Applying to be a CISO for a Fractional CISO Enterprise client.

CISO in a video call with a CTO.

Fractional CISO’s core business is catering to mid-market companies.

However, we get a handful of opportunities each year where the client is a large enterprise.

They often want us to take over their security program because…

  1. They just had a huge incident
  2. Their CISO unexpectedly departed
  3. Their CISO is about to unexpectedly depart

These opportunities often need to be acted on in days.

What characteristics are we looking for in an exceptional Enterprise CISO?

  1. Enterprise CISO experience from a large, well-known organization.
  2. Someone who is 2+ standard deviations above the average CISO’s intelligence. 
  3. Someone with a mastery of executive presence / communication skills for senior leadership and the board of directors.

Wow, that sounds like there are only a small number of people who might qualify!

Right.

What about industry specific knowledge?

Obviously that is valuable. In our experience, the above criteria trumps other considerations.

How do we deliver the service?

Our Enterprise CISO’s bill hourly. Typically, we agree to a range of hours for a given week. Often 10 – 20 hours.

The Enterprise CISO will work remotely, but we have found that it makes sense for the CISO to visit the in-person for approximately three days, two or three times in the beginning of the engagement. The visits helps to cement the relationship between the CISO and the client. The rest of the work is remote unless otherwise specified.

In addition, we provide a skilled cybersecurity analyst that will assist the CISO remotely to provide a number of services that, we have found, CISOs don’t necessarily like doing themselves. Additionally, the analyst will be a catalyst for interactions with Fractional CISO corporate for whatever cybersecurity stuff the CISO might need. Example services that the cybersecurity analyst might provide are the following:

The analyst also has access to Fractional CISO’s library of templates and can facilitate further help from other Fractional CISO team members who have expertise in a variety of fields.

Additionally, the CISO will be given an administrative point of contact with Fractional CISO that can solve administrative problems such as time sheet issues. (Although our time sheet process seems to be really smooth! We rarely, if ever, get complaints.)

Agreement / Contractor logistics

Fractional CISO hires the CISO as a 1099 contractor. 

We pay the CISO through our payroll system, which can pay contractors. Payments follow our payroll cycle which is every two weeks. The CISO needs to make sure that his/her hours are entered correctly.

The CISO is responsible for his/her taxes. 

Am I allowed to do this work on the side of my regular job?

From our perspective, yes! If you can meet your obligations to our client, and your current employer does not bar you from moonlighting.

What rate does Fractional CISO pay?

We do our best to get a market rate from the client.

The CISO typically gets roughly 2/3rds of the fee with Fractional CISO getting the rest. Sometimes, this is below what the CISO would like. That is the way it works though. Our team provides the CISO assistance. We have expenses too!

Can the CISO get subsequent work from us?

If you do a great job then yes! We have brought multiple projects to the same CISOs in the past, though we can’t make promises about availability of future work.

Do I have to be / get to be on the Fractional CISO website?

No, you don’t have to be. Yes, you can be. It is up to you.

When does the CISO  get more details about the client?

In our initial conversations we will speak generally about the opportunity, but will not share identifying details about the client.

This is because our enterprise clients are often in the middle of an incident, or are in the process of letting their existing CISO go. We want to make sure that the candidate is through a significant portion of the interview process before we share these types of confidential details.

Is the Master Service Agreement onerous?

No, CISOs don’t typically have an issue with the agreement. You are welcome to have your attorney review it.

Interview process

Our interview process generally goes something like this, although the order and the required steps sometimes change slightly.

  1. Interview with VP of Business Operations
  2. Interview with CEO
  3. Take Berke behavioral and cognitive assessment. It takes less than an hour.  – https://www.highmatch.com/berke-assessment/
  4. Agree on hourly rate
  5. Execute Master Service Agreement. 
  6. Criminal background check.
  7. Reference check.
  8. Interview with client if client desires.
  9. Execute Work Order.
  10. Start work.

Application Form

© 2025 All rights reserved​

Is your Cyber Insurance really going to cover you?

Only 1/3 of cyber insurance policies actually pay out in incidents. Most companies have cyber insurance policies that insure too little, or too much, and have absurdly low caps and silly exclusions.

To learn more about cyber insurance and determine if you have the right coverage for you, join us for a free vCISO Office Hours session on Tuesday, April 18 at 1 p.m. eastern time. Bring your questions!

New Release: Free SOC 2 eBook!

Getting ready for your first SOC 2? This eBook is full of actionable advice to help you prepare for and succeed in your first SOC 2 audit.

Learn:

  • How to scope your SOC 2 project
  • How to estimate the cost and length of your SOC 2 project
  • How to prepare for your SOC 2
  • How to succeed in your SOC 2 audit period
  • How to leverage your SOC 2 report to enable your business and sales