Home: Northstar Security Advisors
Northstar Security Advisors

Part-time CISO (vCISO)

Mara joins your leadership meeting every week, owns the security roadmap, and answers customer security questions for you.

Length
6 to 18 months
Price
$8,000 to $18,000 a month
First 30 days
Discovery in weeks 1 and 2, roadmap in week 3, weekly cadence from week 4. Mara leads the engagement herself from the first call.

Who this fits

A vCISO engagement fits SaaS companies with 50 to 200 employees that need someone to own security before they can justify a full-time hire. It usually starts when a SOC 2 audit is coming, enterprise questionnaires are piling up, or the board asks who is responsible for security. Your leadership team typically has a CTO and engineering managers and no one with security in their title.

What is included

  • One day a week, two during audit preparation or a large customer review
  • Security policies and procedures, written by Mara
  • Tool and vendor selection: compliance platforms, endpoint tools, managed detection
  • Customer-facing work: questionnaires, prospect calls, auditor calls
  • A quarterly security review with your leadership team
  • Incident response lead if something happens

When a part-time CISO makes sense

Most SaaS companies with 50 to 200 employees reach a point where the CTO can no longer cover security on the side. A prospect requires SOC 2. An incident shows a gap. The board asks for a written program. A full-time CISO is a senior executive hire, and at that stage the work fills about one day a week. A vCISO covers that day.

How a week looks

After the first three weeks, the engagement settles into a weekly rhythm: Mara attends your leadership meeting, reviews open questionnaires, moves policy and control work forward, and checks in with whoever owns the current roadmap item.

Everything she produces lives in your systems: your wiki, your ticket tracker, your compliance platform. If the engagement ends, the program stays with you.

When the engagement ends

Most clients move to a one-day-a-month retainer after the first year to keep the program running and prepare for the annual audit. Some hire a full-time security lead, and Mara helps write the job description and interview candidates.

The first three phases

Every vCISO engagement opens with the same phases of the Northstar Maturity Framework.

  1. 1Discovery 2 weeks

    Data-flow map, frameworks in scope, and where your program stands today.

    You keep: Discovery Document, 6 to 12 pages

  2. 2Roadmap 1 week

    Prioritized work with owners and a budget, reviewed with your leadership team.

    You keep: 12-month roadmap

  3. 3Build 8 to 16 weeks

    Policies written, controls configured, and your compliance platform collecting evidence.

    You keep: Policies, controls and evidence collection in place

Other services

  • SOC 2 readiness program

    A 90-day program that takes you from no formal compliance work to ready for a SOC 2 Type II audit window.

    Length
    90 days to audit-ready
    Price
    $40,000 to $75,000, fixed after scoping
  • Security assessment

    A 2 to 3 week review of your security against NIST CSF, CIS Controls or SOC 2, delivered as a written report with a ranked list of fixes.

    Length
    2 to 3 weeks
    Price
    $15,000 to $30,000
  • Security awareness training

    Live onboarding sessions, quarterly phishing tests and short monthly scenarios, written for engineering-heavy teams.

    Length
    12 months, renewed yearly
    Price
    $24,000 to $48,000 a year

Common questions

Anything else goes on the fit call, or email hello@northstar-demo.example.

A vCISO engagement is $8,000 to $18,000 a month depending on scope. A SOC 2 readiness program is $40,000 to $75,000 for 90 days. An assessment is $15,000 to $30,000. You get a written scope and a fixed price after the fit call, before anything is signed.

90 days from kickoff to audit-ready if you already have cloud infrastructure, source control and single sign-on in place. Starting from scratch takes 4 to 5 months. The audit window itself adds 3 to 12 months for Type II, set by you and your auditor.

Northstar works with SaaS companies under 200 employees, including B2B fintech. Hardware, government contractors and companies over 250 people get a referral to a firm that specializes in them.

It takes 30 minutes. Mara asks what is driving the work, such as a deal, an audit date, an incident or a board request. If Northstar fits, you get a written scope and price within three business days. If it does not, she names a firm that does.

Mara Chen, on every engagement. Northstar does not subcontract. Penetration tests are run by an outside firm you contract directly, and Mara coordinates them.

Yes. When a client is ready, Mara helps write the job description, sits in on interviews, and hands over the program. The engagement has a 30-day exit clause for this.

Most clients move to a one-day-a-month retainer covering quarterly reviews, preparation for the annual audit, and incident response readiness.

Book a 30-minute fit call with Mara.

Tell her what is driving the work. If Northstar fits, you get a written scope and price within three business days.

Book a 30-minute fit call