Echelon Risk + Cyber
Director, vCISO Services - Remote (USA)
Share this job
Job Description
*About us:* At Echelon Risk + Cyber, we believe in defending basic human rights to security and privacy. We seek a highly skilled and experienced Cybersecurity Leader with extensive experience serving as Director, vCISO Services to join our dynamic team at Echelon Risk + Cyber, a leading cybersecurity consulting firm. This role blends hands-on client delivery with people leadership: you'll carry your own book of advisory engagements while leading, coaching, and developing a team of vCISOs and vCISO Managers, serving as their escalation point, partnering with our GRC and Security Engineering practices, and maturing how the practice delivers as it grows.
Our next team member will be ready to roll up their sleeves and identify opportunities for our clients and for Echelon internally with unquestioned integrity. This team member will be passionate about cybersecurity and ready to use their knowledge to be an Entrepreneurial Problem Solver and work alongside their Echelon team members to build creative solutions.
At Echelon, you will have the opportunity to engage with clients, business partners and systems that are at the cutting edge of technology. We allow our employees to build from the ground up and make an impact across the organization. We look for driven and proactive people that are eager to contribute to a distinct and thriving Cybersecurity services organization, that can adapt to a rapid and changing environment
This is a remote position from anywhere in the USA.
*What You Will Do:*
*Team Leadership, Development & Performance:*
- Directly lead a team of vCISOs and vCISO Managers, owning performance management, career pathing, coaching, and day-to-day support for each member of the team.
- Run a consistent leadership cadence of 1:1s, team meetings, and engagement reviews that builds peer learning and a shared standard of practice across the team.
- Develop your people deliberately: build individual development plans, identify skill gaps, and deliver the internal enablement, such as playbooks, templates, shadowing, and certification paths, that moves consultants toward independent client leadership.
- Define and own the KPI set for the practice, including utilization, engagement health, deliverable quality, client satisfaction, and retention; set individual and team targets against it.
- Build and run recurring reporting for practice and executive leadership covering team performance, portfolio status, capacity, and at-risk accounts; use that same performance data in coaching and reviews, not only upward reporting.
- Lead hiring, onboarding, and ramp planning as the practice grows; define what "ready to lead a client" looks like and hold the bar.
- Own staffing and capacity planning in partnership with delivery leadership, matching consultant bandwidth, industry background, and technical depth to client demand.
*Escalation Support & Client Oversight:*
- Serve as the primary escalation point for the vCISO team on complex client situations, scope conflicts, difficult stakeholder dynamics, and technical or strategic questions your team surfaces.
- Provide senior escalation support directly to clients: monitor engagement health across the portfolio and step into at-risk accounts, executive tension, contested findings, and active incidents before an issue becomes a renewal issue.
- Provide oversight and guidance to the client-side security teams your vCISOs advise, coaching client staff, arbitrating priorities, and reinforcing the vCISO's recommendations at the executive level.
- Set and enforce deliverable standards, then review and approve client-facing work (assessments, roadmaps, board decks, policy sets, risk registers) before it reaches the client.
- Spot patterns across accounts, such as recurring escalation types, scope creep, and deliverable rework; fix the underlying process, template, or staffing cause rather than the individual symptom.
- Act as the continuity layer during transitions, absences, and account handoffs so clients never experience a gap in senior coverage.
*Client Delivery & Strategic Advisory:*
- Carry a personal portfolio of vCISO and Managed Security Services engagements, delivering expert advisory at the C-suite and board level.
- Operate comfortably across many concurrent clients, context-switching between industries, maturity levels, regulatory environments, and stakeholder styles without losing depth on any of them.
- Advise clients on the development and execution of security strategies and multi-year roadmaps aligned to business objectives, budget realities, and risk tolerance.
- Lead senior client forums including security steering committees, executive briefings, and board meetings.
- Plan, scope, and execute advisory engagements end to end, from discovery through assessment, roadmap, and reporting, including the development and maturation of client policies, procedures, and control frameworks.
- Facilitate executive workshops, tabletop exercises, and awareness sessions that move client leadership from awareness to action.
*Partnering with GRC and Security Engineering:*
- Work closely with Echelon's GRC team to scope, sequence, and deliver client compliance initiatives, including audits, readiness assessments, framework adoption, and regulatory reporting.
- Work closely with Echelon's Security Engineering team to translate advisory recommendations into implementable technical roadmaps, and to bring engineering expertise into client conversations at the right moment.
- Coordinate cross-practice delivery on shared accounts so the client experiences one Echelon team; identify early where an initiative needs capability beyond the vCISO engagement, such as offensive security, incident response, engineering, or GRC, and bring that practice in.
- Provide senior review on risk assessments and control evaluations against frameworks such as CIS, NIST, ISO, PCI DSS, CMMC, SOC 2, and HIPAA, and align client security strategy with regulatory obligations including SEC, NYDFS, FedRAMP, GDPR, and SOX.
- Advise on the selection, implementation, and optimization of security technologies (SIEM, EDR/MDR, IAM, CSPM, data protection, network security) in partnership with engineering.
- Provide senior oversight on vulnerability management, penetration testing, and incident response readiness across the team's accounts.
*Practice Growth & Maturity:*
- Own how the vCISO practice delivers and mature it as the team scales, covering methodology, engagement lifecycle, QA checkpoints, onboarding runbooks, escalation paths, and reusable templates.
- Standardize what should be consistent and leave room for what should be tailored; reduce variance between consultants without flattening judgment.
- Continuously refine Echelon's vCISO service offerings based on what is working in the field and what clients are asking for next.
- Partner with sales and practice leadership on scoping, proposals, and pricing, and serve as the senior technical and strategic voice in prospect conversations where credibility closes the gap.
- Identify organic growth opportunities within existing accounts managed by your team and support the expansion conversation.
- Produce thought leadership, such as blogs, webinars, and articles, and represent Echelon at industry conferences and events.
*Your Knowledge, Skills, and Abilities*
*Experience & Tenure:*
- 20+ years across progressive information technology and cybersecurity roles, including at least 10 years focused specifically on security, with meaningful time spent in hands-on technical roles before moving into advisory and leadership.
- 7+ years delivering in a consulting, professional services, or managed services environment is required. This role is built for someone who understands billable delivery, scoping discipline, client politics, and the operating rhythm of a services firm, not solely internal enterprise security.
- 5+ years as a vCISO, CISO, or senior cybersecurity advisor, preferably serving multiple clients concurrently in an MSP, MSSP, or consulting model.
- 5+ years of direct people leadership, managing consultants, managers, or advisory staff, including performance management, coaching, career development, and serving as an escalation point for both internal staff and client executives.
*Leadership Capability:*
- Proven ability to lead a distributed advisory team and hold a high delivery standard without micromanaging; the kind of leader people want to work for and stay with.
- Track record of developing people, with specific examples of consultants who advanced because of your coaching.
- Experience defining team KPIs and using performance data to manage, not just to report.
- Comfort making decisions with incomplete information, and the judgment to know which decisions belong to you and which belong to your team.
- Executive presence and credibility with boards, C-suites, and technical practitioners alike, able to move between those audiences in the same day.
*Delivery & Technical Depth:*
- Proven ability to manage a high-volume, concurrent client portfolio personally while overseeing a team doing the same, sustaining quality under simultaneous deadlines.
- Experience in GRC planning, development, and management, including information security policy and procedure development.
- Experience across a range of industries, including financial services, private equity, healthcare, critical infrastructure, manufacturing, technology services, and other regulated environments.
- Proficiency in leading cybersecurity frameworks (CIS, NIST CSF and 800-53, ISO 27001, SOC 2, COBIT, PCI DSS, FFIEC, HIPAA) and experience aligning security strategy with compliance obligations (SEC, NYDFS, GDPR, CMMC, SOX).
- Working knowledge of cloud platforms, security architecture, and modern security tooling (EDR, MDR, SIEM, CSPM, IAM, DLP), plus familiarity with network and data security, vulnerability management, incident response, business continuity, and third-party risk management.
- Certification: CISSP, CISA, CISM, CRISC, CGRC, CvCISO, CGEIT, or similar.
- Education: Degree in Information Systems, Computer Science, or a related discipline preferred.
- Applicants must have authorization to work in the United States without current or future visa sponsorship.
Preferred Qualifications
- Prior experience leading vCISOs or client-facing advisory staff at an MSP, MSSP, or consulting firm, including building or scaling a practice: staffing models, delivery playbooks, QA processes, and metrics frameworks.
- Experience building client security programs from the ground up, including framework adoption and roadmap development with priorities, timelines, and budgets.
- Experience working alongside adjacent practices (GRC, security engineering, offensive security, incident response) on shared client accounts.
- Experience contributing to proposals, pricing, or account growth in a professional services context.
- Strong written communication, capable of producing executive-grade reports and board materials, and coaching others to do the same.
- Intellectual curiosity, attention to detail, and adaptability in a fast-paced environment, with active participation in cybersecurity thought leadership and industry events.
*Why Echelon?*
We are committed to creating an inclusive environment for our team with unquestioned integrity. If you have a special need that requires accommodation, please let your recruiter know. One of our core values is "People with Personality," and we want to allow you the space to bring your full self to work.
We currently offer the following benefits
- Access to medical, dental, and vision insurance through Cigna, with the majority of the employee cost covered by the employer
- Employer funding to HSA accounts and FSA access
- Access to a 401(k) through Vanguard with a guaranteed employer contribution
- Flexible vacation policy that allows you to manage your schedule and rest and recharge when you need to
- 11 holidays with flexibility based on what is important for you and those you love
- Family-friendly benefits, including weeks off for Maternity leave, weeks off for non-birthing parent leave, employer-paid short-term and long-term disability, employer-paid life insurance, and access to additional life insurance, hospital coverage, accidental coverage, discounted mental health support, and more
- Support for individual development through certifications, continued learning, conferences, and more
We value a diverse workforce and a culture of inclusivity and belonging. All employment decisions shall be made without regard to age, race, creed, color, religion, gender, national origin, ancestry, disability status, veteran status, sexual orientation, gender identity or expression, genetic information, marital status, citizenship status, or any other basis as protected by federal, state, or local law. Echelon Risk + Cyber is an Equal Opportunity Employer.
Keep looking
Similar Remote Executive Jobs
Intuitive Health
Director, Real Estate (East Region)
Behavior Interventions, Inc.
Assistant Program Director, EP
Physician Assistant Education Association
Director of Membership
Greater Chicago Food Depository