Private Equity and Venture Capital Cybersecurity
Job description
About the role
Cfgi is seeking a Cybersecurity Consulting Manager with deep private equity and venture capital industry experience to lead and deliver high-impact advisory engagements across the investment lifecycle, from pre-deal cybersecurity due diligence and risk assessment through post-close integration, portfolio company maturity uplift, and exit readiness. This role blends hands-on delivery, executive communication, and practice leadership. You will work directly with PE/VC deal teams, operating partners, portfolio company CISOs, CIOs, CFOs, and Board/Audit Committee members to design pragmatic programs, build scalable operating models, and deliver security outcomes tied to value creation and investment thesis. The position requires a professional who can operate comfortably in fast-paced, deal-driven environments while maintaining a high standard of quality and client trust. You will be expected to translate complex risk scenarios into clear, actionable guidance that supports investment decisions and portfolio value creation. Success in this role will be measured by your ability to execute rigorous assessments, communicate effectively with executive stakeholders, and contribute to the growth of the practice.
Key facts
What you'll do
- Lead cybersecurity advisory engagements across the private equity and venture capital deal lifecycle, including pre-acquisition due diligence, post-close 100-day security planning, portfolio company maturity uplift, carve-out and stand-up activities, and exit readiness assessments.
- Conduct and manage cybersecurity due diligence for buy-side and sell-side transactions, identify material cyber risks, quantify potential exposure, and package findings for use in deal-team discussions, indemnification considerations, and representations and warranties.
- Design and operationalize cybersecurity governance models, including policies, standards, risk appetite definitions, committee structures, and key risk and performance indicators, tailored to the size and ownership model of each portfolio company.
- Build and mature enterprise risk programs by developing risk assessments, maintaining risk registers, curating control libraries, and defining control testing approaches that are appropriate for regulated and growing businesses.
- Develop and implement security policies, standards, and procedures aligned with recognized frameworks such as NIST Cybersecurity Framework, ISO 27001 and 27002, CIS Controls, SOC 2, CMMC, and FedRAMP where relevant to the portfolio.
- Support regulatory readiness and compliance initiatives specific to private equity portfolio sectors, including SEC cybersecurity disclosure rules, SOX ITGC controls for pre-IPO and public company readiness, HIPAA for healthcare investments, PCI DSS for payments-focused businesses, NYDFS 500 for financial services, and GDPR/CCPA where applicable.
- Develop investment-grade cybersecurity roadmaps and detailed remediation plans that align with private equity value-creation timelines, track progress against defined milestones, and provide clear status reporting to operating partners and deal teams.
- Advise on cybersecurity integration and separation activities for mergers and acquisitions, covering areas such as network segmentation, identity and access migration, data classification, Day 1 security controls, and TSA or ITSA cybersecurity workstreams.
- Perform vendor and third-party risk assessments and implement scalable third-party risk management operating models that are suitable for portfolio companies under private equity ownership.
- Coordinate cross-functional stakeholders, including Legal, IT, Security, Compliance, Product, and Human Resources, to drive adoption of security programs and ensure alignment with business objectives.
- Translate complex technical, regulatory, and privacy requirements into business-oriented recommendations that resonate with investment professionals and portfolio company leaders.
- Deliver executive-ready artifacts tailored to private equity and venture capital audiences, such as LP and board cybersecurity reporting, deal-team risk summaries, portfolio-wide security heatmaps, 100-day plan progress updates, and audit committee materials.
- Serve as a trusted advisor to senior leadership and C-suite stakeholders, confidently presenting findings and influencing strategic decisions related to cybersecurity and risk.
- Contribute to the development of the practice through go-to-market activities, including creating offerings, developing templates and accelerators, shaping methodologies and points of view, and producing high-quality proposal and solution documents.
- Support business development efforts by participating in proposal writing, statement of work development, client presentations, and solution shaping that highlight the firm's cybersecurity capabilities.
- Mentor and develop consultants and managers, leading project teams across multiple engagements while maintaining delivery quality, consistency, and adherence to firm standards.
- Partner with other Cfgi service lines, such as Accounting Advisory, CFO Advisory, and Technology Enablement, to deliver integrated solutions that address complex client challenges.
Requirements
- Possess six or more years of relevant experience in cybersecurity consulting, governance/risk management, or compliance, with significant direct experience serving private equity sponsors, venture capital firms, or portfolio companies in fast-paced, deal-driven settings.
- Hold a bachelor's degree in a related field as a minimum educational requirement.
- Demonstrate proven expertise across the full private equity and venture capital cybersecurity advisory lifecycle, including pre-acquisition cyber due diligence on both buy-side and sell-side transactions, post-close 100-day security planning, and integration and carve-out cybersecurity engagements.
- Show strong capability in framework implementation and operationalization, with hands-on experience applying NIST Cybersecurity Framework, ISO 27001 and 27002, SOC 2, and CIS Controls in real-world environments.
- Bring familiarity with privacy and regulatory requirements common to private equity portfolio company sectors, such as HIPAA, GDPR and CCPA, SOX ITGC controls, PCI DSS, and NYDFS 500; deep, hands-on privacy program build-out experience is not required.
- Have direct experience performing or leading cybersecurity due diligence, risk assessments, control evaluations, and vendor risk assessments for portfolio companies across multiple industries and maturity levels.
- Exhibit strong written and verbal communication skills, with the ability to produce clear, concise, and decision-ready reports, risk summaries, and board-level materials under tight timelines.
- Demonstrate the ability to manage multiple engagements simultaneously, prioritize effectively in a dynamic environment, and maintain attention to detail and accuracy in all deliverables.
- Show experience collaborating with cross-functional stakeholders, including legal, finance, IT operations, compliance, and business unit leaders, to implement security programs that support business growth.
- Be comfortable with travel to client sites as required and able to work in the United States in compliance with applicable employment and visa regulations.
Nice to have
Only include preferences explicitly mentioned in the source material.
Practical notes
- Hours: Full Time
- Travel: Travel to client sites as required
- Visa: Must be able to work in the United States in compliance with applicable employment and visa regulations
- Deadlines: None specified