Partner Program

Bring your experience. We will bring the clients.

SecComply places experienced security leaders into fractional CISO engagements with our clients. You lead the security function. We handle the client relationship, the delivery bench, the tooling and the paperwork.

  • Security leaders across India, UAE, Europe and the US
  • Engagements from ISO 27001 and SOC 2 through to full CISO office ownership
  • Backed by a delivery team of GRC, AppSec, VAPT and cloud specialists

What this is

A network of security leaders, not a job board

Most companies that need a CISO cannot justify a full time one. They need someone senior for a few days a month who can set direction, answer the board, sign off on risk decisions and stand in front of an auditor. That is the work we are placing people into.

Independent by design

When you join the network, you stay independent. You choose the region you want to work in, the industries you are comfortable with and how much time you can give. When a client engagement matches your profile, we bring it to you. If it fits, you take it. If it does not, you pass and we go to the next person on the panel.

Client-facing authority

We are not reselling your CV. You are introduced to the client as the security leader for their engagement, working under the SecComply contract with our team behind you.


Why join

What you get out of it

Client flow without business development

You spend your time on security work instead of proposals, follow ups and chasing procurement. Our sales team fills the pipeline.

A delivery bench behind you

Policy drafting, evidence collection, VAPT, cloud reviews, application testing and audit coordination are done by our consultants. You direct the work rather than doing all of it yourself.

Platform access

Every engagement runs on our GRC platform, so control mapping, evidence, and posture reporting are in one place. You get a client dashboard instead of a folder of spreadsheets.

Methodology and templates that already exist

Policy sets, risk registers, board reporting packs, audit checklists and framework mappings for ISO 27001, ISO 27701, ISO 42001, SOC 2, DPDP, GDPR, HIPAA, PCI DSS and NIST CSF. You are not rebuilding the same artefacts for every client.

Clear commercials

Fees are agreed in writing before you accept an engagement, and paid on a fixed monthly cycle. Contracting, invoicing and collections sit with us.

Work you choose

You tell us the region, the industries and the number of days a month. We only bring you engagements that match.


The work

A typical engagement

  • Commitment2–5 days a month
  • Term6–12 months
  • ModeRemote first

Most fractional engagements run between two and five days a month, over a term of six to twelve months. Depending on the client, the work covers:

Lead the function
  • Security strategy and a twelve month roadmap the management team has signed off on
  • Risk register ownership, including the decisions on what gets accepted and what gets funded
Represent the programme
  • Board, management and investor reporting
  • Policy and control framework ownership
  • Certification and audit ownership for ISO 27001, SOC 2, DPDP or the framework the client is chasing
  • Customer security reviews, questionnaires and due diligence responses
Guide readiness
  • Third party and vendor risk decisions
  • Incident readiness, tabletop exercises and the escalation path when something goes wrong
  • Guiding the client's internal IT or engineering team on what to fix first

You are the decision maker and the face of the security function. Execution is shared with our delivery team.


Fit

Is this a fit for you?

We are usually a match if:
  • You have twelve or more years in cybersecurity, with at least three in a leadership role
  • You have run a security program end to end, not just one specialism
  • You have held a CISO, Head of Security, Security Manager or equivalent role, or consulted at that level
  • You are comfortable in front of a board, a customer and an auditor
  • You have working depth in at least two of ISO 27001, SOC 2, DPDP, GDPR, HIPAA, PCI DSS or NIST CSF
  • You can commit a predictable number of days each month

How it works

From registration to first engagement

01

Register

Fill in the form below. Name, email, phone and the region you want to work in is all we need to start.

02

Introduction call

A thirty minute conversation with our team on your background, the kind of clients you want, your availability and your commercial expectations.

03

Empanelment

We take your detailed profile, two professional references, a signed NDA and the partner agreement. Once that is done you are on the panel.

04

Matching

When a client engagement comes in that matches your region, industry and availability, we share the brief with you. You decide whether to take it.

05

Engagement

You are introduced to the client, the scope and fee are confirmed in writing, and the engagement starts. Our delivery team and platform support you from day one.

Typical time from registration to empanelment is two weeks. Time to first engagement depends on demand in your region.


Engagement models

Three ways to work with us

01

Fractional vCISO

You own the client's security function on a part time basis. Strategy, risk, reporting, audits and the security roadmap sit with you.

02

Advisory and on call

A fixed number of hours each month for guidance, design reviews, escalations and management reporting. Suited to clients who have an internal team but no senior leader.

03

Program lead

You lead a specific program such as ISO 27001, SOC 2 Type II or DPDP readiness, with our consultants doing the implementation and evidence work under your direction.


Division of work

What we handle, what you handle

01

SecComply handles

  • Finding and closing the client
  • Contract, scope and commercial terms
  • Invoicing, collections and your payout
  • Delivery team for GRC, VAPT, AppSec and cloud
  • Platform, templates and methodology
  • Auditor and CPA coordination
  • Escalation support if an engagement goes sideways
02

You handle

  • The security strategy and roadmap
  • Risk decisions and prioritisation
  • Board and management reporting
  • Direction of the delivery team on that account
  • Client relationship on security matters
  • Audit readiness and sign off
  • Availability as agreed in the engagement

Regions

Where we are placing security leaders

Tell us your preferred region in the form and we will match accordingly.

  • India

    Pune, Mumbai, Bengaluru, Delhi NCR, Hyderabad, Chennai, Ahmedabad, Kolkata

  • UAE and Gulf

    UAE, Saudi Arabia, Qatar

  • Europe and UK

    Remote-first, with onsite time for boards and audits

  • United States

    Remote-first, with onsite time for boards and audits

  • Bangladesh

    Remote-first, with onsite time for boards and audits

  • Remote only

    Engagements that run entirely remotely, wherever you are based

Most engagements are remote first, with periodic onsite time for board meetings, audits and workshops.


Register

Join the network

Four details to start. If your profile fits, we will get in touch within three working days to set up an introduction call.

Region you want to work in
Choose every region you would take an engagement in.

Changed your mind later? You can ask us to remove your details at any time via this form or by writing to info@seccomply.net.

FAQs

Questions security leaders ask us

No. There is no joining fee, no listing fee and no charge for platform access during an engagement.
No. You can keep your own clients and work with other firms. The only restriction is on directly approaching a client we introduced you to, outside the SecComply engagement, for the duration of the agreement and a period after it.
Most fractional engagements are between two and five days a month. Program lead engagements can be heavier during audit windows. The commitment is agreed before you accept.
On a fixed monthly cycle against the engagement, on terms set out in the partner agreement. Payment is not linked to whether the client has paid us.
Yes, as long as you have the availability and there is no conflict between the clients.
You can register, and we will keep your details on the panel. We would only take you into an engagement once you are free to do so and there is no conflict with your employer.
Tell us early. We will either bring in support from our delivery team, restructure the scope, or transition the engagement to another partner. Nobody benefits from a bad fit continuing.
Yes. We serve clients in India, the UAE, Europe, the US and Bangladesh, and we are building the panel in each of those regions.
No. This is an independent partner arrangement, not employment. The partner agreement sets out the terms.

Ready to take on your first engagement?

Registration takes two minutes. The conversation that follows tells us both whether this is a fit.