← All jobs
vCIO Advisor
Urbandale, Iowa · Hybrid · Full-Time · Managed Services
Apply well, not just fast
Create a free account and upload your resume to get a match score, keyword gaps, a tailored resume, a cover letter and interview prep for this job.
About the role
Account ManagementHIPAANegotiationBudgetingRisk Management
vCIO Advisor
About Dymin
Dymin Systems, Inc. is a managed service provider in Urbandale, Iowa, serving small and mid-sized businesses across Central Iowa. Our vCIO service line gives clients a named technology leader for strategy, budgeting, security, and compliance planning.
Role summary
Dymin Systems is hiring a vCIO Advisor to own day-to-day, client-facing vCIO delivery for an assigned group of clients. The Advisor is the named technology-strategy lead for those clients, delivering assessments, roadmaps, budgets, security and compliance planning, and recurring executive reviews.
Title
vCIO Advisor
Reports to
Chief Information Officer
Works with
Account management, Service Delivery, Innovations, Security
Location
Urbandale, IA (hybrid; on-site client meetings across Central Iowa)
Client base
Small and mid-sized businesses served by Dymin's vCIO service line
The Advisor is a consultant and delivery owner, not a help desk escalation point and not a project engineer. Hands-on remediation belongs to Service Delivery; the Advisor scopes it, sponsors it, and holds it to the roadmap.
Core responsibilities
The Advisor owns every recurring client-facing deliverable in the vCIO SOW for an assigned client book.
Strategic advisory and roadmap ownership
- Build and maintain a 12 to 36 month technology roadmap per client, tied to business goals and reviewed at least annually.
- Own the annual technology budget: lifecycle replacement, licensing, security spend, and project forecasting.
- Translate client business changes (growth, acquisition, new location, compliance pressure) into technology decisions and scoped work.
Assessment and risk management
- Run onboarding and annual assessments: infrastructure, Microsoft 365 licensing and tenant health, backup and recovery, identity, endpoint, and network.
- Maintain a living risk register per client with owner, severity, and remediation status; escalate unaccepted risk in writing.
- Map client posture to the relevant framework (CIS Controls v8, NIST 800-171, HIPAA Security Rule, PCI DSS, CMMC) as a gap analysis. Framework mapping only; the role makes no legal or compliance attestations.
Security and compliance program delivery
- Operate Dymin's primary vCIO platform (Cynomi) as the system of record for assessments, policies, and remediation tracking.
- Drive policy, awareness training, incident-response planning, and tabletop exercises to completion, not just to draft.
Executive reviews and client communication
- Lead scheduled executive business reviews with client leadership and prepare the materials.
- Serve as the client's named point of contact for strategy, escalations that are strategic in nature, and vendor and licensing questions.
- Write executive-grade documents: risk assessments, remediation roadmaps, board and leadership summaries.
Delivery coordination and vendor management
- Convert roadmap items into scoped work and hand off to Service Delivery with clear acceptance criteria; verify completion against the roadmap.
- Manage client relationships with third-party vendors (ISP, line-of-business software, telecom, hardware) at the advisory level.
- Flag service delivery failures affecting a vCIO client to the CIO and Service Delivery leadership with specifics.
Account health and growth
- Track deliverable completion, client satisfaction, and renewal risk for the assigned book.
- Identify expansion opportunities (projects, security services, additional advisory scope) and pass them to account management with a scoped recommendation.
Qualifications
Required
- 7+ years in IT, including 3+ years in a client-facing advisory, vCIO, consulting, or IT management role in an MSP or professional-services environment.
- Working depth in Microsoft 365 (Entra ID, Intune, Defender, licensing and SKU design), Windows Server and virtualization, networking, and backup and recovery.
- Working knowledge of CIS Controls v8 and NIST 800-171, and ability to run a gap assessment and turn it into a sequenced remediation plan.
- Demonstrated ability to write executive-quality documents and present to non-technical business owners without losing the technical substance.
- Budgeting experience: lifecycle planning, licensing forecasts, and project cost estimation.
- Comfortable owning a client book of concurrent relationships with recurring deadlines, without daily supervision.
Preferred
- Prior vCIO or fractional CIO experience at an MSP.
- Experience with vCIO or compliance platforms (Cynomi or comparable), PSA tooling (HaloPSA or comparable), and Power Automate or PowerShell for repeatable delivery.
- Exposure to HIPAA Security Rule, PCI DSS, or CMMC framework mapping.
- Vendor and contract negotiation experience.
- Certifications such as CompTIA Security+, Microsoft (MS-102, SC-300, AZ-104), CISSP, or CCSP. Certification is not a substitute for experience.
Competencies
- Writes clearly and decisively; states a recommendation, not just options.
- Holds a line with clients on scope, risk acceptance, and budget.
- Follows a documented process and improves it; does not rely on memory or heroics.
- Escalates early, with specifics, when delivery is at risk.