Work with me.

Fractional CTO and vCISO engagements for pre-Series-A AI startups, built on the security and engineering function I run at my own companies: production AI delivery, cloud platform modernization, and the security posture that closes enterprise deals. Scoped around what you actually need, run without overhead.

Founding Engineer at EnergyConnect; CISO at Lavender; senior engineering at BlockFi, InsideTrack, and AAMP Global. Co-founded PopSocial — engineering 1 → 15+.

Available for fractional CTO and vCISO engagements, AI product advisory, and selective consulting.

13+

Years shipping software

Founder through CISO

100K+

Users on live AI products

At Lavender, 2023–2026

$400M+

Fintech customer assets protected

At BlockFi — identity, auth, and fraud

40K+

Telematics devices streaming data

At AAMP Global, on GCP Kubernetes

Eight engagements, scoped to your situation.

I co-founded a company and scaled its engineering team from one to fifteen-plus, then ran security as CISO through SOC 2, multi-cloud, and 100K-user AI products. The engagements below are how teams rent that — the judgment of someone who has owned the function, not just advised on it.

Advisory Retainer

Ongoing technical guidance, on call when it matters.

Weekly or bi-weekly sessions covering architecture decisions, hiring, roadmap, and whatever is on fire that week. Best for founders and VPs Eng who need a trusted technical voice without a full-time hire.

Cadence: 4–8 hours/month, month-to-month

Starts at: $3,500/mo

  • Making consequential architecture or vendor decisions
  • Scaling the engineering team and need a hiring bar
  • Need a second opinion before committing to a technical direction

Fractional CTO

Technical direction and the decisions that are expensive to reverse.

Ongoing ownership of where the architecture is going — build-vs-buy, the AI stack, the platform bets that are cheap to make and costly to undo. Board and investor conversations when the technical story has to hold up. For founders carrying the CTO role themselves who need the judgment without the hire.

Cadence: 4–8 hours/month, month-to-month

Starts at: $3,500/mo

  • Non-technical founder carrying technical decisions alone
  • Committing to an AI or infrastructure stack you'll live with for years
  • Board or diligence conversations where the technical story has to hold

Fractional Chief AI Officer

Your engineering team on AI agents, working well and safely.

Ongoing ownership of how your team adopts AI: the workflow, controls and measures your team standardizes on, whichever agents and models it picks, the review workflow that keeps agent-written code from shipping unread, the permission and audit controls a security review will ask about, and the measures that show whether any of it is working. I run four to seven agent sessions in parallel on a normal working day; this is that operating model, fitted to your team and your risk.

Cadence: 4–8 hours/month, month-to-month

Starts at: $3,500/mo

  • Engineers use AI tools ad hoc and nobody owns the standard
  • Agent-written code reaches review faster than anyone can read it
  • A customer or auditor is asking how you control AI coding tools

AI Implementation

Putting AI into the workload your business actually runs on.

Not a chatbot bolted to the marketing site — AI inside the operation that makes you money: the workflow your team repeats a thousand times a week, the review queue, the document pipeline. Model and architecture selection, the eval harness that tells you whether it works, the human-in-the-loop boundary, and the cost model before you scale it. Scoped as a project with a working system at the end.

Cadence: Project-scoped, typically 4–12 weeks

Starts at: Scoped per engagement

  • A core business workflow is expensive, repetitive, and judgment-light
  • A prototype works in a notebook and nobody knows what production costs
  • You need to know whether the AI is right before you let it run unattended

Embedded Engineering

Hands-on delivery inside your team for a fixed period.

I work alongside your engineers on a specific initiative — AI product build, cloud migration, security program — with the depth of a staff+ hire and the flexibility of a contractor. Full code, full reviews, full ownership of the outcome.

Cadence: 20–40 hrs/week, typically 6–16 weeks

Starts at: Scoped per engagement

  • Need to ship something technically complex in a compressed timeline
  • Onboarding a team to a new technology or architecture pattern
  • Backfilling a departing staff or principal engineer

Security Leadership

Security and compliance ownership for AI companies, without the full-time hire.

The security function I built from zero to SOC 2 Type II as CISO — SOC 2 from Type I to Type II, HIPAA, an ISO 27001 kickoff, security architecture, incident response readiness, and the posture that closes enterprise deals — run for your team at a fraction of a full-time hire.

Cadence: 5–10 hours/month minimum

Starts at: $2,500/mo

  • Enterprise prospects are asking for SOC 2 before signing
  • Preparing for a Series A security review
  • Security program built on good intentions rather than documented controls

Security Review Sprint

Your enterprise deal is stuck on a security questionnaire. Defensible answers in one week.

One questionnaire (SIG Lite, CAIQ or the buyer's own, up to 250 questions) answered so every answer is true today and holds up under a follow-up question. Where a control doesn't exist yet, the answer says what you do instead and when the gap closes, not "in progress." You also get the gaps ranked by how likely each is to stall this deal, the AI-specific evidence a SOC 2 report doesn't cover (the agent tool allow-list and tool-call log), and a prep call before the buyer's security follow-up. Not an audit, not a pen test, and I won't write answers that claim controls you don't have.

Cadence: Fixed scope, 5 business days

Starts at: $3,000 fixed

  • A named enterprise prospect sent a security questionnaire
  • The deal is waiting on your answers, with a date attached
  • You were about to auto-fill it and send it back

Technical Assessment

One-time audit of your stack, team, or architecture.

A structured evaluation of your current technical situation — architecture, codebase, infrastructure, team structure — delivered as a written report with a prioritized action plan. Useful before a major investment, acquisition, or strategic pivot.

Cadence: Fixed scope, 1–2 weeks

Starts at: Scoped per engagement

  • Technical due diligence ahead of an M&A or fundraise
  • Need a baseline before a large refactor or replatform
  • Evaluating a proposed architecture before committing headcount

The math

$200–400K for a full-time CISO, or $2–4K a month fractional.

Pre-Series-A founders ask the same question every intro call: do I need to hire a CISO or VP of Engineering yet? Most of the time, no — not because the work isn't needed, but because the work doesn't yet fill a full-time role. The numbers below are why fractional exists at this stage.

Full-time CISO or VP Eng

$200K – $400K loaded annual cost

  • Director-level base $180K–$280K, plus equity, plus benefits, plus the recruiter fee on the hire
  • 3–6 month time-to-hire for executives at this level
  • Over-leveled for pre-Series-A scope — most months, the work doesn't fill 40 hours

Fractional engagement

$2,500 – $3,500/mo · advisory or security leadership

  • Operator-level judgment on the actual decisions in front of you this month — not theoretical strategy
  • Start within two weeks. Graduate when the work consistently fills a full-time role (graduation criteria are in the FAQ)
  • No equity. No recruiter. No 12-month commitment.

Full argument with the make-vs-buy math is in vCISO Math for AI Founders. The graduation criteria are in the FAQ below.

How it works

From first call to a scoped fractional engagement in under a week.

01

Intro call

30 minutes, no prep required

Tell me what you're building, what's breaking, or what decision you're sitting on. I'll tell you honestly whether and how I can help. No pitch, no slides.

02

Written scope

Objectives, deliverables, time commitment

If the intro call points toward an engagement, I'll send a short scope doc within 48 hours. It covers what I'll do, what I won't do, how we'll measure success, and what it costs. No ambiguity, no surprises.

03

Engagement

Hands-on from day one

Retainers start with a structured onboarding session and a running async doc for context and decisions. Embedded work starts with a codebase triage and a shared milestone plan. You get real availability, not calendar roulette.

Common questions

What founders ask before booking a fractional engagement.

What's the difference between a fractional CTO, fractional VP Eng, and fractional CISO?

Three different jobs that get bundled together because the titles all start with the same word. A fractional CTO sets technical direction for the org — what to build, what to buy, where the architecture is going in two years. A fractional VP of Engineering runs delivery and the team — sprint cadence, hiring bar, on-call rotation, the day-to-day of shipping. A fractional CISO owns security and compliance — SOC 2, IAM, incident response, the security questionnaire that just landed. I do all three, and they price differently because they are different jobs. CTO work runs as an ongoing retainer when the decisions are continuous — you are choosing an AI stack, a platform, an architecture you will live inside for years — and as a one-time Technical Assessment when you need a single call made well and then you are fine. The retainer is the wrong purchase if your technical decisions are already settled; I will say so. If you are not sure which one you need, that is the intro call. I will tell you which it is — or that it is none of these — within 30 minutes.

What does a typical engagement look like?

Most start with a 30-minute intro call, then a short written scope doc covering objectives, deliverables, and time commitment. Advisory retainers run month-to-month with 30 days notice to wind down. Embedded work is milestone-scoped upfront.

What does a fractional CISO actually do?

Weeks 1–2: scope the engagement, inventory the controls you already have, and rank the gaps by audit-blocking severity. Weeks 3–8: build out the missing pieces — IAM, MDM, vulnerability management, the policy pack — and stand up the AI-native security layers most pre-Series-A teams don't have yet (credential scoping, prompt-injection defense, audit logging). Weeks 9–12: documentation, evidence collection, auditor fieldwork, and the security questionnaires that have been sitting in your CTO's inbox. Ongoing after week 12: incident response when something happens, vendor reviews when you sign a new tool, and the next security questionnaire that lands.

What's included in the Fractional Chief AI Officer engagement?

Owns how your company adopts AI, part-time, without a full-time executive hire. For an engineering team that means four things. Standardize the workflow, not the vendor: engineers can use whichever agent and model they prefer, because the tools trade places every few months, while the workflow, controls and measures stay fixed. Set the workflow: agents work on branches, never main, a human reviews and merges, and the handoff between agent sessions is written down instead of improvised. Put the controls in: managed permission settings a developer can't override, an allowlist for the MCP servers agents can reach, and an audit trail of what the agents did. Measure it: whether PR review time, PRs merged per week and tickets closed actually moved, rather than how many seats you bought. It runs as a month-to-month retainer at $3,500/month for 4–8 hours, the same shape as a fractional CTO, because the decisions are continuous: the tools change every quarter and the standard has to move with them.

How do you roll out coding agents like Claude Code across an engineering team safely?

Start with the controls, then widen access. First, a managed settings policy the developer can't override: denied reads for secrets, approval-skipping modes turned off, and only the hooks and MCP servers you've approved. Second, a review rule: agent-written code lands on a branch and a human reviews it before it merges, the tests always and the diff where the risk is, because the failure mode is code that compiles, looks reasonable and is subtly wrong. Third, an audit trail: Claude Code can emit telemetry that records whether a policy, a hook or a person approved each tool call, which is the evidence an enterprise security review asks for. Then pilot with a small group on real work, write down what the agents got wrong, and turn that into the team's written standard before everyone gets access. I'm a former CISO, so the security half of this isn't an afterthought; it's usually the part that unblocks the enterprise deal.

Can you help with a security questionnaire that's blocking a deal?

Yes. That's the Security Review Sprint: $3,000 fixed, five business days, one questionnaire up to 250 questions (SIG Lite, CAIQ or the buyer's own). Every answer is written to be true today and defensible on the follow-up call, because experienced reviewers read a wall of auto-filled "in progress" answers as risk, not progress. Where you don't have a control, the answer says what you do instead and when it closes. You also get the weak answers ranked by how much they could stall the deal, the AI-specific evidence your SOC 2 report wasn't scoped for, and a prep call before the buyer's security team follows up. It isn't an audit or an attestation, and I won't claim controls you don't have. If the gap list turns into a program, that's the Security Leadership retainer.

What's your typical rate?

For context: a full-time CISO at a pre-Series-A AI company runs $200K–$400K loaded, plus equity, plus a 3–6 month time-to-hire. A security consultant billing hourly runs $250–400/hour with no ongoing ownership. Advisory retainers start at $3,500/month for 4–8 hours, and so does the fractional Chief AI Officer retainer. Fractional security leadership starts at $2,500/month. A Security Review Sprint for one blocking questionnaire is $3,000 fixed. Embedded engineering is scoped at a weekly rate depending on commitment and duration. All engagements are scoped before we start — no surprise overages, no retainer creep. If the work exceeds the scope, we re-scope in writing before I do the work.

When should I switch from a fractional CISO to a full-time hire?

Four signals, any one of which tips the math. (1) Security work is consistently exceeding 20 hours a week — past that, fractional stops being cheaper than full-time. (2) You're post-Series A with a security-conscious customer base and the security executive needs to be on the org chart, not on a contract. (3) The engineering org has crossed roughly 50 engineers and security needs a permanent seat in planning. (4) You're pursuing a regulated deal (FedRAMP, HIPAA at scale, payments) that requires a named full-time executive on the agreement. Most fractional CISO engagements graduate at month 9–14. That's the goal — not the failure mode. If I'm still your on-call security executive at month 18 without one of those four signals firing, I've failed the engagement.

What does the first 30 / 60 / 90 days look like?

Day 30: scope locked, controls inventory complete, the policy pack drafted and signed, one quick win shipped (usually credential scoping for the highest-blast-radius service accounts). Day 60: gap-closure work in flight, evidence collection running in the compliance tool, the first enterprise security questionnaire answered cleanly without the CTO writing it. Day 90: ready for auditor fieldwork or the Series A security review, depending on what triggered the engagement.

Are you available right now?

I maintain a small number of active engagements at a time to ensure real availability. Book the intro call — if I'm fully committed, I'll say so directly and we can plan around it.

Do you work with early-stage companies that can't yet afford a full staff engineer?

Yes. Advisory retainers are specifically designed for this. Six hours of operator-level guidance per month on architecture, hiring decisions, and technical risk is often exactly what a seed-stage team needs before they can justify a full-time hire.

What's included in a fractional engagement, and what's billed separately?

Included: the scoped hours each month, async support over Slack or email during the engagement, every deliverable I produce (scope docs, policies, runbooks, architecture decisions, the written report at the end of an assessment), and an operator's judgment on every escalation that lands during the month. Billed separately or out of scope: penetration-test engagements (referred to specialist partners, not run by me), tooling subscriptions like Vanta, Drata, or SIEM vendors (paid by you directly, since you'll own them after I'm gone), travel for the rare on-site week, and any work past the retainer band. No retainer creep. If the work exceeds the scope, we re-scope in writing before I do the work — never after.

What's the best way to start?

Book the 30-minute intro call. Come with the specific problem you're trying to solve — not a job description, but the actual situation: what's breaking, what you're building, what's blocking you. We'll figure out from there whether and how I can help.

Tell me what you're building.

Whether you're staring down a hard technical decision, scaling pains, a security review blocking enterprise deals, or a production system that needs real attention — I'd love to hear about it. Thirty minutes, no agenda required.

Or reach me directly: jared@sublimecoding.com LinkedIn