What are the responsibilities and job description for the vCISO Consultant position at Reactforce?
Virtual Chief Information Security Officer (vCISO) - 1099 Independent Contractor
Reactforce | Remote / Client-Facing | Contract
Reactforce is expanding our Managed CISO practice and is seeking an experienced Virtual Chief Information Security Officer (vCISO) to work directly with our clients as a trusted cybersecurity and risk advisor.
This is not a behind-the-scenes consulting position. We are looking for someone who combines strong CISO-level technical, governance, risk, and compliance expertise with an exceptional client-facing personality. You must be comfortable working with executives, boards, IT teams, security teams, auditors, and business leaders.
The right person is highly professional, confident, responsive, organized, and self-sufficient. You should be able to take ownership of client engagements with minimal oversight while representing Reactforce at an executive level.
What You'll Do
• Serve as the fractional or virtual CISO for assigned Reactforce clients
• Develop and manage cybersecurity strategies, roadmaps, and security programs
• Advise executive leadership and boards on cybersecurity, technology risk, and business risk
• Conduct cybersecurity and risk assessments and translate findings into actionable remediation plans
• Develop and maintain security policies, standards, governance structures, and security programs
• Lead or advise incident response planning, tabletop exercises, and security incident management
• Oversee vulnerability management, penetration testing, security operations, SIEM, EDR, and related security capabilities
• Support third-party and vendor risk management programs
• Assist clients with cybersecurity insurance requirements and security questionnaires
• Provide security architecture and control recommendations
• Track cybersecurity risks, remediation activities, metrics, and KPIs
• Prepare and deliver executive and board-level cybersecurity reporting
• Work with client IT teams, MSPs, MSSPs, SOC providers, auditors, legal teams, and other third parties
• Lead client meetings and maintain strong, trusted client relationships
• Help clients prepare for audits, regulatory examinations, and compliance initiatives
Experience We're Looking For
• Significant experience in cybersecurity leadership, preferably as a CISO, Deputy CISO, Director of Security, Security Executive, or experienced vCISO
• Strong knowledge of cybersecurity governance, risk management, security operations, incident response, vulnerability management, and security architecture
• Experience with frameworks and regulatory requirements such as NIST CSF, NIST 800-53, NIST 800-171, CMMC, HIPAA, SOC 2, PCI DSS, ISO 27001, and related standards
• Experience developing cybersecurity strategies and multi-year security roadmaps
• Ability to evaluate both technical security issues and their business impact
• Experience communicating cybersecurity risk to executives and boards
• Strong understanding of cloud security, identity and access management, endpoint security, network security, SIEM/SOC operations, vulnerability management, and third-party risk
• Excellent written communication and documentation skills
What Is Critical for This Role
Technical knowledge alone is not enough.
You must be highly client-facing, personable, confident, and able to establish credibility quickly. Our vCISOs become an extension of the client's leadership team.
You must also be self-sufficient. We are looking for professionals who can take an engagement, understand the client's environment, identify priorities, manage deliverables, run meetings, and move the program forward without requiring constant direction.
Preferred Qualifications
CISSP, CISM, CRISC, CCSP, CISA, or similar senior-level cybersecurity certifications are strongly preferred.
Prior consulting, advisory, MSP/MSSP, or fractional CISO experience is highly desirable.
Engagement Structure
This position is offered exclusively as a 1099 independent contractor engagement. It is not a W-2 employment position.
Work will primarily be remote, although occasional client travel may be required depending on the engagement.
About Reactforce
Reactforce provides cybersecurity, technology risk, business resilience, and executive advisory services to organizations across multiple industries. Our approach goes beyond delivering assessments and reports. We become part of our clients' teams and help them build practical, sustainable security and risk programs.
If you have operated at the CISO level, enjoy working directly with clients, and can independently lead cybersecurity programs and executive conversations, we'd like to hear from you.