> Markdown version of [/jobs/ext/572393-virtual-chief-information-security-officer-vciso](https://www.wearedevelopers.com/jobs/ext/572393-virtual-chief-information-security-officer-vciso). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Virtual Chief Information Security Officer (vCISO) - **Company:** cloudIT, LLC - **Location:** Phoenix, AZ, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Cyber Security, PCI Data Security Standards, Security Information and Event Management, Vulnerability Analysis - **Published:** June 20, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=8e0cee494c9300fb ## About the Role Do you have experience in Senior leadership?, 5+ years in information security, with at least 2 years in a leadership or advisory capacity Ability to engage effectively with both IT leaders and non-technical business owners Comfort managing multiple client engagements with competing priorities Experience working with or for an MSP or TSP is a strong plus ## Description As a vCISO at cloudIT, you will serve as a fractional security leader for a portfolio of clients who do not have and cannot afford a full-time CISO. You will work from our Phoenix office, managing multiple client relationships simultaneously, building practical security programs around cloudIT's proven security stack. This role is equal parts strategist, communicator, and trusted advisor. WHAT YOU WILL DO Security Strategy and Leadership Develop and own practical, business-aligned security roadmaps built on cloudIT's security stack Present security posture updates to IT leaders and business owners in clear, actionable terms Track emerging threats and regulatory shifts across healthcare, real estate, financial services, and construction Risk Management Conduct risk and vulnerability assessments calibrated to client environments Prioritize remediation based on business impact, not just severity scores Build realistic risk treatment plans clients can actually execute Compliance and Governance Guide clients through HIPAA, PCI-DSS, CMMC, NIST CSF, and other relevant frameworks Develop right-sized policies and procedures that are actionable, not shelf-ware Conduct periodic audits and gap assessments using cloudIT's toolset Incident Response and Management Build and test incident response plans suited to SMB realities Lead response coordination during incidents, keeping stakeholders informed Drive post-incident improvements supported by cloudIT's monitoring capabilities Security Stack Adoption and Technical Oversight Champion cloudIT's stack including MDR, SIEM, endpoint protection, MFA, and cloud security controls Ensure solutions are implemented correctly and delivering measurable value Assess third-party vendor risk and guide secure procurement decisions Client Relationship Management Manage a portfolio of clients, engaging at the right level for each organization Show up as a trusted partner by proactively communicating risks and celebrating wins Translate complex security concepts into plain language across industries and experience levels ## Related Videos - [GitOps keeps focus on apps, not on infrastructure](https://www.wearedevelopers.com/videos/182-gitops-keeps-focus-on-apps-not-on-infrastructure) - [How to Cause (or Prevent) a Massive Data Breach- Secure Coding and IDOR](https://www.wearedevelopers.com/videos/39-how-to-cause-or-prevent-a-massive-data-breach-secure-coding-and-idor) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Reporting Active Exploits in 24 Hours: Are You Ready for the CRA?](https://www.wearedevelopers.com/videos/100248-reporting-active-exploits-in-24-hours-are-you-ready-for-the-cra) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [System change: restart as developer?](https://www.wearedevelopers.com/magazine/39-system-change-restart-as-developer) - [7 Cloud Computing Trends Coming in 2025 for Developers](https://www.wearedevelopers.com/magazine/412-7-cloud-computing-trends-coming-in-2025-for-developers) - [What’s the Difference between a Junior, Mid, and Senior Developer?](https://www.wearedevelopers.com/magazine/238-what-s-the-difference-between-a-junior-mid-and-senior-developer)