Fractional CISO / vCISO
Pass the security review that’s holding up your deal.
SOC 2 and ISO 27001 readiness, led by a CISSP-certified security leader. Embedded in your team in weeks, not a $200k full-time hire.
Included in every retainer
- CISSP
- OSCP
- AIGP
- ISO 27001 Lead Auditor (trained)
25+ years hands-on security
Senior-level delivery on every engagement. The lead you meet is the lead you get.
Fig. A · Retainer spec
Fractional, not freelance.
Three things that separate this from hiring a consultant or signing up another vendor.
-
Embedded, not one-and-doneOngoing leadership inside your sprint cycles, architecture reviews, and incident response. Not a 200-page report that collects dust.
-
Senior only, alwaysEvery engagement is hands-on and owned end to end. You work directly with the lead.
-
Security that shipsWe don’t say no, we find the way. Security built into the way your team already works.
Your security team, without the headcount.
Every retainer is built from these. We scope the mix to your stage, your stack, and your compliance pressure. Penetration testing and ISO 27001 are scoped in as deliverables, never upsells.
Security roadmap & posture
A prioritized plan that fits your stage and updates as you grow. We tell you what to fix first, and in what order.
SOC 2 & ISO 27001 readiness
Certification on a timeline that matches yours. We’ve taken a startup through ISO 27001 without slowing down a single sprint.
Vulnerability assessment & penetration testing
OSCP-level offensive testing, scoped into your retainer when you need it. We find what automated scanners miss, before someone else does.
Cloud security & DevSecOps
Security built into your pipeline from the start. It scales with your engineering instead of fighting it.
Incident response & vendor risk
A plan before you need it, expert hands on deck when you do, and a vendor-risk program your enterprise buyers will ask about.
Ship AI without shipping new risk.
We help you adopt it, secure it, and prove it’s governed, the same embedded way we run the rest of your security.
Adopt AI, safely
Put AI to work across the team without the risk. We pick the right tools, set guardrails and access controls, and write an acceptable-use policy your auditors and enterprise buyers will accept.
Secure AI
Ship AI features without new attack surface. We red-team your LLM apps for prompt injection, data leakage, and abuse, and lock down the model and data pipeline behind them.
Govern AI
Governance that satisfies regulators and investors without killing velocity. EU AI Act, ISO 42001, NIST AI RMF, and whatever comes next.
The standard operating procedure.
The machinery of an engagement: four named deliverables, produced in this order, by the lead you meet on the first call.
Gap assessment
Artifact · Control-mapped gap report
Your current posture, mapped control-by-control against SOC 2 or ISO 27001: which controls pass, which fail, and which are blocking the deal. It starts in the free consult
Roadmap
Artifact · Prioritized remediation roadmap
Every gap becomes a ranked task with an owner and an order. You see what gets fixed first, and why, before we touch anything.
Embedded cadence
Cadence · Weekly sync + async Slack
The lead joins your Slack and your sprint cycle: policy drafting, vendor reviews, questionnaire turnaround, and remediation guidance, inside the stack you already run.
Audit-ready
Artifact · Evidence pipeline, managed audit
Controls produce evidence continuously, we brief and manage the auditor, and the reporting reads clean to your board and your buyer’s security team.
Fig. B · Operating procedure
From first call to embedded CISO.
No death by RFP. We start with a conversation and embed from there.
-
01AlignA free 30-minute call. We learn your stack, your timeline, and your compliance pressure, then tell you honestly if we’re a fit.
-
02EmbedWe join your team as your fractional CISO. Weekly syncs, async Slack, and direct access to your engineering channel.
-
03DeliverPrioritized roadmap, active remediation guidance, compliance readiness, and incident response. Ongoing, measurable, and aligned to your sprints.
Security leadership, scoped to your stage.
Retainers usually start around $4,000/mo. What you pay depends on how urgent the work is and how much you need us to own. We figure that out on a free consult.
For early-stage teams building real security for the first time.
You get a clear plan, the risky stuff fixed, and someone senior to call when you’re not sure.
- Security roadmap, with the risks ranked
- Hands-on fixes for the riskiest gaps
- Cloud and DevSecOps guidance for your stack
- Slack access, same-day in business hours
For teams where SOC 2, ISO 27001, or a customer security review is holding up a deal.
We build what the audit needs and answer the questionnaire that’s stalling your deal. Your engineers keep shipping while we do it.
- SOC 2 and ISO 27001 readiness, through to certification
- Policies, controls, and the evidence to back them
- We answer the security questionnaires for you
- Weekly sync with you or your CTO
- Incident response plan, plus on-call when it matters
For scaling or regulated teams (fintech, healthcare, AI-native) that need security to have a real owner.
A senior security lead who owns it: the program, the board conversations, AI governance. Without the $200k full-time hire.
- Full program build-out, and we manage the certifications
- AI governance and the rules that come with it (EU AI Act, ISO 42001)
- Security reporting your board and investors can follow
- Priority incident response, 4-hour SLA
- Embedded in your engineering and leadership meetings
Not sure which one fits? Book a free consult and we’ll work it out together.
Built for teams that build things.
Post-seed to Series B. Ten to a hundred people. Moving fast, with real compliance pressure.
SaaS Startups
Ship fast, stay secure.
Fintech & Finance
Trust is the product.
Healthcare Tech
Patient data, protected.
AI-Native Companies
Govern what you build.
Selected outcomes.
SECURIQUE is new. The track record behind it isn’t: 25+ years of doing this work.
-
Led ISO 27001 certification to completion inside a cloud-first startup on an aggressive timeline, without slowing a single sprint.
-
Built DevSecOps programs embedded directly into engineering workflows, so security kept pace with the team rather than slowing it down.
-
Ran OSCP-level offensive assessments across SaaS and fintech to surface the scanner-blind spots before someone else did.
Finding record · What you receive
- Client
- Cloud-first SaaS, post-seed
- Trigger
- Enterprise security review stalling the deal
- Finding
- Access-control gap, invisible to the automated scanner
- Disposition
- Remediated, evidence filed for audit
Sanitized composite, generalized from real engagements. Client-identifiable detail never leaves the engagement.
One fractional CISO. Embedded in your team.
You’re not getting a junior consultant with a playbook, or an account manager who outsources the work. You’re getting the person who actually does it.
25+ years across network engineering, cloud architecture, application security, DevSecOps, and security leadership. CISSP, OSCP, and AIGP, with ISO 27001 Lead Auditor training. You get that experience directly, start to finish.
Capability index
Book a free 30-minute consult.
We’ll scope a retainer to what you actually need.
You’ll talk to the founder, not a sales rep. If we’re not the right fit, we’ll tell you.