vCISO Security Risk Assessment
Be a junior security consultant. Find a company's weak spots, score them on NIST and create a deck for senior leaders.
Step into the role of a junior security consultant at a veteran-owned cybersecurity firm — running real vulnerability scans, thinking like an attacker, and delivering a client-ready findings report using the same tools and frameworks pros use every day.
No cyber experience required; you'll finish with a portfolio piece that maps directly to what entry-level security jobs actually ask for.
Project Output
This externship places students in the role of a junior security consultant at vCISO Services. You will deliver the following:
- A ten-slide audit readout, re-sequenced to open with the conclusion a client's leadership needs to hear;
- A one-page executive summary: conclusion first, method second;
- A completed 27-question customer security questionnaire, answered only with evidence you produced and mapped to NIST CSF 2.0;
- An assessment workbook with the engagement charter, asset inventory, findings register, and a consolidated, ranked risk picture.
Get Started with Onboarding Today Before Live Sessions Begin
Join this 8-week Externship with vCISO to build a client-ready Security Risk Assessment!
This Externship has passed
What past Externs have to say
Skills You'll Gain
Your Schedule


Tom Pruett
Tom is a seasoned cybersecurity executive with 20 years of experience leading security strategy across some of the most complex regulated industries in the world — including capital markets, investment banking, financial services, and healthcare. He serves as a virtual CISO at vCISO Services, LLC, a boutique, veteran-owned firm that places only senior-level security executives — professionals who have actually held the CISO title — with organizations that need expert guidance without a full-time hire. Tom works with national companies to build and mature cybersecurity programs aligned to frameworks like NIST CSF, NIST 800-53, FFIEC, and PCI DSS, and his results are concrete: a 40% reduction in critical audit findings and a 62% cut in vulnerability backlogs through strategic remediation governance.
Beyond the technical depth, Tom is a natural leader and communicator — someone equally fluent talking to a security technician or a company president. He's built multi-year roadmaps, developed teams, and is actively consulting on the emerging frontier of AI in cybersecurity governance. As a veteran, he brings a mission-first, team-oriented mindset to the work. Externs in this externship will get direct exposure to how a top-tier security executive actually operates — the frameworks, the tradeoffs, and the strategic thinking that separates a great CISO from a good one.
Get Started Today
Join this 8-week Externship with vCISO to build a client-ready Security Risk Assessment!










