Virtual Chief Information Security Officer (vCISO)

Ntiva Branding

Leawood (KS, IL)

Hybrid

USD 100,000 - 140,000

Full time

14 days+
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Medical, Dental and Vision coverage
401k with 4% match
Group Life and AD&D
Disability coverage (short/long term)
HSA / PPO plans
Employee Assistance Program
PTO + VTO + 8 holidays + 3 floating
Education Reimbursement
Referral program
Recognition and rewards
Promotion and advancement tracks
Work with industry-leading talent

Job summary

Ntiva is seeking a vCISO to serve as the fractional security leader for GovCon clients, guiding their security programs and roadmaps.

You will lead readiness for CMMC Level 2 and NIST 800-171, translate technical risk into business guidance, and collaborate with Sales, Engineering, and Delivery to align security with client goals. Hybrid work in the Chicago or Kansas City areas is available.

Qualifications

  • 5+ years in cybersecurity or IT compliance with client-facing advisory experience.
  • Hands-on experience leading CMMC Level 2 / NIST 800-171 readiness engagements end to end.
  • Strong knowledge of identity and access management (Microsoft Entra ID / Azure AD, MFA).
  • Experience with Microsoft 365 and Azure security, including GCC High and DFARS applicability.
  • Ability to translate technical risk into business guidance for executives and delivery teams.
  • Background in IT consulting, MSP, cybersecurity, or compliance advisory services.
  • Experience supporting GovCon clients and navigating federal regulatory requirements.
  • Experience tracking and documenting billable time in a client-facing environment.
  • Strong documentation and communication skills for technical and executive audiences.

Responsibilities

  • Serve as the fractional security leader for GovCon clients, setting program direction and roadmaps.
  • Lead client risk management, conduct risk assessments, and prioritize remediation.
  • Own ongoing compliance assurance, SSPs, and POA&M upkeep.
  • Lead CMMC Level 2 and NIST 800-171 readiness efforts from scoping to remediation.
  • Validate controls across identity, endpoint, network, cloud, and logging.
  • Advise on security architecture and tooling to enable scalable compliance.
  • Provide security leadership during incidents with containment and reporting.
  • Develop client security governance, policies, standards, and procedures.
  • Support Sales and Account Management with security insights in client discussions.
  • Escalate security risks with business impact and recommended actions.
  • Contribute to Ntiva’s GovCon go-to-market strategy and service maturity.

Skills

Cybersecurity
Security consulting
IT compliance
Client-facing
Risk management
Security architecture
CMMC readiness
NIST 800-171
Governance
English communication

Tools

Azure AD
Microsoft 365 security
SIEM
M365 Defender

Job description

Are you looking for limitless career opportunities with a company that values growth, innovation, and teamwork?At Ntiva,we’remore than a Managed ServicesProvider,we’rea community dedicated to helping each other, our clients, and their businesses thrive both personally and professionally. Ntiva is a culture of people who are passionate about the work…and each other.

Our clients view us as an essential part of their teams, relying on us for strategic guidance, fast solutions to complex challenges, and proactive support. With strategic locations across the U.S. and leadership from our founder, Steven Freidkin,we’reon the front lines of a fast-paced industry, facing cybersecurity threats and rapid technology changes together.

If you thrive in a dynamic, supportive environment and enjoy going above and beyond,we’dlove to meet you. Come explore one of our many opportunities and grow with us!

How you’ll make an Impact

As a vCISO, you will serve as a fractional security leader and trusted advisor to Ntiva’s GovCon clients, owning the direction of their security program while staying close enough to the work to move it forward. You will lead security and compliance strategy for both prospective and existing clients across the defense industrial base regulatory landscape (CMMC, NIST 800-171/172, DFARS, and the frameworks around them), translate those requirements into practical, prioritized roadmaps, and provide the ongoing assurance clients need to stay defensible over time — not just at a point-in-time assessment. You will support new-business pursuits, strengthen and expand current relationships, and work closely with Sales, Account Management, Engineering, and Delivery teams to align security initiatives with client business objectives. In this role you will help shape Ntiva’s go-to-market approach for security and compliance services, mature the GovCon service stack, and ensure a consistent, scalable, and high-quality client experience across delivery, compliance, and advisory.

Location and Work Expectations
  • This is a hybrid role with approximately 10% on-site work at client locations. We are seeking candidates located in either the Chicago or Kansas City areas. The specific allocation of remote versus onsite requirements may fluctuate based on business needs.
  • Monday-Friday, 8am-5pm CST
What you will be doing
  • Serve as the fractional security leader for a portfolio of GovCon clients, setting security program direction, building and maintaining multi-year security roadmaps, and reporting risk and progress to client leadership in clear business terms.
  • Lead client risk management: conduct and interpret risk assessments, maintain risk registers, and drive risk-based prioritization of remediation and security investment.
  • Own ongoing compliance assurance across client programs, continuous control monitoring, periodic reassessment, and evidence maintenance, keeping SPRS scores, SSPs, and POA&M current and defensible between formal assessments.
  • Lead CMMC Level 2 and NIST 800-171 readiness for clients: scope the environment, direct gap assessments, and guide remediation from findings through validated closure. (Ntiva prepares and maintains clients for certification; it is not a C3PAO and does not perform the certifying assessment.)
  • Technically validate control implementation, review configurations across identity, endpoint, network, cloud (Microsoft 365 / Azure), and logging to confirm NIST 800-171 controls are actually in place and effective, not just documented on paper.
  • Advise on security architecture and tooling, identity, endpoint, network/firewall, and logging/monitoring, partnering with Engineering and Delivery on designs and controls that make compliance scalable and sustainable.
  • Provide security leadership during events and incidents: guide client response, oversee containment and remediation, and ensure applicable reporting obligations (e.g., DFARS 252.204-7012) are met.
  • Develop and maintain client security governance, policies, standards, and procedures aligned to NIST 800-171 and client contractual requirements.
  • Support Sales and Account Management as the senior security voice in prospective and existing client discussions, including client calls, strategy sessions, and proposal development.
  • Escalate critical security and compliance risks to GovCon leadership with clear business impact and recommended actions.
  • Contribute to Ntiva’s security and compliance go-to-market strategy and to the standardization, documentation, and maturity of the GovCon service stack.
You’ll be successful in this role if you have experience in/with:
  • 5+ years in cybersecurity, security consulting, or IT compliance with a strong technical foundation, including client-facing advisory experience serving as the senior security voice for client leadership.
  • Hands‑on experience leading CMMC Level 2 / NIST 800-171 readiness engagements end to end, scoping, control assessment, POA&M management, remediation tracking, and evidence and audit documentation.
  • Strong hands‑on command of the security stack, identity and access management (Microsoft Entra ID / Azure AD, MFA, conditional access), endpoint protection (EDR/MDR), network and firewall controls, SIEM/log management, vulnerability management, and email security.
  • Working knowledge of Microsoft 365 and Azure security, including government cloud (GCC / GCC High), FIPS‑validated encryption, and CUI protection as they apply to DFARS and NIST 800-171.
  • Ability to read and evaluate system configurations and technically validate that controls are implemented and effective, not just documented on paper.
  • Ability to translate technical risk into business‑level guidance for client executives and working knowledge of risk management within a managed‑services delivery model.
  • Background in IT consulting, managed services (MSP), cybersecurity, or compliance advisory services.
  • Experience supporting GovCon clients and navigating federal regulatory requirements (CMMC, DFARS, NIST 800-171).
  • Experience accurately tracking and documenting billable time in a client‑facing consulting or managed‑services environment.
  • Strong documentation and communication skills for both technical and executive audiences.
Bonus Points for
  • Technical security certifications such as CompTIA Security+, Microsoft SC-200 / SC-300 / SC-100, or Azure Security Engineer (AZ-500).
  • CISSP, CISM, or an equivalent senior security certification.
  • CMMC Registered Practitioner (RP/RPA), CCP, or CCA designation.
  • Hands‑on experience implementing or hardening Microsoft 365 GCC High / Azure Government environments.
  • Experience working with or for an IT/Managed Service Provider (MSP).
  • Scripting or automation experience (e.g., PowerShell) for security configuration and validation.
  • Experience participating in or preparing clients for C3PAO assessments.
  • Experience building or maturing a security program from the ground up.
  • Experience supporting sales cycles, including proposal development and compliance‑focused client discussions.
  • Experience contributing to go‑to‑market strategy, service standardization, and cross‑functional enablement, including developing repeatable messaging, playbooks, and training for security and compliance programs.
Required language skills
  • Ability to communicate professionally, in English, both written and orally
  • Ability to write business correspondence and process procedures
  • Ability to effectively present information and respond to questions from groups of managers, clients, and the general public
Benefits and Perks
  • Medical, Dental and Vision coverage for employee and family
  • 401k + company‑matched contributions 4% match on 5% contribution‑ no vesting period!(Employee and Company contribute after 90 days)
  • Group Term Life and Accidental Death and Dismemberment coverage (company provided)
  • Short‑Term (voluntary enrollment) and Long‑Term Disability coverage (company provided)
  • Health Savings Account (HSA) Options / PPO Options
  • Employee Assistance Program
  • Paid Time Off (PTO) +Volunteer Time Off (VTO) +8PaidHolidays+ 3 Floating Holidays
  • EducationReimbursement Program
  • Generous Employee Referral Program-cash bonus for successful referrals!
  • Dynamic Recognition and Rewards
  • Clear Promotion and Advancement Tracks
  • Work with Industry‑Leading Talent

The base pay range for this position is expected to be between $100,000 and $140,000 per year. The base pay offered may vary depending on multiple non‑discriminatory factors including, but not limited to, market location, job‑related knowledge, skills, and experience. The total compensation package for this position also includes medical benefits, 401(k) eligibility, and PTO.Additionaldetails of participation in these benefit plans will be provided if an employee receives an offer of employment.

FLSA Status: Salaried, Exempt

Work Authorization Criteria

Standard:We welcome applicants who are U.S. persons.At this time, we are unable to offer sponsorship or assume sponsorship of an employment visa.

This position requires U.S. citizenship due to federal government contract obligations and access to secured information systems.

Workspace Requirements and Remote Work Policy

Team members must establish a dedicated safe workspace that is free from distractions, hazards, and that is secure from unauthorized access. This includes following Ntiva’s IT User and Security Policies that include but are not limited to password‑protecting all equipment, keeping confidential and proprietary documents secure, refraining from using public Wi‑Fi, having adequate arrangements in place to avoid significant interruptions from caregiving responsibilities during work hours(except in emergency situations with manager approval). Any remote work away from a team member’s normal expected dedicated safe workspace must be requested by team member, is subject to review by management, and must adhere to Ntiva policies and procedures.

Our Commitment to a Diverse Workforce

At Ntiva, we are committed to creating and maintaining a diverse, inclusive, and welcoming work environment for all employees and job applicants. We firmly believe that a diverse workforce fosters a wider range of perspectives, experiences, and ideas that lead to increased creativity, innovation, and problem‑solving capabilities. As an equal opportunity employer, we actively seek to recruit and retain a diverse workforce that reflects the communities we serve. We prohibit discrimination of any kind, including but not limited to race, color, religion, gender, gender identity or expression, sexual orientation, marital status, national origin, age, hair length, protective hairstyles, organ donor status, disability, veteran status, or any other legally protected status and comply with all applicable laws governing nondiscrimination in employment.

Application Deadline

Applications will be accepted until 9/30/2026.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Virtual Chief Information Security Officer (vCISO)
Virtual Chief Information Security Officer (vCISO)

Ntiva • Leawood (KS)

Hybrid
USD 100,000 - 140,000
Medical, Dental and Vision coverage
401k + company-matched contributions
Employee Referral Program
Virtual Chief Information Security Officer (vCISO)
Virtual Chief Information Security Officer (vCISO)

Ntiva, Inc. • Lombard (IL)

Hybrid
USD 100,000 - 140,000
Medical, Dental and Vision coverage
401k + company-matched 4%
Paid PTO & holidays
Senior Account Manager (GovCon)
Senior Account Manager (GovCon)

Ntiva • Lombard (IL)

On-site
USD 75,000 - 105,000
Medical/Dental/Vision
401k + company match
Life Insurance
+6
Senior Account Manager (GovCon)
Senior Account Manager (GovCon)

Ntiva, Inc. • Lombard (IL)

Hybrid
USD 75,000 - 105,000
Medical, Dental and Vision coverage
401k + company-matched contributions
Paid Time Off + Holidays
+4
Senior Account Manager (GovCon)
Senior Account Manager (GovCon)

Ntiva Branding • Lombard (IL)

Hybrid
USD 75,000 - 105,000
Medical, Dental, and Vision coverage
401k + company match
Education Reimbursement
+1
Service Desk Technician II
Service Desk Technician II

Ntiva, Inc. • Virginia (MN), Northern (KY)

Hybrid
USD 42,000 - 70,000
Medical, Dental and Vision coverage
401k with company match 4%
Life Insurance
+4
Account Manager
Account Manager

Ntiva, Inc. • Leawood (KS)

Hybrid
USD 75,000 - 85,000
Medical, Dental and Vision coverage
401k with company match
Paid time off and holidays
+2
Systems Administrator II
Systems Administrator II

Ntiva Branding • Town of Texas (WI)

Hybrid
USD 54,000 - 60,000
Health/Dental/Vision
401k matching
Life Insurance
+8
Solutions Consultant
Solutions Consultant

Ntiva Branding • United States

On-site
USD 80,000 - 110,000
Medical, Dental and Vision coverage for employee and family
401k with company match
Education Reimbursement Program
+1
Solutions Consultant
Solutions Consultant

Ntiva Branding • McLean (VA)

On-site
USD 110,000 - 170,000
Medical, Dental & Vision coverage
401k with company match
Life Insurance
+5