Part-time CISO (vCISO)
Mara joins your leadership meeting every week, owns the security roadmap, and answers customer security questions for you.
- 6 to 18 months
- $8,000 to $18,000 a month
- Discovery in weeks 1 and 2, roadmap in week 3, weekly cadence from week 4. Mara leads the engagement herself from the first call.
Who this fits
A vCISO engagement fits SaaS companies with 50 to 200 employees that need someone to own security before they can justify a full-time hire. It usually starts when a SOC 2 audit is coming, enterprise questionnaires are piling up, or the board asks who is responsible for security. Your leadership team typically has a CTO and engineering managers and no one with security in their title.
What is included
- One day a week, two during audit preparation or a large customer review
- Security policies and procedures, written by Mara
- Tool and vendor selection: compliance platforms, endpoint tools, managed detection
- Customer-facing work: questionnaires, prospect calls, auditor calls
- A quarterly security review with your leadership team
- Incident response lead if something happens
When a part-time CISO makes sense
Most SaaS companies with 50 to 200 employees reach a point where the CTO can no longer cover security on the side. A prospect requires SOC 2. An incident shows a gap. The board asks for a written program. A full-time CISO is a senior executive hire, and at that stage the work fills about one day a week. A vCISO covers that day.
How a week looks
After the first three weeks, the engagement settles into a weekly rhythm: Mara attends your leadership meeting, reviews open questionnaires, moves policy and control work forward, and checks in with whoever owns the current roadmap item.
Everything she produces lives in your systems: your wiki, your ticket tracker, your compliance platform. If the engagement ends, the program stays with you.
When the engagement ends
Most clients move to a one-day-a-month retainer after the first year to keep the program running and prepare for the annual audit. Some hire a full-time security lead, and Mara helps write the job description and interview candidates.
The first three phases
Every vCISO engagement opens with the same phases of the Northstar Maturity Framework.
| Phase | Length | What happens | What you keep |
|---|---|---|---|
| 1Discovery | 2 weeks | Data-flow map, frameworks in scope, and where your program stands today. | Discovery Document, 6 to 12 pages |
| 2Roadmap | 1 week | Prioritized work with owners and a budget, reviewed with your leadership team. | 12-month roadmap |
| 3Build | 8 to 16 weeks | Policies written, controls configured, and your compliance platform collecting evidence. | Policies, controls and evidence collection in place |
-
1Discovery 2 weeks
Data-flow map, frameworks in scope, and where your program stands today.
You keep: Discovery Document, 6 to 12 pages
-
2Roadmap 1 week
Prioritized work with owners and a budget, reviewed with your leadership team.
You keep: 12-month roadmap
-
3Build 8 to 16 weeks
Policies written, controls configured, and your compliance platform collecting evidence.
You keep: Policies, controls and evidence collection in place
Other services
-
SOC 2 readiness program
A 90-day program that takes you from no formal compliance work to ready for a SOC 2 Type II audit window.
- Length
- 90 days to audit-ready
- Price
- $40,000 to $75,000, fixed after scoping
-
Security assessment
A 2 to 3 week review of your security against NIST CSF, CIS Controls or SOC 2, delivered as a written report with a ranked list of fixes.
- Length
- 2 to 3 weeks
- Price
- $15,000 to $30,000
-
Security awareness training
Live onboarding sessions, quarterly phishing tests and short monthly scenarios, written for engineering-heavy teams.
- Length
- 12 months, renewed yearly
- Price
- $24,000 to $48,000 a year
Common questions
Anything else goes on the fit call, or email hello@northstar-demo.example.
A vCISO engagement is $8,000 to $18,000 a month depending on scope. A SOC 2 readiness program is $40,000 to $75,000 for 90 days. An assessment is $15,000 to $30,000. You get a written scope and a fixed price after the fit call, before anything is signed.
90 days from kickoff to audit-ready if you already have cloud infrastructure, source control and single sign-on in place. Starting from scratch takes 4 to 5 months. The audit window itself adds 3 to 12 months for Type II, set by you and your auditor.
Northstar works with SaaS companies under 200 employees, including B2B fintech. Hardware, government contractors and companies over 250 people get a referral to a firm that specializes in them.
It takes 30 minutes. Mara asks what is driving the work, such as a deal, an audit date, an incident or a board request. If Northstar fits, you get a written scope and price within three business days. If it does not, she names a firm that does.
Mara Chen, on every engagement. Northstar does not subcontract. Penetration tests are run by an outside firm you contract directly, and Mara coordinates them.
Yes. When a client is ready, Mara helps write the job description, sits in on interviews, and hands over the program. The engagement has a 30-day exit clause for this.
Most clients move to a one-day-a-month retainer covering quarterly reviews, preparation for the annual audit, and incident response readiness.
Book a 30-minute fit call with Mara.
Tell her what is driving the work. If Northstar fits, you get a written scope and price within three business days.