vCISO
Location
United States
Posted
22 days ago
Salary
$100K - $150K / year
No structured requirement data.
Job Description
Role Description
As vCISO, you will provide strategic and operational cybersecurity and compliance guidance and serve as a trusted security advisor to Ntiva’s GovCon clients. You will be responsible for leading CMMC Level 2 and broader compliance strategies for both prospective and existing clients, supporting new business pursuits while strengthening and expanding current relationships. The vCISO works closely with Sales, Account Management, Engineering, and Delivery teams to align compliance initiatives with client business objectives and regulatory requirements. In this role, you will:
- Personally execute full-cycle CMMC Level 2 audits from initial gap assessment through remediation validation and final documentation, ensuring alignment with regulatory and contractual requirements.
- Provide direct support to Sales and Account Management teams during CMMC and broader compliance discussions with prospective and existing clients, including but not limited to client calls, strategy sessions, and proposal development.
- Serve as a subject-matter expert to help shared services teams navigate evolving compliance requirements and client expectations.
- Contribute to the development and refinement of Ntiva’s compliance go-to-market strategy, ensuring alignment across sales, delivery, and marketing.
- Drive the standardization, documentation, and refinement of the GovCon service stack to ensure a unified and scalable delivery model.
- Help ensure Ntiva’s compliance offerings remain competitive, scalable, and aligned with industry standards.
- Conduct monthly security log reviews and oversee timely remediation activities to maintain CMMC Compliance.
- Document and upload remediation results into the GRC platform.
- Escalate critical security and compliance risks to GovCon leadership with clear impact and recommended actions.
- Validate that all remediation efforts align with applicable regulatory and contractual requirements.
Qualifications
- 3–4+ years of IT compliance experience with a strong security focus.
- Two full-cycle CMMC Level 2 audit completions with direct, hands-on execution from gap assessment through remediation validation and final documentation (not solely oversight or advisory).
- Demonstrated full audit lifecycle experience, including control testing, evidence collection, POA&M management, remediation tracking, and audit documentation.
- Background in IT consulting, managed services (MSP), cybersecurity, or compliance advisory services.
- Strong knowledge of managed services delivery models and cybersecurity tooling that enable scalable compliance.
- Practical understanding of core security technologies, including firewalls and infrastructure controls that support compliance frameworks.
- Deep working knowledge of CMMC (Levels 1–2) and NIST 800-171.
- Experience accurately tracking and documenting billable time in accordance with client-facing consulting or managed services environments.
- Experience supporting GovCon clients and navigating federal regulatory requirements.
- Strong documentation and communication skills for both technical and executive audiences.
Bonus Points for
- Experience participating in or preparing clients for C3PAO assessments.
- CMMC Registered Practitioner (RP) or RPA designation.
- Experience supporting sales cycles, including proposal development and compliance-focused client discussions.
- Experience contributing to go-to-market strategy, service standardization, and cross-functional enablement across Sales, Account Management, Engineering, and Delivery teams.
- Ability to develop repeatable messaging, playbooks, and training materials for compliance programs.
Requirements
- Ability to communicate professionally, in English, both written and orally.
- Ability to write business correspondence and process procedures.
- Ability to effectively present information and respond to questions from groups of managers, clients, and the general public.
Benefits
- Medical, Dental and Vision coverage for employee and family.
- 401k + company-matched contributions 4% match on 5% contribution - no vesting period! (Employee and Company contribute after 90 days).
- Group Term Life and Accidental Death and Dismemberment coverage (company provided).
- Short-Term (voluntary enrollment) and Long-Term Disability coverage (company provided).
- Health Savings Account (HSA) Options / PPO Options.
- Employee Assistance Program.
- Paid Time Off (PTO) + Volunteer Time Off (VTO) + 8 Paid Holidays + 3 Floating Holidays.
- Education Reimbursement Program.
- Generous Employee Referral Program - cash bonus for successful referrals!
- Dynamic Recognition and Rewards.
- Clear Promotion and Advancement Tracks.
- Work with Industry-Leading Talent.
Job Requirements
- 3–4+ years of IT compliance experience with a strong security focus.
- Two full-cycle CMMC Level 2 audit completions with direct, hands-on execution from gap assessment through remediation validation and final documentation (not solely oversight or advisory).
- Demonstrated full audit lifecycle experience, including control testing, evidence collection, POA&M management, remediation tracking, and audit documentation.
- Background in IT consulting, managed services (MSP), cybersecurity, or compliance advisory services.
- Strong knowledge of managed services delivery models and cybersecurity tooling that enable scalable compliance.
- Practical understanding of core security technologies, including firewalls and infrastructure controls that support compliance frameworks.
- Deep working knowledge of CMMC (Levels 1–2) and NIST 800-171.
- Experience accurately tracking and documenting billable time in accordance with client-facing consulting or managed services environments.
- Experience supporting GovCon clients and navigating federal regulatory requirements.
- Strong documentation and communication skills for both technical and executive audiences.
- Bonus Points for
- Experience participating in or preparing clients for C3PAO assessments.
- CMMC Registered Practitioner (RP) or RPA designation.
- Experience supporting sales cycles, including proposal development and compliance-focused client discussions.
- Experience contributing to go-to-market strategy, service standardization, and cross-functional enablement across Sales, Account Management, Engineering, and Delivery teams.
- Ability to develop repeatable messaging, playbooks, and training materials for compliance programs.
- Ability to communicate professionally, in English, both written and orally.
- Ability to write business correspondence and process procedures.
- Ability to effectively present information and respond to questions from groups of managers, clients, and the general public.
Benefits
- Medical, Dental and Vision coverage for employee and family.
- 401k + company-matched contributions 4% match on 5% contribution - no vesting period! (Employee and Company contribute after 90 days).
- Group Term Life and Accidental Death and Dismemberment coverage (company provided).
- Short-Term (voluntary enrollment) and Long-Term Disability coverage (company provided).
- Health Savings Account (HSA) Options / PPO Options.
- Employee Assistance Program.
- Paid Time Off (PTO) + Volunteer Time Off (VTO) + 8 Paid Holidays + 3 Floating Holidays.
- Education Reimbursement Program.
- Generous Employee Referral Program - cash bonus for successful referrals!
- Dynamic Recognition and Rewards.
- Clear Promotion and Advancement Tracks.
- Work with Industry-Leading Talent.
Related Guides
Related Categories
Related Job Pages
More Chief Technology Officer Jobs
Manage and resolve a portfolio of distressed, rent-regulated NYC multifamily loans through underwriting, restructuring, loan documentation review, judicial foreclosure oversight, REO management, and negotiations with borrowers and counsel. Prepare credit memoranda, execute workout strategies, and ensure regulatory and policy compliance to maximize recovery.
Lead Account Technology Strategists
Cloud Software GroupEnabling customers to evolve, compete & succeed in data, automation, insight, and collaboration.
Serve as a trusted technical advisor to senior customer stakeholders, developing strategic cloud technology roadmaps, driving adoption and consumption, leading complex multi-product proofs-of-concept, and accelerating sales through technical leadership, mentoring ATS teams, and cross-functional collaboration to retain and grow enterprise accounts.
Lead technology recovery and business continuity programs, manage SOC report reviews and third‑party risk, maintain risk registers, advise stakeholders, drive testing and remediation, and report KRIs/KPIs to leadership.
As CTO, you'll lead the development of an AI-powered career operating system, transforming an MVP into a scalable platform while building and managing a technical team.