Agencycyber

Agencycyber

Senior vCISO / GRC Consulting Manager

Richmond, VA · Senior · Full-time

Sponsorship not specified$171k-$800kDetected 26 days ago
AWSGCPAzureCloud PlatformsCybersecurityIncident ResponseComplianceProject ManagementAuditingProcurementHIPAALeadershipCommunicationInternal Audit

About the role

  • About Agency Cybersecurity: Agency Cybersecurity is fast growing ventured back startup that provides best-in-class cybersecurity and compliance.
  • Our software and services simplify complex compliance frameworks including SOC2, ISO 27001, HIPAA, and others, empowering businesses to scale securely and confidently.
  • We're backed by top tier investors like Y Combinator and have offices in NYC, Boston, Richmond, and London.

Responsibilities

  • Advise clients on security program design, risk prioritization, compliance strategy, policy development, and control implementation.
  • Lead client meetings, executive briefings, audit readiness sessions, and risk review discussions.
  • GRC and Compliance Program Delivery Lead client engagements related to SOC 2, ISO 27001, and other audited security frameworks.
  • Develop and manage compliance roadmaps, audit readiness plans, and remediation timelines for clients.
  • Guide clients through the full lifecycle of compliance readiness, including scoping, gap assessments, control implementation, evidence collection, audit support, and ongoing maintenance.
  • Audit Readiness and Framework Management Lead SOC 2 Type 1 and Type 2 readiness initiatives for clients.
  • Support ISO 27001 implementation, certification preparation, surveillance audit readiness, and continuous improvement.
  • Help clients understand audit findings and develop clear plans to address gaps.
  • Maintain strong working knowledge of SOC 2 Trust Services Criteria, ISO 27001 requirements, and common security control expectations.
  • Team Management and Delivery Oversight Manage a team of GRC consultants, analysts, and implementation resources.

Requirements

  • Minimum 6 years of professional experience in GRC, cybersecurity compliance, security advisory, audit readiness, IT risk, internal audit, or a related field.
  • Minimum 4 years of management or team leadership experience.
  • Experience managing client-facing consulting engagements or advisory relationships.
  • Strong understanding of security controls, risk management, compliance frameworks, and audit processes.
  • Experience leading or supporting external audits, including evidence collection, control testing, auditor communications, and remediation.
  • Ability to explain complex security and compliance concepts to executives, founders, technical teams, and non-technical stakeholders.
  • Ability to work in person from Richmond, VA.
  • Willingness to attend in-person meetings with internal teams, clients, and leadership as required.

Nice to have

  • Prior experience in a consulting, advisory, MSSP, vCISO, CPA firm, audit firm, cybersecurity firm, or compliance services environment.
  • Experience with GRC platforms such as Vanta, Drata, Secureframe, Hyperproof, AuditBoard, OneTrust, or similar tools.
  • Experience with additional frameworks such as HIPAA, HITRUST, NIST CSF, NIST 800-53, NIST 800-171, CMMC, PCI DSS, GDPR, CIS Controls, or privacy/security requirements for SaaS companies.
  • Familiarity with AWS, Azure, Google Cloud, identity providers, endpoint security tools, vulnerability management tools, ticketing systems, and security monitoring platforms.
  • Ideal Candidate Profile The ideal candidate is a strong consultant, manager, and security advisor.
  • This person knows how to help clients make good security decisions without overwhelming them with unnecessary complexity.
  • You should be able to walk into a client environment, quickly understand their business, assess their compliance and security needs, and tell them what matters most.
  • You should know how to guide clients through SOC 2, ISO 27001, and broader security program development in a way that is practical, credible, and aligned with the client's stage of growth.

Skills

  • Agency Cybersecurity is fast growing ventured back startup that provides best-in-class cybersecurity and compliance.

Compensation

  • $125,000 base salary About the Role We are seeking a Senior vCISO / GRC Consulting Manager to lead client-facing cybersecurity, governance, risk, and compliance engagements for organizations pursuing or maintaining security frameworks such as NIST 800-171, 800-53, or CMMC.
  • As well as experience with SOC 2, ISO 27001, and related trust and security standards.
  • This is an in-person consulting leadership role based in Richmond, VA.
  • The Senior vCISO will work directly with clients, internal delivery teams, and company leadership to provide hands-on advisory support, manage GRC engagements, and lead a team responsible for delivering high-quality cybersecurity and compliance services.
  • The Senior vCISO will serve as a strategic advisor to clients, helping them understand their security and compliance obligations, prioritize risk, prepare for audits, implement practical controls, and build scalable security programs.
  • This person will also manage a team of GRC consultants, analysts, and implementation specialists responsible for delivering client work.
  • Compensation The base salary for this role is $125,000 per year.

Benefits

  • Additional compensation, benefits, bonus eligibility, and other incentives may be provided depending on company policy and candidate qualifications.
  • Benefits We believe in rewarding hard work with meaningful perks that support your growth, health, and well-being.
  • 10 days of paid time off (PTO) 11 paid federal holidays 401(k) with 4% company match Monthly healthcare stipend Gym membership stipend Weekly team lunches and in-office snacks

This listing is sourced directly from Agencycyber's careers page and normalized into a canonical job model.