Senior Fractional CISO & Product Security Advisor

Remote
Contractor

About Hammer IT Consulting

Hammer IT Consulting, Inc. is a cybersecurity and IT consulting firm providing cybersecurity, compliance, risk management, and advisory services to organizations across regulated industries.

We are expanding our Fractional CISO capabilities and are seeking an experienced Senior Fractional CISO & Product Security Advisor to support a prospective client engagement involving a technology company serving commercial, federal, government, and defense-related customers.

This is initially a contract opportunity with the potential for an ongoing relationship and additional client engagements through Hammer IT Consulting.

About the Role

We are looking for a senior cybersecurity professional who can serve as the named Fractional CISO for a client while representing Hammer IT Consulting.

This is not solely a compliance role. The ideal candidate combines executive security leadership, CMMC/NIST 800-171 expertise, SOC 2 experience, Microsoft GCC High knowledge, and product/application security experience.

The individual will provide security leadership and governance while working closely with the client's executives, engineering teams, IT/MSP resources, auditors, and other stakeholders.

The selected candidate must be comfortable participating in client-facing meetings and serving as a trusted security advisor to executive leadership.

Key Responsibilities

Fractional CISO & Security Leadership

  • Serve as the client's named Fractional CISO and senior cybersecurity advisor.
  • Develop and maintain the organization's security strategy, roadmap, policies, standards, and security governance program.
  • Maintain security risk registers and oversee risk-treatment decisions.
  • Establish security KPIs, metrics, and maturity objectives.
  • Provide executive-level reporting on cybersecurity posture, risks, compliance, and remediation.
  • Lead incident-response planning and participate in security incidents and tabletop exercises as required.

CMMC / Federal Compliance

  • Lead CMMC Level 2 / NIST SP 800-171 readiness and certification initiatives.
  • Define and validate CUI environments and CMMC scope boundaries.
  • Develop, review, and maintain System Security Plans (SSPs) and POA&Ms.
  • Coordinate implementation and evidence collection with technical teams.
  • Prepare organizations for C3PAO assessments and support interactions with assessors.
  • Provide guidance related to CUI, DFARS 252.204-7012, FIPS 140-2/3, and other applicable federal/DoD cybersecurity requirements.
  • Provide security leadership for Microsoft 365 Commercial and Microsoft GCC High environments.

SOC 2 & GRC

  • Lead SOC 2 Type II readiness, recertification, and audit activities.
  • Coordinate control design, evidence collection, auditor interactions, and remediation.
  • Establish and maintain security policies and control frameworks.
  • Oversee internal control monitoring, exceptions, and third-party/vendor risk management.
  • Work with GRC/compliance automation platforms as appropriate.
  • Help map common controls across multiple cybersecurity and compliance frameworks.

Product & Application Security

  • Provide security leadership for software products and associated development environments.
  • Establish and mature a secure software development lifecycle (Secure SDLC).
  • Conduct or lead product threat-modeling and security architecture reviews.
  • Establish requirements for SAST, DAST, SCA, secrets scanning, dependency management, and related application-security controls.
  • Oversee vulnerability management and remediation processes for software products.
  • Provide guidance around DevSecOps and CI/CD security.
  • Oversee software supply-chain security and SBOM practices.
  • Coordinate independent penetration testing and product-security assessments.
  • Work with engineering teams to identify, prioritize, and remediate product-security risks.
  • Establish product vulnerability disclosure and security incident-response processes.

Customer & Audit Support

  • Lead or support responses to customer security questionnaires and RFP security requirements.
  • Participate in customer security discussions as a cybersecurity SME.
  • Lead interactions with auditors and security assessors.
  • Help prepare employees and technical teams for audit interviews and assessments.

Required Qualifications

  • Significant cybersecurity leadership experience at the CISO, Deputy CISO, Director, Principal Consultant, or senior security advisory level.
  • Demonstrated experience leading CMMC Level 2 / NIST SP 800-171 initiatives.
  • Strong understanding of CUI environments and federal/DoD cybersecurity requirements.
  • Hands-on experience with Microsoft GCC High security and compliance requirements.
  • Experience leading SOC 2 Type II readiness, audits, or recertifications.
  • Strong product/application security and Secure SDLC knowledge.
  • Experience working with engineering and DevOps teams on product-security initiatives.
  • Strong knowledge of vulnerability management, application-security testing, threat modeling, and software supply-chain risk.
  • Ability to translate technical security issues into business and executive-level risk discussions.
  • Excellent written and verbal communication skills.
  • Strong client-facing presence and ability to represent Hammer IT Consulting professionally.
  • Must be U.S.-based and able to support U.S. business hours.

Highly Preferred Qualifications

One or more of the following would be highly desirable:

  • CISSP
  • CISM
  • CMMC CCP, CCA, Registered Practitioner, or related CMMC assessment/advisory experience
  • Experience working directly with a C3PAO
  • Previous CISO or Fractional CISO experience
  • Experience supporting DoD contractors or federal technology organizations
  • Experience securing SaaS, cybersecurity, cryptographic, or enterprise software products
  • Experience with FedRAMP or StateRAMP
  • Experience with Microsoft security technologies including Entra ID, Defender, Intune, Purview, and Conditional Access

Loading Job Application......