Virtual Chief Information Security Officer (vCISO)
About the role
Ntiva is a Managed Services Provider that values growth, innovation, and teamwork. We are a community dedicated to helping each other, our clients, and their businesses thrive both personally and professionally. We are seeking a vCISO to serve as a fractional security leader and trusted advisor to Ntiva's GovCon clients.
Responsibilities
- Serve as the fractional security leader for a portfolio of GovCon clients, setting security program direction, building and maintaining multi-year security roadmaps, and reporting risk and progress to client leadership in clear business terms.
- Lead client risk management: conduct and interpret risk assessments, maintain risk registers, and drive risk-based prioritization of remediation and security investment.
- Own ongoing compliance assurance across client programs, continuous control monitoring, periodic reassessment, and evidence maintenance, keeping SPRS scores, SSPs, and POA&Ms current and defensible between formal assessments.
- Lead CMMC Level 2 and NIST 800-171 readiness for clients: scope the environment, direct gap assessments, and guide remediation from findings through validated closure. (Ntiva prepares and maintains clients for certification; it is not a C3PAO and does not perform the certifying assessment.)
- Technically validate control implementation, review configurations across identity, endpoint, network, cloud (Microsoft 365 / Azure), and logging to confirm NIST 800-171 controls are actually in place and effective, not just documented on paper.
- Advise on security architecture and tooling, identity, endpoint, network/firewall, and logging/monitoring, partnering with Engineering and Delivery on designs and controls that make compliance scalable and sustainable.
- Provide security leadership during events and incidents: guide client response, oversee containment and remediation, and ensure applicable reporting obligations (e.g., DFARS 252.204-7012) are met.
- Develop and maintain client security governance, policies, standards, and procedures aligned to NIST 800-171 and client contractual requirements.
- Support Sales and Account Management as the senior security voice in prospective and existing client discussions, including client calls, strategy sessions, and proposal development.
- Escalate critical security and compliance risks to GovCon leadership with clear business impact and recommended actions.
- Contribute to Ntiva’s security and compliance go-to-market strategy and to the standardization, documentation, and maturity of the GovCon service stack.
Requirements
- 5+ years in cybersecurity, security consulting, or IT compliance with a strong technical foundation, including client-facing advisory experience serving as the senior security voice for client leadership.
- Hands-on experience leading CMMC Level 2 / NIST 800-171 readiness engagements end to end, scoping, control assessment, POA&M management, remediation tracking, and evidence and audit documentation.
- Strong hands-on command of the security stack, identity and access management (Microsoft Entra ID / Azure AD, MFA, conditional access), endpoint protection (EDR/MDR), network and firewall controls, SIEM/log management, vulnerability management, and email security.
- Working knowledge of Microsoft 365 and Azure security, including government cloud (GCC / GCC High), FIPS-validated encryption, and CUI protection as they apply to DFARS and NIST 800-171.
- Ability to read and evaluate system configurations and technically validate that controls are implemented and effective, not just documented on paper.
- Ability to translate technical risk into business-level guidance for client executives and working knowledge of risk management within a managed-services delivery model.
- Background in IT consulting, managed services (MSP), cybersecurity, or compliance advisory services.
- Experience supporting GovCon clients and navigating federal regulatory requirements (CMMC, DFARS, NIST 800-171).
- Experience accurately tracking and documenting billable time in a client-facing consulting or managed-services environment.
- Strong documentation and communication skills for both technical and executive audiences.
Qualifications
- Technical security certifications such as CompTIA Security+, Microsoft SC-200 / SC-300 / SC-100, or Azure Security Engineer (AZ-500).
- CISSP, CISM, or an equivalent senior security certification.
- CMMC Registered Practitioner (RP/RPA), CCP, or CCA designation.
- Hands-on experience implementing or hardening Microsoft 365 GCC High / Azure Government environments.
- Experience working with or for an IT/Managed Service Provider (MSP).
- Scripting or automation experience (e.g., PowerShell) for security configuration and validation.
- Experience participating in or preparing clients for C3PAO assessments.
- Experience building or maturing a security program from the ground up.
- Experience supporting sales cycles, including proposal development and compliance-focused client discussions.
- Experience contributing to go-to-market strategy, service standardization, and cross-functional enablement, including developing repeatable messaging, playbooks, and training for security and compliance programs.
Skills
- Communication skills, both written and oral.
- Writing business correspondence and process procedures.
- Presenting information and responding to questions from groups of managers, clients, and the general public.
Benefits and Perks
- Medical, Dental and Vision coverage for employee and family.
- 401k + company-matched contributions 4% match on 5% contribution- no vesting period!
- Group Term Life and Accidental Death and Dismemberment coverage (company provided).
- Short-Term (voluntary enrollment) and Long-Term Disability coverage (company provided).
- Health Savings Account (HSA) Options / PPO Options.
- Employee Assistance Program.
- Paid Time Off (PTO) + Volunteer Time Off (VTO) + 8 Paid Holidays + 3 Floating Holidays.
- Education Reimbursement Program.
- Generous Employee Referral Program - cash bonus for successful referrals!
- Dynamic Recognition and Rewards.
- Clear Promotion and Advancement Tracks.
Pay
The base pay range for this position is expected to be between $100,000 and $140,000 per year. The base pay offered may vary depending on multiple non-discriminatory factors including, but not limited to, market location, job-related knowledge, skills, and experience.
Schedule
This is a hybrid role with approximately 10% on-site work at client locations. We are seeking candidates located in either the Chicago or Kansas City areas. The specific allocation of remote versus onsite requirements may fluctuate based on business needs.
Location
Mondays-Fridays, 8am-5pm CST.