Virtual CISO (vCISO)
WEBIT Services
| Company | WEBIT Services |
| Category | Security |
| Location | Naperville |
| Remote | Hybrid |
| Employment | Full-time |
| Level | Director |
| Salary | Not stated by the employer |
| Posted | 3 Aug 2026 |
| Last verified | 12 Aug 2026 |
| Source | Employer ATS (workable) |
Description
WEBIT SERVICES is a Managed Services Provider in Naperville, Illinois, servicing customers in the Western Suburbs of Chicago. WEBIT Services is looking for an experienced vCISO to join our team. Are you a security leader who's just as comfortable in the boardroom as you are in risk management? WEBIT is looking for Virtual CISO to serve as a trusted, named security advisor for our managed security clients. A person who can translate technical risk into business strategy and help executives make confident, informed decisions about security posture. This is a strategic, client facing leadership role. You won't be doing hands-on remediation (that is what our service desk is for) --- instead, you will own the big picture: security, planning, compliance posture, executive relationships, and driving real business value through structured, evidence-based assessments. What You'll Do Client Security Advisory Serve as the named vCISO and trusted security leader for your assigned clients. Own and maintain a comprehensive Security Roadmap, updated quarterly based upon assessment findings Build and lead executive relationships, including quarterly briefings with C-suite and board members as appropriate Partner closely with the vCIO team, providing quarterly reporting for each client. Driving Growth Through Control Map Assessments Conduct quarterly Control Map gap assessments using the NIST CSF 2.0 framework Identify Net Revenue Retention (NRR) opportunities and articulate them in clear business language Convert identified gaps into ScalePad Lifecycle Manager initiatives Keep the vCIO team in the loop on client changes tied to NRR projects Security Posture Oversight Own patching compliance KPI's (95%+ within 14 days for OS, 90%+ within 7 days for third party, 100% of critical patches within 72 hours) Monitor vulnerability remediation SLA adherence (95%= target) Ensure full tool coverage across managed assets: Huntress, Threatlocker, ConnectSecure, and Datto RMM Client Reporting Deliver monthly security posture reports in plain business language--no raw scanner output Lead quarterly Security Roadmap briefings with executive stakeholders Provide a weekly internal posture summary to WEBIT leadership Documentation Keep thorough records of interactions, decisions, and action items in Autotask Document NRR opportunities with clear business justification Track risk acceptance decisions and their compensating controls Escalation & Incident Response Acknowledge security incidents within 1 hour Coordinate response efforts with the service desk, keeping communication clear Immediately escalate breaches, regulatory exposure, or media -sensitive incidents to the COO