Skip to main content
Service / vCISO

A vCISO engagement, led by Elissa Shevinsky.

Senior security leadership for founders, boards, and growth-stage teams. Fractional hours, senior judgment. Elissa serves as Lorikeet's Field CISO and runs the vCISO practice directly, built for companies that need a CISO voice in the room before they need a CISO on the payroll.

Field CISO
Elissa Shevinsky
Engagement
Retainer, fractional hours
Frameworks
SOC 2, ISO 27001, PCI DSS
Starts in
2 weeks or less
01 Who this is for

Companies that need CISO-grade judgment without the CISO-grade headcount.

Founders & operators

Your first security hire

You are closing enterprise deals that keep asking for a SOC 2 report, a security questionnaire, and a named executive in the room. You need a real answer, not a template.

Boards & PE

Portfolio oversight

You need a trusted security executive who can sit across multiple companies, run the program, and translate risk into numbers your LPs understand.

Engineering leaders

Cover for the gap

Your CISO left, your VP Eng is covering security on top of a day job, or you need interim leadership while you run a proper executive search.

02 Practice lead
Elissa Shevinsky, vCISO practice lead at Lorikeet Security
Field CISO
Elissa Shevinsky / Field CISO, Lorikeet Security

20+ years in the industry, shipped from the operator's chair.

Elissa has built, led, and shipped inside cybersecurity for most of her career. She served as Chief Product and Technology Officer at Cointelegraph, where she ran product and engineering for one of the most-read independent newsrooms in crypto, and as CTO for Global Growth Strategy at Yonex, a publicly traded company. Before that she was CEO of Faster Than Light, a static analysis platform built for developers who ship fast and still want their code audited before it hits production.

Earlier in her career she led product at Brave during its earliest growth, helped launch Geekcorps (acquired) and Everyday Health (IPO), and was a MACH37 portfolio founder with JeKuDo. She has keynoted BSidesCharm and spoken at DEF CON, PyCon events worldwide, and DevOpsDays events worldwide on container security, Kubernetes hardening, and the ethics of shipping secure software. She edited Lean Out (OR Books, 2015) and her bylines have appeared in TIME and the Christian Science Monitor. She holds a BA from Williams College.

At Lorikeet she serves as Field CISO and runs the vCISO practice directly. Bring a senior expert into your organization — the advice and hands-on operational support you need to protect the business.

Elissa specializes in right-sizing security initiatives to fit a company's budget and threat model. Whatever your resources, we can prioritize to create the most impact for the time and money spent.

Field CISO
Lorikeet Security
Former Chief Product & Technology Officer
Cointelegraph
Former CTO, Global Growth Strategy
Yonex (public company)
Former CEO
Faster Than Light / static analysis
Former Head of Product
Brave
Editor
Lean Out (OR Books, 2015)
Speaker
RVAsec, SecretCon
Selected talks
Also spoken at: RVAsec / SecretCon / ShmooCon / O'Reilly Solid / SXSW / Computers Freedom and Privacy / HOPE / BLOCKCON
03 What you get

A security program, owned end to end.

i/01

Security strategy & roadmap

A baseline assessment, a prioritized 12-month roadmap, and quarterly reviews tied to your business objectives.

i/02

Compliance program leadership

SOC 2 Type I and II, ISO 27001, PCI DSS, HIPAA. Auditor liaison, evidence ownership, and clean audit outcomes.

i/03

Board & investor reporting

Board decks, security questionnaire support, and the hard conversations with LPs and enterprise procurement teams.

i/04

Policy & procedure

A full policy set, built to your context and not copy-pasted from a template. Reviewed annually, updated on exception.

i/05

Third-party & vendor risk

Vendor inventory, tiering, and an approval workflow that does not grind procurement to a halt.

i/06

Incident response leadership

An IR plan your team will actually follow, tabletop exercises, and executive-level coordination when something real happens.

i/07

Security team coaching

Mentorship for your first security hires. We raise their ceiling instead of replacing them.

i/08

Offensive testing oversight

Direct pipeline into Lorikeet's pentest and ASM practices. Findings route straight into your roadmap.

i/09

On-demand executive presence

Customer calls, sales cycles, due diligence, acquisition paths. A named executive answering the security questions.

04 Engagement tiers

Three ways to bring her in.

Advisor
Strategic oversight, light touch.
~8 hours / month
  • Monthly strategy session
  • Quarterly board-ready reporting
  • Security questionnaire support
  • Slack / email access, business hours
  • Roadmap review & prioritization
Discuss scope
Interim
Dedicated cover, fixed term.
3 to 6 months, dedicated
  • Acting CISO, named on the org chart
  • Daily presence with engineering & legal
  • Runs the audit end to end
  • Hires your permanent CISO
  • Clean handoff documentation
Discuss scope
05 How it unfolds

From kickoff to owning your program, in weeks not quarters.

01 / Discovery

Scope & fit call

A 45 minute working session. We leave with a shared picture of where you are, what is on fire, and what the next 90 days look like.

Week 0
02 / Baseline

Security posture review

Controls review, architecture walkthrough, policy audit, and a prioritized gap analysis. You get the document. Your auditor does not.

Weeks 1 to 3
03 / Roadmap

Program design

A 12 month security roadmap, scoped to your compliance obligations, customer contracts, and engineering capacity.

Weeks 3 to 4
04 / Operate

Run the program

Weekly execution, monthly reporting, quarterly board updates. The roadmap becomes the calendar.

Week 5 onward
Start here

Put a real security executive in the room. This week.

Tell us what is in front of you. Audit in 60 days. Enterprise deal stuck on a questionnaire. Board asking hard questions. We will tell you honestly whether a vCISO is the right shape of help, and if it is, Elissa is on the call.

Lory waving

Hi, I'm Lory! Need help finding the right service? Click to chat!