Senior vCISO / GRC Consulting Manager
$125kAgency Cyber Inc
Agency Cybersecurity is fast growing, venture-backed startup that provides best‑in‑class cybersecurity and compliance. Our software and services simplify complex compliance frameworks including SOC2, ISO 27001, HIPAA, and others, empowering businesses to scale securely and confidently. We are backed by top tier investors like YCombinator and have offices in NYC, Boston, Richmond, and London. About the Role We are seeking a Senior vCISO / GRC Consulting Manager to lead client‑facing cybersecurity, governance, risk, and compliance engagements for organizations pursuing or maintaining security frameworks such as NIST800‑171, 800‑53, or CMMC as well as experience with SOC2, ISO27001, and related trust and security standards . This is an in‑person consulting leadership role based in Richmond, VA . The Senior vCISO will work directly with clients, internal delivery teams, and company leadership to provide hands‑on advisory support, manage GRC engagements, and lead a team responsible for delivering high‑quality cybersecurity and compliance services. The Senior vCISO will serve as a strategic advisor to clients, helping them understand their security and compliance obligations, prioritize risk, prepare for audits, implement practical controls, and build scalable security programs. This person will also manage a team of GRC consultants, analysts, and implementation specialists responsible for delivering client work. The ideal candidate has at least 6 years of professional experience in GRC, cybersecurity compliance, audit readiness, or related advisory work , including at least 4 years in a management or team leadership role . This person should be comfortable advising executives, managing client relationships, leading teams, working with auditors, and translating complex security and compliance requirements into clear business actions. Key Responsibilities Client Advisory and vCISO Leadership Serve as a trusted vCISO advisor to clients across cybersecurity, governance, risk, and compliance matters. Provide practical guidance to executive teams, founders, security leaders, IT teams, and business stakeholders. Help clients understand what they need to do to improve security, pass audits, reduce risk, and satisfy customer requirements. Advise clients on security program design, risk prioritization, compliance strategy, policy development, and control implementation. Lead client meetings, executive briefings, audit readiness sessions, and risk review discussions. Translate technical and compliance requirements into clear, business‑friendly recommendations. GRC and Compliance Program Delivery Lead client engagements related to SOC2, ISO 27001 , and other audited security frameworks. Develop and manage compliance roadmaps, audit readiness plans, and remediation timelines for clients. Guide clients through the full lifecycle of compliance readiness, including scoping, gap assessments, control implementation, evidence collection, audit support, and ongoing maintenance. Help clients determine the right level of security and compliance maturity for their size, industry, customer expectations, and business goals. Ensure compliance programs are practical, defensible, and not unnecessarily burdensome. Audit Readiness and Framework Management Lead SOC2 Type1 and Type2 readiness initiatives for clients. Support ISO27001 implementation, certification preparation, surveillance audit readiness, and continuous improvement. Coordinate with external auditors, assessors, client stakeholders, and internal delivery teams. Review audit evidence, control documentation, risk registers, policies, and remediation plans. Help clients understand audit findings and develop clear plans to address gaps. Maintain strong working knowledge of SOC2 Trust Services Criteria, ISO27001 requirements, and common security control expectations. Team Management and Delivery Oversight Manage a team of GRC consultants, analysts, and implementation resources. Assign work, oversee deliverables, manage deadlines, and ensure consistent quality across client engagements. Coach and mentor team members on GRC consulting, client communication, audit readiness, and control implementation. Review team deliverables, including gap assessments, policies, risk registers, audit evidence, project plans, and client‑facing reports. Ensure the team delivers work that is accurate, practical, professional, and aligned with client expectations. Build repeatable delivery processes, templates, playbooks, and quality standards for the consulting team. Security Control and Risk Advisory Advise clients on the design, implementation, and improvement of security and compliance controls. Help clients assess risks across cloud infrastructure, identity and access management, endpoint security, vulnerability management, vendor risk, change management, incident response, and secure development practices. Maintain and improve client risk registers and remediation plans. Work with client technical teams to prioritize security improvements based on business impact, audit requirements, and real‑world risk. Provide practical recommendations that balance security, compliance, cost, and operational complexity. Policy, Governance, and Documentation Lead the development and review of client security policies, procedures, standards, and governance documentation. Help clients implement policy review cycles, access review processes, vendor review workflows, risk acceptance procedures, and other governance activities. Ensure client documentation aligns with actual business practices and audit expectations. Help clients avoid “paper compliance” by tying policies and controls to real operational processes. Customer Trust and Security Questionnaire Support Advise clients on customer security reviews, vendor assessments, and trust‑related requests. Help clients respond to security questionnaires, customer due diligence requests, and enterprise procurement reviews. Support the development of reusable security and compliance response libraries. Help clients use compliance and security posture to support sales, customer trust, and enterprise readiness. Client Relationship Management Own or support client relationships across multiple GRC and vCISO engagements. Set clear expectations with clients regarding scope, timelines, responsibilities, and deliverables. Identify client risks, blockers, and expansion opportunities. Communicate engagement status, risks, and next steps clearly to both internal leadership and client stakeholders. Ensure clients receive strategic advice, not just task completion. Required Qualifications Minimum 6 years of professional experience in GRC, cybersecurity compliance, security advisory, audit readiness, IT risk, internal audit, or a related field. Minimum 4 years of management or team leadership experience . Direct experience advising organizations on audited frameworks such as SOC2 and ISO27001 . Experience managing client‑facing consulting engagements or advisory relationships. Strong understanding of security controls, risk management, compliance frameworks, and audit processes. Experience leading or supporting external audits, including evidence collection, control testing, auditor communications, and remediation. Ability to explain complex security and compliance concepts to executives, founders, technical teams, and non‑technical stakeholders. Strong written and verbal communication skills. Strong project management skills with the ability to manage multiple clients, deadlines, stakeholders, and team members. Ability to work in person from Richmond, VA . Willingness to attend in‑person meetings with internal teams, clients, and leadership as required. Preferred Qualifications Prior experience in a consulting, advisory, MSSP, vCISO, CPA firm, audit firm, cybersecurity firm, or compliance services environment. Experience with GRC platforms such as Vanta, Drata, Secureframe, Hyperproof, AuditBoard, OneTrust, or similar tools. Experience with additional frameworks such as HIPAA, HITRUST, NIST CSF, NIST800‑53, NIST800‑171, CMMC, PCIDSS, GDPR, CIS Controls, or privacy/security requirements for SaaS companies. Experience advising startups, SaaS companies, technology companies, fintech companies, healthcare companies, or mid‑market organizations. Familiarity with AWS, Azure, Google Cloud, identity providers, endpoint security tools, vulnerability management tools, ticketing systems, and security monitoring platforms. Relevant certifications such as CISA, CISSP, CRISC, CISM, ISO27001 Lead Implementer, ISO27001 Lead Auditor, Security+, or similar. Ideal Candidate Profile The ideal candidate is a strong consultant, manager, and security advisor. This person knows how to help clients make good security decisions without overwhelming them with unnecessary complexity. You should be able to walk into a client environment, quickly understand their business, assess their compliance and security needs, and tell them what matters most. You should know how to guide clients through SOC2, ISO27001, and broader security program development in a way that is practical, credible, and aligned with the client’s stage of growth. You should also be a strong people manager. This role requires someone who can lead a team, review work, improve delivery quality, coach junior team members, and create repeatable consulting processes. This is not just a documentation role or an audit coordination role. We are looking for someone who can act as a true vCISO: someone who can advise clients, manage risk, guide security strategy, lead a team, and help clients build security and compliance programs they can actually operate. Compensation The base salary for this role is $125,000 per year . Additional compensation, benefits, bonus eligibility, and other incentives may be provided depending on company policy and candidate qualifications. Work Location This is an in‑person role based in one of the following locations: Richmond, Virginia Candidates must be able to work in person from one of these locations and collaborate directly with clients, internal teams, auditors, and external stakeholders. We believe in rewarding hard work with meaningful perks that support your growth, health, and well‑being. 10 days of paid time off (PTO) 11 paid federal holidays 401(k) with 4% company match Monthly healthcare stipend Weekly team lunches and in‑office snacks #J-18808-Ljbffr
- ...Achilleion, based in Richmond, Virginia, is seeking a Senior vCISO / GRC Consulting Manager to lead client engagements in cybersecurity and compliance. The role requires at least 6 years of experience in GRC and cybersecurity, along with 4 years in a management position...Senior
- ...Agency Cyber Inc in Richmond, VA, is looking for a Senior vCISO / GRC Consulting Manager to lead cybersecurity engagements and manage client relationships. This role requires a strong background in GRC, with at least six years of relevant experience and a proven ability...Senior
- ...A leading global consulting firm is seeking a Senior Consultant for its Risk Technology practice, focusing... ...involves assessing and implementing risk management strategies, leading project teams,... ...a related field and experience with GRC principles. This position offers a...Senior
- ...A leading global consulting firm is seeking a Senior Project Manager to drive US Federal business growth, particularly for the US Army Corps of Engineers. This role involves leading delivery teams, managing client relationships, and supporting business development initiatives...Senior
- ...Job Description Job Description Tax Senior Manager - Private Client Services Due to recent growth in our Private Client Services... ...At least five years of experience in public accounting, tax consulting, or other related experience › Ability to develop relationships...Senior
- ...A leading archaeological consulting firm is seeking a Senior Archaeologist to manage Phase I-III fieldwork and conduct archaeological research in Virginia and surrounding areas. The ideal candidate should have a Master’s degree in anthropology, over 8 years of experience...Senior
$133.3k - $200k
...A leading consulting firm is seeking a Conveyance Sr. Project Manager to lead water infrastructure projects. Ideal candidates must have a Bachelor's degree in Engineering and 15+ years of relevant experience. The role involves managing teams, business development, and...Senior- ...A leading consulting firm is seeking a Conveyance Sr. Project Manager in Virginia. The role involves managing wastewater infrastructure projects, mentoring engineers, and leading client relations. Candidates should have over 15 years of experience in project management...Senior
- ...Job Description Job Description Tiger Analytics is looking for experienced Senior Consultant/ Manager to join our fast-growing advanced analytics consulting firm. We are the trusted analytics partner for multiple Fortune 500 companies, enabling them to generate...SeniorLocal area
$105.56k - $247.9k
...Ranked among the largest accounting and consulting firms in the country and consistently recognized as a Great Place to Work ( , Cherry... ...Advisory ( practice, an opportunity has been created for a Senior Manager to join our high performing team with the flexibility to sit...SeniorWork experience placementLocal areaRemote work- UDR Consulting Inc is seeking a Senior Project Controls Specialist for its Glen Allen, VA office. The role requires a Bachelor's Degree in Engineering or Construction Management along with 7 years of direct project controls experience. Key responsibilities include leading...SeniorWork at office
- A leading consulting firm seeks a Digital Project Manager to manage multiple technical projects. The ideal candidate will have over 8 years of experience, spearheading software solutions and collaborating with clients. Responsibilities include defining project scope, leading...Senior
- ...Johnson, Mirmiran & Thompson is a dynamic, 100% employee-owned consulting firm of more than 2,300 professionals that provides a full... ...manpower requirements and prepares invoices. Develop Project Management plans for assigned projects Establish project pricing and budgets...SeniorContract workWork at officeLocal area
$8k
...Doing... With your sales experience, ability to efficiently manage your time, excellent customer relations skills, and excitement... ...prospecting for new business or growing existing accounts, you'll consult with customers to identify their business challenges and...SeniorTemporary workWork experience placementShift work$112k - $251.6k
...Description Oracle Health is seeking a highly motivated Senior Manager for Fed Edge & Analytics with a strong technical foundation... ...maintenance. This leader will manage a specialized team of consultants and consulting software developers responsible for delivering...SeniorTemporary workFlexible hours$171.6k - $392.1k
...better working world. ServiceNow – ServiceNow AI Architect Senior Manager In the digital economy, it takes more than good ideas... ...efficient solutions for business decision-making. As a ServiceNow Consulting Senior Manager you will play a leading role in that mission,...SeniorSummer holidayWorldwideFlexible hours- ...infrastructure and our expertise in engineering, procurement, consulting and construction, together we are building a world of difference... .... Our revenues exceed $3 billion. The Sr. Project Manager position is a high-profile leadership role at Black & Veatch....SeniorFull timeContract workPart timeWork experience placementWork at officeLocal areaRemote workRelocationVisa sponsorshipFlexible hours2 days per week3 days per week
$108k - $175k
...About the job Tax Manager / Senior Manager - Private Client Services Pay: $108,000.00 - $175,000.00 per year Why This Is a... ...businesses, owners, and nonprofits with tax, audit, accounting, consulting, transaction advisory, valuation, forensic, and private...SeniorFull timePrivate practiceWork at officeRemote workRelocation packageFlexible hours- ...BELIEVE in what they're doing! Job Description Summary: As a Senior Project Manager at Rocket Software, you will lead the delivery of... ...you will collaborate with diverse stakeholders, including consultants, software engineers, end users, sales teams, and senior leadership...SeniorWorldwide
$27.07 - $54.13 per hour
...Job Description Job Description: Federal Project Manager - Critical Support Company Overview: We're on a journey to advance how health happens with technologies that support clinicians, inspire innovation, empower patients, and save lives. Our mission? To create...SeniorHourly payTemporary workWork at officeFlexible hours- ...Company Description CapTech is an award-winning consulting firm that collaborates with clients to achieve what's possible through... ...captechconsulting.com. Job Description The Technical Project Manager role at CapTech is multi-faceted by the very nature of the...SeniorWork at officeRemote workVisa sponsorshipWork visaFlexible hours
- ...Senior Validation Project Lead/Manager Compli, LLC was founded in 2001 to provide Commissioning, Validation and Regulatory Support Services to the... ...Compli is a full service engineering contracting and consulting services company with a life sciences division specializing...SeniorFor contractorsLocal area
- ...As perceptive partners, our U.S-based consultants find inspiration in the unknown and enjoy... ...helps each organization use technology, management, and insight to turn ideas into action.... ...you to succeed as a highly consultative senior management advisor or to drive highly visible...SeniorWork at officeImmediate startRemote workVisa sponsorshipWork visaFlexible hours
- ...Assistant General Counsel, Technology and Managed Services - Senior Manager Location: Anywhere in Country At EY, we’re all in to shape... ...Experience in a managed services counsel role in a technology or consulting organization with experience leading negotiations ~ A...SeniorFull timeSummer holidayLocal areaImmediate startFlexible hours
$91.4k - $187k
...North America and India. We’re growing fast, and we need consultants ready to bring their unique skills, energy, and creativity... ...applications projects. The role of a Cloud Consulting Senior Project Manager requires an experienced project management professional with...SeniorTemporary workFlexible hours$225.4k - $257.2k
...Senior Manager, Information Security Office Consultant At Capital One, you will help consult on initiatives, programs, and projects to raise their game in Information Security. You are pragmatic and practical in your understanding of risk and security, but also willing...SeniorFull timePart timeH1bWork at officeLocal areaShift work- ...Tiger Analytics is an advanced analytics consulting firm recognized for our deep expertise... ...currently looking for a Sr. Consultant/Manager to join our team and contribute to transformative... ...Prepare and present detailed reports to senior leadership, highlighting model...SeniorLocal area
$143k - $243k
Prime Therapeutics is seeking a Senior Principal Actuary to provide actuarial direction and strategic consulting. This remote position will innovate pricing strategies and lead actuarial staff. The ideal candidate will have 10 years of actuarial experience, a relevant...SeniorRemote work$170.6k - $390k
...working world. Join EY’s Cybersecurity consulting practice – the best place in the world... ...information security! The opportunity The Senior Network Security Architect is a... ...Join our dynamic team as a Senior Manager in Cybersecurity Engineering, where you...SeniorSummer holidayRemote workFlexible hours- ...A global engineering consultancy is seeking a skilled commissioning engineer in Richmond, Virginia, to lead technically challenging projects. This position focuses on engineering design reviews, testing, and performance investigations of mechanical, electrical, and plumbing...Senior
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Senior vCISO / GRC Consulting Manager. Be the first to apply!


