Agencycyber
Senior vCISO / GRC Consulting Manager
Richmond, VA · Senior · Full-time
Sponsorship not specified$171k-$800kDetected 26 days ago
AWSGCPAzureCloud PlatformsCybersecurityIncident ResponseComplianceProject ManagementAuditingProcurementHIPAALeadershipCommunicationInternal Audit
About the role
- About Agency Cybersecurity: Agency Cybersecurity is fast growing ventured back startup that provides best-in-class cybersecurity and compliance.
- Our software and services simplify complex compliance frameworks including SOC2, ISO 27001, HIPAA, and others, empowering businesses to scale securely and confidently.
- We're backed by top tier investors like Y Combinator and have offices in NYC, Boston, Richmond, and London.
Responsibilities
- Advise clients on security program design, risk prioritization, compliance strategy, policy development, and control implementation.
- Lead client meetings, executive briefings, audit readiness sessions, and risk review discussions.
- GRC and Compliance Program Delivery Lead client engagements related to SOC 2, ISO 27001, and other audited security frameworks.
- Develop and manage compliance roadmaps, audit readiness plans, and remediation timelines for clients.
- Guide clients through the full lifecycle of compliance readiness, including scoping, gap assessments, control implementation, evidence collection, audit support, and ongoing maintenance.
- Audit Readiness and Framework Management Lead SOC 2 Type 1 and Type 2 readiness initiatives for clients.
- Support ISO 27001 implementation, certification preparation, surveillance audit readiness, and continuous improvement.
- Help clients understand audit findings and develop clear plans to address gaps.
- Maintain strong working knowledge of SOC 2 Trust Services Criteria, ISO 27001 requirements, and common security control expectations.
- Team Management and Delivery Oversight Manage a team of GRC consultants, analysts, and implementation resources.
Requirements
- Minimum 6 years of professional experience in GRC, cybersecurity compliance, security advisory, audit readiness, IT risk, internal audit, or a related field.
- Minimum 4 years of management or team leadership experience.
- Experience managing client-facing consulting engagements or advisory relationships.
- Strong understanding of security controls, risk management, compliance frameworks, and audit processes.
- Experience leading or supporting external audits, including evidence collection, control testing, auditor communications, and remediation.
- Ability to explain complex security and compliance concepts to executives, founders, technical teams, and non-technical stakeholders.
- Ability to work in person from Richmond, VA.
- Willingness to attend in-person meetings with internal teams, clients, and leadership as required.
Nice to have
- Prior experience in a consulting, advisory, MSSP, vCISO, CPA firm, audit firm, cybersecurity firm, or compliance services environment.
- Experience with GRC platforms such as Vanta, Drata, Secureframe, Hyperproof, AuditBoard, OneTrust, or similar tools.
- Experience with additional frameworks such as HIPAA, HITRUST, NIST CSF, NIST 800-53, NIST 800-171, CMMC, PCI DSS, GDPR, CIS Controls, or privacy/security requirements for SaaS companies.
- Familiarity with AWS, Azure, Google Cloud, identity providers, endpoint security tools, vulnerability management tools, ticketing systems, and security monitoring platforms.
- Ideal Candidate Profile The ideal candidate is a strong consultant, manager, and security advisor.
- This person knows how to help clients make good security decisions without overwhelming them with unnecessary complexity.
- You should be able to walk into a client environment, quickly understand their business, assess their compliance and security needs, and tell them what matters most.
- You should know how to guide clients through SOC 2, ISO 27001, and broader security program development in a way that is practical, credible, and aligned with the client's stage of growth.
Skills
- Agency Cybersecurity is fast growing ventured back startup that provides best-in-class cybersecurity and compliance.
Compensation
- $125,000 base salary About the Role We are seeking a Senior vCISO / GRC Consulting Manager to lead client-facing cybersecurity, governance, risk, and compliance engagements for organizations pursuing or maintaining security frameworks such as NIST 800-171, 800-53, or CMMC.
- As well as experience with SOC 2, ISO 27001, and related trust and security standards.
- This is an in-person consulting leadership role based in Richmond, VA.
- The Senior vCISO will work directly with clients, internal delivery teams, and company leadership to provide hands-on advisory support, manage GRC engagements, and lead a team responsible for delivering high-quality cybersecurity and compliance services.
- The Senior vCISO will serve as a strategic advisor to clients, helping them understand their security and compliance obligations, prioritize risk, prepare for audits, implement practical controls, and build scalable security programs.
- This person will also manage a team of GRC consultants, analysts, and implementation specialists responsible for delivering client work.
- Compensation The base salary for this role is $125,000 per year.
Benefits
- Additional compensation, benefits, bonus eligibility, and other incentives may be provided depending on company policy and candidate qualifications.
- Benefits We believe in rewarding hard work with meaningful perks that support your growth, health, and well-being.
- 10 days of paid time off (PTO) 11 paid federal holidays 401(k) with 4% company match Monthly healthcare stipend Gym membership stipend Weekly team lunches and in-office snacks
Apply directly at Agencycyber →Create a free account for alerts like thisView Agencycyber immigration profile
This listing is sourced directly from Agencycyber's careers page and normalized into a canonical job model.