When you join the network, you stay independent. You choose the region you want to work in, the industries you are comfortable with and how much time you can give. When a client engagement matches your profile, we bring it to you. If it fits, you take it. If it does not, you pass and we go to the next person on the panel.
Bring your experience. We will bring the clients.
SecComply places experienced security leaders into fractional CISO engagements with our clients. You lead the security function. We handle the client relationship, the delivery bench, the tooling and the paperwork.
A network of security leaders, not a job board
Most companies that need a CISO cannot justify a full time one. They need someone senior for a few days a month who can set direction, answer the board, sign off on risk decisions and stand in front of an auditor. That is the work we are placing people into.
We are not reselling your CV. You are introduced to the client as the security leader for their engagement, working under the SecComply contract with our team behind you.
What you get out of it
Client flow without business development
You spend your time on security work instead of proposals, follow ups and chasing procurement. Our sales team fills the pipeline.
A delivery bench behind you
Policy drafting, evidence collection, VAPT, cloud reviews, application testing and audit coordination are done by our consultants. You direct the work rather than doing all of it yourself.
Platform access
Every engagement runs on our GRC platform, so control mapping, evidence, and posture reporting are in one place. You get a client dashboard instead of a folder of spreadsheets.
Methodology and templates that already exist
Policy sets, risk registers, board reporting packs, audit checklists and framework mappings for ISO 27001, ISO 27701, ISO 42001, SOC 2, DPDP, GDPR, HIPAA, PCI DSS and NIST CSF. You are not rebuilding the same artefacts for every client.
Clear commercials
Fees are agreed in writing before you accept an engagement, and paid on a fixed monthly cycle. Contracting, invoicing and collections sit with us.
Work you choose
You tell us the region, the industries and the number of days a month. We only bring you engagements that match.
A typical engagement
Most fractional engagements run between two and five days a month, over a term of six to twelve months. Depending on the client, the work covers:
- Security strategy and a twelve month roadmap the management team has signed off on
- Risk register ownership, including the decisions on what gets accepted and what gets funded
- Board, management and investor reporting
- Policy and control framework ownership
- Certification and audit ownership for ISO 27001, SOC 2, DPDP or the framework the client is chasing
- Customer security reviews, questionnaires and due diligence responses
- Third party and vendor risk decisions
- Incident readiness, tabletop exercises and the escalation path when something goes wrong
- Guiding the client's internal IT or engineering team on what to fix first
You are the decision maker and the face of the security function. Execution is shared with our delivery team.
Is this a fit for you?
- You have twelve or more years in cybersecurity, with at least three in a leadership role
- You have run a security program end to end, not just one specialism
- You have held a CISO, Head of Security, Security Manager or equivalent role, or consulted at that level
- You are comfortable in front of a board, a customer and an auditor
- You have working depth in at least two of ISO 27001, SOC 2, DPDP, GDPR, HIPAA, PCI DSS or NIST CSF
- You can commit a predictable number of days each month
From registration to first engagement
Register
Fill in the form below. Name, email, phone and the region you want to work in is all we need to start.
Introduction call
A thirty minute conversation with our team on your background, the kind of clients you want, your availability and your commercial expectations.
Empanelment
We take your detailed profile, two professional references, a signed NDA and the partner agreement. Once that is done you are on the panel.
Matching
When a client engagement comes in that matches your region, industry and availability, we share the brief with you. You decide whether to take it.
Engagement
You are introduced to the client, the scope and fee are confirmed in writing, and the engagement starts. Our delivery team and platform support you from day one.
Typical time from registration to empanelment is two weeks. Time to first engagement depends on demand in your region.
Three ways to work with us
Fractional vCISO
You own the client's security function on a part time basis. Strategy, risk, reporting, audits and the security roadmap sit with you.
Advisory and on call
A fixed number of hours each month for guidance, design reviews, escalations and management reporting. Suited to clients who have an internal team but no senior leader.
Program lead
You lead a specific program such as ISO 27001, SOC 2 Type II or DPDP readiness, with our consultants doing the implementation and evidence work under your direction.
What we handle, what you handle
SecComply handles
- Finding and closing the client
- Contract, scope and commercial terms
- Invoicing, collections and your payout
- Delivery team for GRC, VAPT, AppSec and cloud
- Platform, templates and methodology
- Auditor and CPA coordination
- Escalation support if an engagement goes sideways
You handle
- The security strategy and roadmap
- Risk decisions and prioritisation
- Board and management reporting
- Direction of the delivery team on that account
- Client relationship on security matters
- Audit readiness and sign off
- Availability as agreed in the engagement
Where we are placing security leaders
Tell us your preferred region in the form and we will match accordingly.
India
Pune, Mumbai, Bengaluru, Delhi NCR, Hyderabad, Chennai, Ahmedabad, Kolkata
UAE and Gulf
UAE, Saudi Arabia, Qatar
Europe and UK
Remote-first, with onsite time for boards and audits
United States
Remote-first, with onsite time for boards and audits
Bangladesh
Remote-first, with onsite time for boards and audits
Remote only
Engagements that run entirely remotely, wherever you are based
Most engagements are remote first, with periodic onsite time for board meetings, audits and workshops.
Join the network
Four details to start. If your profile fits, we will get in touch within three working days to set up an introduction call.
Questions security leaders ask us
Ready to take on your first engagement?
Registration takes two minutes. The conversation that follows tells us both whether this is a fit.