Fractional CISO / vCISO

Pass the security review that’s holding up your deal.

SOC 2 and ISO 27001 readiness, led by a CISSP-certified security leader. Embedded in your team in weeks, not a $200k full-time hire.

Included in every retainer

  • CISSP
  • OSCP
  • AIGP
  • ISO 27001 Lead Auditor (trained)

25+ years hands-on security

Senior-level delivery on every engagement. The lead you meet is the lead you get.

Fig. A · Retainer spec

Fractional, not freelance.

Three things that separate this from hiring a consultant or signing up another vendor.

  • Embedded, not one-and-done
    Ongoing leadership inside your sprint cycles, architecture reviews, and incident response. Not a 200-page report that collects dust.
  • Senior only, always
    Every engagement is hands-on and owned end to end. You work directly with the lead.
  • Security that ships
    We don’t say no, we find the way. Security built into the way your team already works.

Your security team, without the headcount.

Every retainer is built from these. We scope the mix to your stage, your stack, and your compliance pressure. Penetration testing and ISO 27001 are scoped in as deliverables, never upsells.

Security roadmap & posture

A prioritized plan that fits your stage and updates as you grow. We tell you what to fix first, and in what order.

SOC 2 & ISO 27001 readiness

Certification on a timeline that matches yours. We’ve taken a startup through ISO 27001 without slowing down a single sprint.

Vulnerability assessment & penetration testing

OSCP-level offensive testing, scoped into your retainer when you need it. We find what automated scanners miss, before someone else does.

See the testing services and packages

Cloud security & DevSecOps

Security built into your pipeline from the start. It scales with your engineering instead of fighting it.

Incident response & vendor risk

A plan before you need it, expert hands on deck when you do, and a vendor-risk program your enterprise buyers will ask about.

Ship AI without shipping new risk.

We help you adopt it, secure it, and prove it’s governed, the same embedded way we run the rest of your security.

Adopt AI, safely

Put AI to work across the team without the risk. We pick the right tools, set guardrails and access controls, and write an acceptable-use policy your auditors and enterprise buyers will accept.

Secure AI

Ship AI features without new attack surface. We red-team your LLM apps for prompt injection, data leakage, and abuse, and lock down the model and data pipeline behind them.

Govern AI

Governance that satisfies regulators and investors without killing velocity. EU AI Act, ISO 42001, NIST AI RMF, and whatever comes next.

Start with a fixed-scope AI Governance Gap Assessment

The standard operating procedure.

The machinery of an engagement: four named deliverables, produced in this order, by the lead you meet on the first call.

SOP–01

Gap assessment

Artifact · Control-mapped gap report

Your current posture, mapped control-by-control against SOC 2 or ISO 27001: which controls pass, which fail, and which are blocking the deal. It starts in the free consult

SOP–02

Roadmap

Artifact · Prioritized remediation roadmap

Every gap becomes a ranked task with an owner and an order. You see what gets fixed first, and why, before we touch anything.

SOP–03

Embedded cadence

Cadence · Weekly sync + async Slack

The lead joins your Slack and your sprint cycle: policy drafting, vendor reviews, questionnaire turnaround, and remediation guidance, inside the stack you already run.

SOP–04

Audit-ready

Artifact · Evidence pipeline, managed audit

Controls produce evidence continuously, we brief and manage the auditor, and the reporting reads clean to your board and your buyer’s security team.

Fig. B · Operating procedure

From first call to embedded CISO.

No death by RFP. We start with a conversation and embed from there.

  1. 01
    Align
    A free 30-minute call. We learn your stack, your timeline, and your compliance pressure, then tell you honestly if we’re a fit.
  2. 02
    Embed
    We join your team as your fractional CISO. Weekly syncs, async Slack, and direct access to your engineering channel.
  3. 03
    Deliver
    Prioritized roadmap, active remediation guidance, compliance readiness, and incident response. Ongoing, measurable, and aligned to your sprints.

Security leadership, scoped to your stage.

Retainers usually start around $4,000/mo. What you pay depends on how urgent the work is and how much you need us to own. We figure that out on a free consult.

Foundation

For early-stage teams building real security for the first time.

You get a clear plan, the risky stuff fixed, and someone senior to call when you’re not sure.

  • Security roadmap, with the risks ranked
  • Hands-on fixes for the riskiest gaps
  • Cloud and DevSecOps guidance for your stack
  • Slack access, same-day in business hours

Typical involvement · ~10 hrs/mo

Book a consult
Embedded Fractional CISO

For scaling or regulated teams (fintech, healthcare, AI-native) that need security to have a real owner.

A senior security lead who owns it: the program, the board conversations, AI governance. Without the $200k full-time hire.

  • Full program build-out, and we manage the certifications
  • AI governance and the rules that come with it (EU AI Act, ISO 42001)
  • Security reporting your board and investors can follow
  • Priority incident response, 4-hour SLA
  • Embedded in your engineering and leadership meetings

Typical involvement · ~40 hrs/mo

Book a consult

Not sure which one fits? Book a free consult and we’ll work it out together.

Built for teams that build things.

Post-seed to Series B. Ten to a hundred people. Moving fast, with real compliance pressure.

SaaS Startups

Ship fast, stay secure.

Fintech & Finance

Trust is the product.

Healthcare Tech

Patient data, protected.

AI-Native Companies

Govern what you build.

Selected outcomes.

SECURIQUE is new. The track record behind it isn’t: 25+ years of doing this work.

  • Led ISO 27001 certification to completion inside a cloud-first startup on an aggressive timeline, without slowing a single sprint.

  • Built DevSecOps programs embedded directly into engineering workflows, so security kept pace with the team rather than slowing it down.

  • Ran OSCP-level offensive assessments across SaaS and fintech to surface the scanner-blind spots before someone else did.

Finding record · What you receive

Client
Cloud-first SaaS, post-seed
Trigger
Enterprise security review stalling the deal
Finding
Access-control gap, invisible to the automated scanner
Disposition
Remediated, evidence filed for audit

Sanitized composite, generalized from real engagements. Client-identifiable detail never leaves the engagement.

Fig. C · Sample finding record
Que Sengmany, founder and principal security lead at SECURIQUE
Que Sengmany
Founder & Principal Security Lead
CISSP · OSCP · AIGP

One fractional CISO. Embedded in your team.

You’re not getting a junior consultant with a playbook, or an account manager who outsources the work. You’re getting the person who actually does it.

25+ years across network engineering, cloud architecture, application security, DevSecOps, and security leadership. CISSP, OSCP, and AIGP, with ISO 27001 Lead Auditor training. You get that experience directly, start to finish.

Capability index

Network Engineering
Cloud Architecture
Application Security
DevSecOps
GRC & Compliance
AI Security & Governance
Vulnerability Assessment
Penetration Testing
Incident Response
Security Leadership
More about SECURIQUE

Book a free 30-minute consult.

We’ll scope a retainer to what you actually need.

You’ll talk to the founder, not a sales rep. If we’re not the right fit, we’ll tell you.

We’ll never share your details. This goes straight to the founder’s inbox.