← All jobs
Programming.com

Virtual Chief Information Security Officer (vCISO)

MH, INOn-siteVpvia jobspy_indeed
cybersecurityrisk managementcompliancegovernanceiso 27001nistincident responsesecurity strategy

Observed pay for security engineer jobs in the united states

Among 19 openings that publish compensation, the median stated annual range is $100K–$150K USD. This uses observed listing data across 274 live jobs, never an estimated salary.

Don't apply into the void.

Most applications for this Programming.com role vanish into an ATS. With jobfinder-ai, your agent finds the actual hiring manager or founder behind this opening and sends a tailored email from your own inbox — so a real person reads your pitch and replies. We then follow up until you land on the calendar.

Reach the decision-maker — $5

View original posting →

The Virtual Chief Information Security Officer (vCISO) is responsible for providing strategic cybersecurity leadership, governance, risk management, compliance oversight and advisory services to the organization. The role serves as a trusted security advisor to executive leadership, ensuring that information security initiatives align with business objectives, regulatory requirements, and industry best practices while enhancing the organization's overall security posture.

**Key Responsibilities**

* Develop, implement, and maintain the organization's enterprise\-wide cybersecurity and information security strategy. * Provide executive\-level security guidance, recommendations, and periodic reporting to senior management and stakeholders. * Establish and drive the long\-term cybersecurity roadmap aligned with business goals and emerging threats. * Advise leadership on security investments, priorities, and risk\-based decision making. * Ensure compliance with applicable security frameworks, standards, and regulations, including ISO 27001, NIST, IT Act, and other relevant requirements. * Conduct enterprise\-wide information security risk assessments and maintain the organizational risk register. * Develop, review, and enforce information security policies, standards, procedures, and governance frameworks. * Strong domain knowledge of Network security, Risk control, IAM, Encryption, Zero trust, Security operations, vulnerability management, Incident response etc. * Support internal and external audits and ensure continuous compliance readiness. * Develop and oversee incident response plans, processes, and coordination activities. * Identify, assess, and mitigate cybersecurity risks across the organization. * Provide guidance on threat intelligence, vulnerability management, security monitoring, and emerging cyber threats. * Act as a key advisor during major security incidents and crisis management situations. * Lead and oversee cybersecurity programs, initiatives, resources, and security teams. * Establish security governance forums, steering committees, and reporting mechanisms. * Define and monitor security KPIs, KRIs, metrics, and maturity improvement programs. * Drive continuous improvement of the organization's cybersecurity capabilities and resilience. * Design and conduct enterprise\-wide security awareness and education programs. * Develop role\-based cybersecurity training initiatives for employees and leadership teams. * Plan and execute phishing simulation campaigns and measure effectiveness. **Foster a security\-conscious culture across the organization.** Conduct and oversee third\-party and vendor security risk assessments. * Establish security requirements and controls for suppliers, vendors, and service providers. * Evaluate supply chain cybersecurity risks and recommend mitigation measures. **Support procurement and contract reviews from a cybersecurity perspective.** * Review and assess the security of infrastructure, applications, endpoints, networks, and cloud environments. * Provide strategic and technical recommendations to enhance security controls and architecture. * Oversee security audits, vulnerability assessments, and penetration testing activities. * Advise on implementation of industry best practices and security technologies. * Conduct Operational Technology (OT) security assessments and maturity reviews. * Provide guidance on the implementation of OT\-specific security controls and frameworks. * Identify and mitigate cybersecurity risks in industrial control systems (ICS), SCADA, and OT environments. * Support secure integration between IT and OT environments.

**Required Qualifications**

* Bachelor’s degree in information security, Cybersecurity, Computer Science, Information Technology, or a related field. * Minimum 8\-10 years of experience in information security, cybersecurity, risk management, or IT leadership roles. * Proven experience in a CISO, Deputy CISO, Security Director, or vCISO capacity. * Strong understanding of security frameworks such as ISO 27001, NIST CSF, CIS Controls, COBIT, and regulatory compliance requirements. * Experience in risk management, incident response, security governance, cloud security, and third\-party risk management. * Knowledge of OT/ICS security principles and industrial cybersecurity practices.

**Preferred Certifications**

* CISSP (Certified Information Systems Security Professional) * CISM (Certified Information Security Manager) * CRISC (Certified in Risk and Information Systems Control) * ISO 27001 Lead Implementer / Lead Auditor * CCSP (Certified Cloud Security Professional) * GIAC / GICSP (for OT Security)

**Key Competencies**

* Strategic Leadership * Cybersecurity Governance * Risk Management * Stakeholder Management * Regulatory Compliance * Incident Response \& Crisis Management * Security Architecture \& Cloud Security * Third\-Party Risk Management * OT Security Expertise * Communication \& Executive Reporting * Program \& Team Management

**Reporting To:** Executive Management / Board / CIO / CEO (as applicable) **Employment Type:** Full\-Time / Consulting / Managed Security Services Engagement (as applicable)

Location: Pune

Pay: ₹258,055\.12 \- ₹1,400,000\.53 per year

Work Location: In person

Set this role as a target and your agent does the sourcing, finds the verified email, writes the pitch, and follows up — on autopilot.

Start your hunt