Fractional CISO leadership
Strategy, roadmap, budget, vendor risk, board reporting, and the judgement calls a first security hire can't make yet. I sit in the leadership meeting, not on the sidelines.
Get the strategic security leadership your organization needs without the $400K+ salary. SOC 2, ISO 27001, FedRAMP, AI governance, delivered by someone who has built and led the teams, not just audited them. Senior operator. Month to month.
Sound familiar? Every rmrfs engagement starts in one of these four places.
A 300-row SIG questionnaire landed in someone's inbox three weeks ago. Nobody owns it. Procurement has stopped replying to your AE.
The Vanta dashboard has been 61% green since March. Nobody knows which controls the auditor will actually pull evidence for, or who is accountable when they do.
LLM features are in production. There's no model inventory, no AI use policy, and an enterprise prospect just asked about ISO 42001 and prompt-injection testing.
At 40 to 300 people you need fifteen senior hours a week, not forty. You need someone who has run the program before, starting this month.
Not another slide deck of recommendations. The retainer owns outcomes: audits passed, questionnaires closed, risks retired, and a board that understands what it's paying for.
Strategy, roadmap, budget, vendor risk, board reporting, and the judgement calls a first security hire can't make yet. I sit in the leadership meeting, not on the sidelines.
SOC 2, ISO 27001, FedRAMP, IL4/IL5, GDPR. Gap assessment to certificate, with evidence that collects itself.
ISO 42001, NIST AI RMF, LLM application reviews, AI use policy. Governance that lets you ship AI to enterprise buyers.
SIG, CAIQ, VSAQ and the custom 400-row spreadsheet. Answered in 48 hours from a knowledge base that gets sharper every time.
Vulnerability management, SAST/DAST in the pipeline, AWS posture, incident response plans and tabletops. Built with your engineers, not around them.
The engagement starts from how your company actually runs, not a generic control checklist. By day 30 you have an operating cadence, not a PDF.
Read-only access to cloud, identity and source. I map commitments, critical systems, data flows and deadlines, and interview the people who actually run them.
Gap assessment against your target framework. A 90-day plan with owners and dates. The cheap, high-impact fixes go out immediately.
Working sessions start. Policies drafted in your voice, GRC tooling wired to real systems, and the first investor or board update written.
Audit scheduled. Questionnaires answered in 48 hours. Vendors reviewed on a cadence. Monthly report your board can read in five minutes.
Every tier is senior-led, month to month, scoped around outcomes. Start where you are; move tiers when the audit date or the funding round changes the math.
Your team executes. I set direction, review decisions, and keep you honest about risk.
I own the security and compliance program. You get outcomes, not a list of recommendations.
I'm inside your operating cadence. For FedRAMP, IL4, AI-governance builds, tight audit dates or M&A.
Month to month, 30 days notice. Annual billing saves 15%; cancel and the unused balance is refunded pro rata.
Prices are engagement baselines. Final scope depends on your environment, frameworks, and how fast you need to move. One-time assessments and builds are quoted separately below.
Two-week posture review with a risk-ranked, costed roadmap. Often the first step before a retainer.
Readiness build scoped to your size: policies, controls, tooling, evidence, auditor selection.
ISO 42001 / NIST AI RMF gap review plus an LLM application security pass.
SIG, CAIQ or custom, with an evidence pack. Priced on question count and turnaround.
Senior security time with no scoping exercise. Architecture reviews, board prep, a second opinion.
rmrfs is a solo practice on purpose: you work with the operator, not a delivery bench. That caps me at four concurrent retainers, so when I'm full I say so instead of subcontracting you out. Ask on the call and you'll get a straight answer on capacity and a start date.
I've spent 15+ years building and securing production systems: cloud infrastructure, site reliability, security, and governance, risk & compliance. Today I run all four of those functions as an engineering manager at a B2B SaaS company that sells to enterprises and government.
That means I've led SOC 2, ISO 27001, FedRAMP and IL4 programs from the inside, answered the questionnaires that gate enterprise deals, and explained risk to boards in language that drives action. I've also written the Terraform at 2am during an incident. None of this is theory from an audit checklist.
rmrfs exists because too many companies get stuck choosing between a CISO they can't afford and consultants who hand over PDFs nobody implements. The goal of every engagement is independence: a program that runs without me.
Self-assessments I use on real calls. No sign-up, no gate, a branded PDF at the end. If the score stings, that's the point.
Score yourself across the Trust Services Criteria and see exactly which controls will stall your audit.
Run the checkHow exposed is your AI usage? Scored against ISO 42001 and NIST AI RMF with prioritised fixes.
Get your scoreWhat I'd tell a founder over coffee about security, compliance and AI governance. Written for CTOs and engineering leaders, not auditors.
Everyone says six to twelve months. A Type I in twelve weeks is realistic if three preconditions hold. The week-by-week plan, what it costs, and where it slips.
It isn't ethics statements. It's inventories, owners and evidence. The three mistakes that derail most programs, and an honest 90-day plan.
Four questions that settle it, where fractional breaks, and the hybrid most companies end up with.
If yours isn't here, ask it on the call. I'd rather lose a bad-fit engagement in ten minutes than in month three.
Me. No juniors, no offshore bench, no account manager between us. When scope calls for something I don't do in-house, like a penetration test or 24/7 monitoring, I bring in a vetted partner and tell you before it happens.
Advisory is roughly ten senior hours a month, Managed roughly twenty, Embedded is scoped to the program. I price on outcomes, not timesheets; the hours tell you what cadence to expect, not where I stop.
Type I, yes, if leadership is committed and tooling is wired up in the first two weeks. Type II needs an observation window of three to twelve months, so the calendar matters more than effort. You get an honest timeline on the first call, not the one you want to hear.
No, I make them mean something. Those platforms collect evidence. A program decides which evidence matters, who owns each control, and what you tell the auditor when a test fails. I administer whichever one you already have.
Yes, and it's where most consultants get vague. I've run these programs from the vendor side. You'll get realistic costs, a realistic timeline, and a candid view of whether your architecture is ready. I won't tell you it takes three months.
A model and vendor inventory, an AI use policy your engineers will actually follow, risk assessments per system using NIST AI RMF, security reviews of LLM applications (prompt injection, data leakage, tool-call boundaries), and an ISO 42001 gap review if certification is on the roadmap.
Yes. Thirty days notice, no lock-in. Annual billing saves 15% and refunds the unused balance pro rata if you cancel. Start monthly; move to annual once the audit is scheduled if you want the discount.
If you need a 24/7 SOC, a large team on site, or a healthcare-first compliance program built around HIPAA, I'm not your person and I'll point you to someone who is. I stay inside the frameworks I've actually run.
Thirty minutes. If rmrfs isn't the right fit I'll say so and point you toward someone who is. If it is, we'll leave the call with a scope and a start date.