Skip to content Kellwick Security, GRC and compliance readiness for organisations facing external scrutiny - ISO 27001, DORA, NIS2, SOC 2, CMMC, NIST and security governance.
Explore
Legal
Stay audit-ready
Occasional, practical notes on ISO 27001 readiness and ISMS maintenance. No noise.
Kellwick
Operated by Sodasoft LLC. hello@kellwick.com
Independent advisory practice. Not a certification body. Certification decisions are made only by accredited certification bodies.
© 2026 Sodasoft LLC. All rights reserved.
Internal operations login
← All roles Careers
Fractional CISO / Senior Security & GRC Advisor - Independent Contractor Remote Part-time / Retainer-based Independent Contractor English - C1+ required
vCISO Security Leadership GRC ISO 27001 SOC 2
About the Role
Kellwick is looking for experienced security leaders to deliver fractional CISO and senior Security & GRC advisory services to client organisations.
This is not primarily a documentation or compliance analyst role.
You will act as a senior security leader for organisations that need experienced security and GRC ownership but do not require, or are not yet ready for, a full-time CISO.
You must be comfortable working directly with founders, CEOs, COOs, CTOs, boards, auditors, regulators, enterprise customers and senior client stakeholders.
What You Will Do
Act as fractional CISO or senior security/GRC advisor
Develop security strategies and roadmaps
Establish security governance structures
Define security priorities based on business risk
Own or oversee information security risk management
Establish security metrics and executive reporting
Present security posture, risks and priorities to senior management
Support board and management security discussions
Fractional CISO / Senior Security & GRC Advisor - Independent Contractor | Kellwick
Oversee security policies and governance
Coordinate ISO 27001, SOC 2, NIST and other assurance programmes
Support regulatory security requirements
Oversee third-party and supplier security risk
Support incident governance and executive incident response
Guide cloud and SaaS security priorities
Support security architecture and control decisions
Review security tooling and investment priorities
Support enterprise customer security reviews
Support security questionnaires and procurement requirements
Coordinate penetration testing, vulnerability management and remediation priorities
Work with Kellwick framework specialists where deeper regulatory or technical expertise is required
Keep clients continuously ready for audits, customer reviews and external scrutiny
Required Experience
8+ years of professional information security experience
Significant experience in senior security or GRC leadership
Previous experience as CISO, Head of Security, Security Director, Deputy CISO, Head of GRC or equivalent senior role
Strong information security risk management experience
Strong security governance experience
Experience working with executive leadership
Experience communicating security risk in business terms
Experience managing or overseeing security programmes
Understanding of cloud and modern SaaS environments
Experience with security audits and assurance
Working knowledge of ISO 27001 and NIST
Strong stakeholder management skills
Excellent written and verbal communication
Professional English at C1 level or higher
Strong Plus
CISSP
CISM
CRISC
CISA
ISO 27001 Lead Implementer
ISO 27001 Lead Auditor
SOC 2 experience
DORA/NIS2 knowledge
Privacy/GDPR governance knowledge
Previous fractional CISO experience
Experience supporting organisations with 50-500 employees
Experience working across multiple clients simultaneously
Board reporting experience
Enterprise security questionnaire and customer assurance experience
Engagement Model This is a part-time, retainer-based independent contractor role.
Kellwick assigns fractional security leaders to clients based on expertise, jurisdiction, language, availability and client requirements.
Engagements may range from several hours per month to structured weekly involvement.
The consultant remains supported by Kellwick's specialist network for ISO, DORA, NIS2, privacy, AI governance, CMMC and other specialist requirements.