, post-incident reviews, and remediation tracking.

  • Advise customers on security tooling, vendor selection, solution rationalization, and managed service alignment to ensure investments reduce measurable business risk.

  • Coordinate with Meriplex delivery, SOC, engineering, account management, and customer teams to ensure governance recommendations are translated into operational execution.



Collaboration And Communication


  • Represent Meriplex and assigned customers in executive meetings, board-level discussions, audit meetings, customer security reviews, and strategic planning sessions.

  • Communicate cybersecurity risk, strategy, program maturity, and recommended actions in clear business language suitable for executives, boards, non-technical leaders, and client stakeholders.

  • Support MSP/MSSP customer growth activities by assisting with pre-sales conversations, renewal discussions, security questionnaires, RFP responses, and customer-facing advisory sessions.

  • Partner with sales, account management, and service delivery teams to identify customer security needs, clarify business value, and shape practical cybersecurity roadmaps.



Knowledge, Skills, Abilities, And Behaviors


  • Minimum of 5 years of progressive experience across cybersecurity leadership, risk management, governance, compliance, security operations, or IT advisory roles.

  • Demonstrated ability to operate as a fractional executive advisor, influence senior leaders, brief boards, and guide cybersecurity decisions in business terms.

  • Strong working knowledge of security and compliance frameworks including HIPAA, NIST CSF, SOC 2, and PCI DSS.

  • Experience leading security assessments, audit readiness, incident response planning, tabletop exercises, security roadmaps, and risk remediation programs.

  • Ability to support customer-facing advisory work, executive presentations, security questionnaires, RFP responses, and pre-sales technical discussions.

  • Excellent communication, prioritization, consulting, and relationship management skills with the ability to manage multiple customers, competing deadlines, and executive expectations.



Education/ Experience


  • Bachelor's degree from an accredited university/college preferred; equivalent executive cybersecurity, risk, compliance, or advisory experience may be considered.

  • Proven experience in client relationship management, executive advisory, governance, audit support, and customer-facing cybersecurity services within an MSP, MSSP, consulting, or managed services environment.



Certifications


  • Cybersecurity credentials such as CISSP, CISM, CISA, CRISC, or equivalent are strongly preferred.



Physical Demands

Sedentary Work – Exerts up to 10 pounds of force occasionally, a negligible amount of force frequently, and/or constantly having to lift, carry, push, pull or otherwise move objects, including the human body. Sedentary work involves sitting most of the time.



Disclaimer

The above information in this description has been designed to indicate the general nature and level of work performed by employees within this classification. It is not designed to contain or be interpreted as a comprehensive inventory of all duties, responsibilities, and qualifications required of employees assigned to this job.


Meriplex Communications and Meriplex Solutions are Equal Employment Opportunity Employers. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender perception or identity, national origin, age, marital status, protected veteran status, or disability status.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Virtual Chief Information Security Officer (vCISO)
Virtual Chief Information Security Officer (vCISO)

Meriplex Communications, Ltd. • Houston (TX)

On-site
USD 180,000 - 230,000
Virtual Chief Information Security Officer (vCISO)
Virtual Chief Information Security Officer (vCISO)

Meriplex-Communication • Houston (TX)

On-site
USD 150,000 - 230,000
Cyber Incident Responder
Cyber Incident Responder

Meriplex-Communication • Town of Texas (WI)

On-site
USD 110,000 - 160,000
Cyber Incident Responder
Cyber Incident Responder

Meriplex Communications, Ltd. • Town of Texas (WI), Northern (KY)

Hybrid
USD 110,000 - 150,000
Cybersecurity Operations Manager
Cybersecurity Operations Manager

In-Telecom • Arlington (TX)

On-site
USD 120,000 - 160,000
Medical Insurance
Dental Insurance
Vision Insurance
+2
16267 Senior Cyber Security Specialist
16267 Senior Cyber Security Specialist

Socket.dev • Duluth (GA)

On-site
USD 110,000 - 150,000
Health Insurance
401(k) Plan
Paid Time Off
+1
Cyber Incident Responder
Cyber Incident Responder

Meriplex • Town of Texas (WI)

On-site
USD 120,000 - 180,000
Virtual CISO (vCISO)
Virtual CISO (vCISO)

Jobtailor • Naperville (IL)

On-site
USD 140,000 - 200,000
Cyber Security Specialist
Cyber Security Specialist

Vensure Employer Solutions • Duluth (GA)

On-site
USD 80,000 - 100,000
Health Insurance
401(k) Retirement Plan
Paid Time Off
Technical Account Manager
Technical Account Manager

Meriplex Communications, Ltd. • Bedford (MA)

On-site
USD 100,000 - 130,000
Medical, Dental, Vision insurance
401k
PTO
+2