Fractional CISO / vCISO
Pass the security review that’s holding up your deal.
SOC 2 and ISO 27001 readiness, led by a CISSP-certified security leader. Embedded in your team in weeks, not a $200k full-time hire.
Included in every retainer
- CISSP
- OSCP
- AIGP
- ISO 27001 Lead Auditor (trained)
25+ years hands-on security
Senior-level delivery on every engagement. The lead you meet is the lead you get.
Fig. A · Retainer spec
Fractional, not freelance.
Three things that separate this from hiring a consultant or signing up another vendor.
-
Embedded, not one-and-doneOngoing leadership inside your sprint cycles, architecture reviews, and incident response. Not a 200-page report that collects dust.
-
Senior only, alwaysEvery engagement is hands-on and owned end to end by one named senior. You meet them before you sign, and any specialist brought in is named up front.
-
Security that shipsWe don’t say no, we find the way. Security built into the way your team already works.
Your security team, without the headcount.
Every retainer is built from these. We scope the mix to your stage, your stack, and your compliance pressure. In a normal week that means a working session with your team, policy and evidence work done by us, security questionnaires answered on your behalf, and remediation guidance in your Slack. Penetration testing and ISO 27001 are scoped in as deliverables, never upsells.
Security roadmap & posture
We map your current controls against the framework your buyer is asking for, then hand you a ranked remediation plan: every gap, an owner, and the order to fix it. Re-ranked every month as your stack and your deadlines move.
SOC 2 & ISO 27001 readiness
We write the policies, stand up the controls, collect the evidence the auditor will ask for, and manage the audit itself. Your engineers keep shipping. We’ve taken a startup through ISO 27001 without slowing down a single sprint.
Vulnerability assessment & penetration testing
OSCP-level offensive testing against your networks, apps, and APIs, scoped into your retainer when you need it. You get a report with reproduction steps and fixes, a live findings walkthrough with your engineers, and one free retest after you patch.
Cloud security & DevSecOps
We harden your AWS, Azure, or GCP accounts and wire security checks into CI/CD, so misconfiguration and leaked secrets get caught in the pipeline instead of in the pentest.
Incident response & vendor risk
An incident response plan and runbooks written before you need them, senior hands on deck when something happens, and a vendor-risk process that answers the third-party questions in every enterprise security review.
Ship AI without shipping new risk.
We help you adopt it, secure it, and prove it’s governed, the same embedded way we run the rest of your security.
Adopt AI, safely
Put AI to work across the team without the risk. You get a tool-by-tool call on what is safe to use, access controls and guardrails configured, and an acceptable-use policy your auditors and enterprise buyers will accept.
Secure AI
Ship AI features without new attack surface. We red-team your LLM apps for prompt injection, data leakage, and abuse, then lock down the model and data pipeline behind them. Findings come back with reproduction steps and fixes your engineers can action.
Govern AI
We map your AI use against the EU AI Act, ISO 42001, and NIST AI RMF, write the governance policies to close the gaps, and leave you with the evidence investors and regulators ask for. Without killing velocity.
The standard operating procedure.
The machinery of an engagement: four named deliverables, produced in this order, by the lead you meet on the first call.
Gap assessment
Artifact · Control-mapped gap report
Your current posture, mapped control-by-control against SOC 2 or ISO 27001: which controls pass, which fail, and which are blocking the deal. It starts in the free consult
Roadmap
Artifact · Prioritized remediation roadmap
Every gap becomes a ranked task with an owner and an order. You see what gets fixed first, and why, before we touch anything.
Embedded cadence
Cadence · Weekly sync + async Slack
The lead joins your Slack and your sprint cycle: policy drafting, vendor reviews, questionnaire turnaround, and remediation guidance, inside the stack you already run.
Audit-ready
Artifact · Evidence pipeline, managed audit
Controls produce evidence continuously, we brief and manage the auditor, and the reporting reads clean to your board and your buyer’s security team.
Fig. B · Operating procedure
From first call to embedded CISO.
No death by RFP. We start with a conversation and embed from there.
-
01AlignA free 30-minute call. We learn your stack, your timeline, and your compliance pressure, then tell you honestly if we’re a fit.
-
02EmbedWe join your team as your fractional CISO. Weekly syncs, async Slack, and direct access to your engineering channel.
-
03DeliverPrioritized roadmap, active remediation guidance, compliance readiness, and incident response. Ongoing, measurable, and aligned to your sprints.
Security leadership, scoped to your stage.
Price follows scope: how much of the program you need owned, and how hard the deadline is. Penetration testing and ISO 27001 work are scoped in as retainer deliverables, not billed as extras. You see the number and exactly what it covers before you commit.
For early-stage teams building real security for the first time.
You get a ranked plan, the riskiest gaps actually fixed, and a senior person to call before you make a decision that is hard to undo.
- Ranked security roadmap, re-ranked as you grow
- Hands-on fixes for the riskiest gaps
- Cloud and DevSecOps guidance for your stack
- Slack access, same-day in business hours
For teams where SOC 2, ISO 27001, or a customer security review is holding up a deal.
We build what the audit needs, answer the questionnaire that’s stalling the deal, and manage the auditor. Your engineers keep shipping while we do it.
- SOC 2 and ISO 27001 readiness, through to certification
- Policies, controls, and the evidence to back them
- We answer the security questionnaires for you
- Weekly sync with you or your CTO
- Incident response plan, plus on-call when it matters
For scaling or regulated teams (fintech, healthcare, AI-native) that need security to have a real owner.
A senior security lead who owns the program end to end: the roadmap, the certifications, the board conversation, and AI governance. Without the $200k full-time hire.
- Full program build-out, and we manage the certifications
- AI governance and the rules that come with it (EU AI Act, ISO 42001)
- Security reporting your board and investors can follow
- Priority incident response, 4-hour SLA
- Embedded in your engineering and leadership meetings
Every retainer is custom-scoped; these three are the shapes teams land on most. Not sure which one fits? Book a free consult and we’ll size it with you.
Built for teams that build things.
Post-seed to Series B. Ten to a hundred people. Moving fast, with real compliance pressure.
SaaS Startups
Ship fast, stay secure.
Fintech & Finance
Trust is the product.
Healthcare Tech
Patient data, protected.
AI-Native Companies
Govern what you build.
Selected outcomes.
SECURIQUE is new. The track record behind it isn’t: 25+ years of doing this work.
-
Led ISO 27001 certification to completion inside a cloud-first startup on an aggressive timeline, without slowing a single sprint.
-
Built DevSecOps programs embedded directly into engineering workflows, so security kept pace with the team rather than slowing it down.
-
Ran OSCP-level offensive assessments across SaaS and fintech to surface the scanner-blind spots before someone else did.
Finding record · What you receive
- Client
- Cloud-first SaaS, post-seed
- Trigger
- Enterprise security review stalling the deal
- Finding
- Access-control gap, invisible to the automated scanner
- Disposition
- Remediated, evidence filed for audit
Sanitized composite, generalized from real engagements. Client-identifiable detail never leaves the engagement.
One fractional CISO. Embedded in your team.
You’re not getting a junior consultant with a playbook, or an account manager who hands the work to someone you’ll never meet. You’re getting the person who owns it, does the work, and names anyone else who touches it.
25+ years across network engineering, cloud architecture, application security, DevSecOps, and security leadership. CISSP, OSCP, and AIGP, with ISO 27001 Lead Auditor training. You get that experience directly, start to finish.
Capability index
Book a free 30-minute consult.
We’ll scope a retainer to what you actually need.
You’ll talk to the founder, not a sales rep. If we’re not the right fit, we’ll tell you.