Fractional CISO / vCISO

Pass the security review that’s holding up your deal.

SOC 2 and ISO 27001 readiness, led by a CISSP-certified security leader. Embedded in your team in weeks, not a $200k full-time hire.

Included in every retainer

  • CISSP
  • OSCP
  • AIGP
  • ISO 27001 Lead Auditor (trained)

25+ years hands-on security

Senior-level delivery on every engagement. The lead you meet is the lead you get.

Fig. A · Retainer spec

Fractional, not freelance.

Three things that separate this from hiring a consultant or signing up another vendor.

  • Embedded, not one-and-done
    Ongoing leadership inside your sprint cycles, architecture reviews, and incident response. Not a 200-page report that collects dust.
  • Senior only, always
    Every engagement is hands-on and owned end to end by one named senior. You meet them before you sign, and any specialist brought in is named up front.
  • Security that ships
    We don’t say no, we find the way. Security built into the way your team already works.

Your security team, without the headcount.

Every retainer is built from these. We scope the mix to your stage, your stack, and your compliance pressure. In a normal week that means a working session with your team, policy and evidence work done by us, security questionnaires answered on your behalf, and remediation guidance in your Slack. Penetration testing and ISO 27001 are scoped in as deliverables, never upsells.

Security roadmap & posture

We map your current controls against the framework your buyer is asking for, then hand you a ranked remediation plan: every gap, an owner, and the order to fix it. Re-ranked every month as your stack and your deadlines move.

SOC 2 & ISO 27001 readiness

We write the policies, stand up the controls, collect the evidence the auditor will ask for, and manage the audit itself. Your engineers keep shipping. We’ve taken a startup through ISO 27001 without slowing down a single sprint.

Vulnerability assessment & penetration testing

OSCP-level offensive testing against your networks, apps, and APIs, scoped into your retainer when you need it. You get a report with reproduction steps and fixes, a live findings walkthrough with your engineers, and one free retest after you patch.

See the testing services and packages

Cloud security & DevSecOps

We harden your AWS, Azure, or GCP accounts and wire security checks into CI/CD, so misconfiguration and leaked secrets get caught in the pipeline instead of in the pentest.

Incident response & vendor risk

An incident response plan and runbooks written before you need them, senior hands on deck when something happens, and a vendor-risk process that answers the third-party questions in every enterprise security review.

Ship AI without shipping new risk.

We help you adopt it, secure it, and prove it’s governed, the same embedded way we run the rest of your security.

Adopt AI, safely

Put AI to work across the team without the risk. You get a tool-by-tool call on what is safe to use, access controls and guardrails configured, and an acceptable-use policy your auditors and enterprise buyers will accept.

Secure AI

Ship AI features without new attack surface. We red-team your LLM apps for prompt injection, data leakage, and abuse, then lock down the model and data pipeline behind them. Findings come back with reproduction steps and fixes your engineers can action.

Govern AI

We map your AI use against the EU AI Act, ISO 42001, and NIST AI RMF, write the governance policies to close the gaps, and leave you with the evidence investors and regulators ask for. Without killing velocity.

Start with a fixed-scope AI Governance Gap Assessment

The standard operating procedure.

The machinery of an engagement: four named deliverables, produced in this order, by the lead you meet on the first call.

SOP–01

Gap assessment

Artifact · Control-mapped gap report

Your current posture, mapped control-by-control against SOC 2 or ISO 27001: which controls pass, which fail, and which are blocking the deal. It starts in the free consult

SOP–02

Roadmap

Artifact · Prioritized remediation roadmap

Every gap becomes a ranked task with an owner and an order. You see what gets fixed first, and why, before we touch anything.

SOP–03

Embedded cadence

Cadence · Weekly sync + async Slack

The lead joins your Slack and your sprint cycle: policy drafting, vendor reviews, questionnaire turnaround, and remediation guidance, inside the stack you already run.

SOP–04

Audit-ready

Artifact · Evidence pipeline, managed audit

Controls produce evidence continuously, we brief and manage the auditor, and the reporting reads clean to your board and your buyer’s security team.

Fig. B · Operating procedure

From first call to embedded CISO.

No death by RFP. We start with a conversation and embed from there.

  1. 01
    Align
    A free 30-minute call. We learn your stack, your timeline, and your compliance pressure, then tell you honestly if we’re a fit.
  2. 02
    Embed
    We join your team as your fractional CISO. Weekly syncs, async Slack, and direct access to your engineering channel.
  3. 03
    Deliver
    Prioritized roadmap, active remediation guidance, compliance readiness, and incident response. Ongoing, measurable, and aligned to your sprints.

Security leadership, scoped to your stage.

Price follows scope: how much of the program you need owned, and how hard the deadline is. Penetration testing and ISO 27001 work are scoped in as retainer deliverables, not billed as extras. You see the number and exactly what it covers before you commit.

Foundation

For early-stage teams building real security for the first time.

You get a ranked plan, the riskiest gaps actually fixed, and a senior person to call before you make a decision that is hard to undo.

  • Ranked security roadmap, re-ranked as you grow
  • Hands-on fixes for the riskiest gaps
  • Cloud and DevSecOps guidance for your stack
  • Slack access, same-day in business hours

Typical involvement · ~10 hrs/mo

Book a consult
Embedded Fractional CISO

For scaling or regulated teams (fintech, healthcare, AI-native) that need security to have a real owner.

A senior security lead who owns the program end to end: the roadmap, the certifications, the board conversation, and AI governance. Without the $200k full-time hire.

  • Full program build-out, and we manage the certifications
  • AI governance and the rules that come with it (EU AI Act, ISO 42001)
  • Security reporting your board and investors can follow
  • Priority incident response, 4-hour SLA
  • Embedded in your engineering and leadership meetings

Typical involvement · ~40 hrs/mo

Book a consult

Every retainer is custom-scoped; these three are the shapes teams land on most. Not sure which one fits? Book a free consult and we’ll size it with you.

Built for teams that build things.

Post-seed to Series B. Ten to a hundred people. Moving fast, with real compliance pressure.

SaaS Startups

Ship fast, stay secure.

Fintech & Finance

Trust is the product.

Healthcare Tech

Patient data, protected.

AI-Native Companies

Govern what you build.

Selected outcomes.

SECURIQUE is new. The track record behind it isn’t: 25+ years of doing this work.

  • Led ISO 27001 certification to completion inside a cloud-first startup on an aggressive timeline, without slowing a single sprint.

  • Built DevSecOps programs embedded directly into engineering workflows, so security kept pace with the team rather than slowing it down.

  • Ran OSCP-level offensive assessments across SaaS and fintech to surface the scanner-blind spots before someone else did.

Finding record · What you receive

Client
Cloud-first SaaS, post-seed
Trigger
Enterprise security review stalling the deal
Finding
Access-control gap, invisible to the automated scanner
Disposition
Remediated, evidence filed for audit

Sanitized composite, generalized from real engagements. Client-identifiable detail never leaves the engagement.

Fig. C · Sample finding record
Que Sengmany, founder and principal security lead at SECURIQUE
Que Sengmany
Founder & Principal Security Lead
CISSP · OSCP · AIGP

One fractional CISO. Embedded in your team.

You’re not getting a junior consultant with a playbook, or an account manager who hands the work to someone you’ll never meet. You’re getting the person who owns it, does the work, and names anyone else who touches it.

25+ years across network engineering, cloud architecture, application security, DevSecOps, and security leadership. CISSP, OSCP, and AIGP, with ISO 27001 Lead Auditor training. You get that experience directly, start to finish.

Capability index

Network Engineering
Cloud Architecture
Application Security
DevSecOps
GRC & Compliance
AI Security & Governance
Vulnerability Assessment
Penetration Testing
Incident Response
Security Leadership
More about SECURIQUE

Book a free 30-minute consult.

We’ll scope a retainer to what you actually need.

You’ll talk to the founder, not a sales rep. If we’re not the right fit, we’ll tell you.

We’ll never share your details. This goes straight to the founder’s inbox.