Fractional vCISO

Security leadership for companies that just got asked to prove it.

Compliance and security programs built to hold up when a customer, an auditor, or a regulator looks closely.

  • CISSP
  • CISA
  • GSLC
  • CISO and vCISO
  • USMC veteran
  • 29 years in the field
01 — Services

What I'm usually called in for

Three situations account for most engagements. If yours looks like one of these, we should talk.

A compliance deadline you can't miss

A framework has become a condition of doing business. I build the program end to end — risk analysis, policies, controls, and the evidence to back them up — so it survives the first serious look.

SOC 2 · ISO 27001 · HIPAA · CMMC · PCI DSS · NIST · and others

A deal blocked by a security review

An enterprise customer sent a questionnaire and the answers aren't there yet. I organize the evidence, answer what's answerable, and close the gaps that are holding up signature.

Questionnaires · Diligence · Evidence packages

Security leadership you can't yet hire

You need someone accountable for the security program without carrying a full-time executive. Ongoing advisory on retainer — roadmap, vendor risk, board and customer reporting.

Fractional vCISO retainer

02 — Process

How engagements work

No open-ended hourly arrangements. Scope and price are agreed before work starts.

01

Discovery call

Thirty minutes. What's driving the deadline, what's already in place, and what you're actually obligated to do — which is often narrower than you've been told.

02

Written scope of work

A fixed fee against defined deliverables, each with a stated completion standard. You know what you're getting and what it costs before anyone signs.

03

Built, documented, handed over

The program is yours to run when I'm done — editable policies, a live risk register, and a compliance calendar. Retainer support afterward is optional, not assumed.

Every engagement is scoped and priced to what the situation actually requires. Retainers are scoped separately.

03 — Background

Who you'd be working with

I'm Jason Hamilton. I've spent nearly thirty years in security leadership across financial services, healthcare, technology, and defense — building and running programs in regulated environments where the work has to hold up under outside scrutiny.

Most of my work is with small and mid-sized companies facing a requirement they haven't had to meet before. They rarely need a scaled-down enterprise program. They need the parts that carry real weight, documented well enough to defend, and nothing they'll never use.

I've worked across the major regulatory and security frameworks. Whatever standard is in front of you, the conversation starts the same way: what are you actually obligated to do, and what will it take to prove it.

Next step

Ready to talk?

Thirty minutes, no pitch. Bring your deadline and whatever you've got so far, and we'll scope it honestly.