🎁 Give the gift of Extern 🎁
Security Risk Assessment
Vulnerability Prioritization
Email Security
Compliance & Audit Readiness
Credential Breach Checks
Attack Surface Mapping

vCISO Security Risk Assessment

Be a junior security consultant. Find a company's weak spots, score them on NIST and create a deck for senior leaders.

8 weeks
Live Sessions Start
October 26, 2026

Step into the role of a junior security consultant at a veteran-owned cybersecurity firm — running real vulnerability scans, thinking like an attacker, and delivering a client-ready findings report using the same tools and frameworks pros use every day.

No cyber experience required; you'll finish with a portfolio piece that maps directly to what entry-level security jobs actually ask for.

Project Output

‍

This externship places students in the role of a junior security consultant at vCISO Services. You will deliver the following:

‍

- A ten-slide audit readout, re-sequenced to open with the conclusion a client's leadership needs to hear;

- A one-page executive summary: conclusion first, method second;

- A completed 27-question customer security questionnaire, answered only with evidence you produced and mapped to NIST CSF 2.0;

- An assessment workbook with the engagement charter, asset inventory, findings register, and a consolidated, ranked risk picture.

Get Started with Onboarding Today Before Live Sessions Begin

Join this 8-week Externship with vCISO to build a client-ready Security Risk Assessment!

This Externship has passed

What past Externs have to say

Erik Schalk
Beats by Dre Extern
"Extern played a crucial role in bridging the gap between my formal business education & real-world application. The opportunity to present actionable recommendations to the Head of Customer Insights at Beats by Dre was invaluable, propelling my leadership journey and paving the way for my current role at Rolls-Royce.”
Now a Project Lead
at Rolls-Royce
Tori Nguyen
AT&T Extern
“I credit the Externship as the sole reason I was hired to intern at AT&T. I had never heard of the AT&T internship program and would never have applied to it if I hadn’t gone through the Externship. It allowed me to develop my skills, showcase my work and ultimately stand out so I was awarded the opportunity to interview the CEO of AT&T!”
Became an intern
at AT&T
Richard Wilson
Meta Extern
"The Externship is a great way to introduce students to what it is like to work on a project. I became a lot more data-focused and analytical in my approach. As an industrial engineering major, people questioned how the externship was related to my studies. My journey has shown me that you don’t have to be limited by your major."
Now a Technical
Program Manager at Meta
Maisa Mirza
HP Tech Ventures Externship
“During my venture capital externship, I learned how to use industry-standard metrics and tools like SQL and Tableau to determine startup success potential.This opportunity helped me stand out as a candidate and opened new doors for me - including offers from EY and Accenture."
Now an Analyst
at Accenture
Garrett Boyce
HP Tech Ventures Externship
“If I hadn’t done a VC externship during term time, I know I’d be spending hours watching YouTube videos just to understand which careers I might enjoy! I don’t think I fully understood the value of an externship till I actually did one and now I want to argue that externships should be a part of the college experience for every student.”
Now an Analyst at Boston Consulting Group
Diego Juarez
Crafted Capital Externship
“My Externship really changed my career trajectory. As students, we often chase after Fortune 500 work experiences, but the intimate experience of getting to work with a startup can actually really help you learn a lot and level up what you can bring to the table. My cohort even had the opportunity to speak with the founder of Crafted Capital and learn from his firsthand experience.”
Now a CLDP Analyst at
JP Morgan Chase & Co

Skills You'll Gain

Defining the scope of a security assessment and writing the boundary down, including what is deliberately excluded.
Building an asset inventory from incomplete records that contradict each other, and documenting the conflicts.
Mapping an organization's internet-facing attack surface using certificate transparency logs, internet scan data and breach records.
Triaging a vulnerability scan by real-world exploitability, using the CISA KEV catalog rather than CVSS base score alone.
Scoring an organization against NIST CSF 2.0, and separating a control that operates from a rule that only exists on paper.
Judging whether a security claim can be proved, and telling weak evidence from no evidence at all.
Answering a customer security questionnaire with evidence rather than assertion, each answer mapped to a framework reference.
Prioritizing security risks by business impact rather than technical severity.

Your Schedule

8 weeks
What Do They Have?
—
Agree your scope, write the engagement charter, and build the first real asset inventory from two client records that disagree (Week 1)
Is It Looked After?
—
Map the client's internet exposure from public records, then triage a real scan down to the eight findings that matter (Weeks 2–3)
Does the Policy Match Reality?
—
Test which policy rules actually operate, then score the business against NIST CSF 2.0 (Weeks 4–5)
Can They Prove Any of It?
—
Grade eight client claims against real evidence files and rewrite the answers so they hold up (Weeks 6–7)
What Matters Most?
—
Consolidate your findings into a ranked risk picture and deliver the readout and one-page executive summary (Week 8)

About vCISO

The Home Depot is not accepting or considering any applications for this Externship through other channels.
Meet Your Host

Tom Pruett

Virtual CISO, vCISO Services

Tom is a seasoned cybersecurity executive with 20 years of experience leading security strategy across some of the most complex regulated industries in the world — including capital markets, investment banking, financial services, and healthcare. He serves as a virtual CISO at vCISO Services, LLC, a boutique, veteran-owned firm that places only senior-level security executives — professionals who have actually held the CISO title — with organizations that need expert guidance without a full-time hire. Tom works with national companies to build and mature cybersecurity programs aligned to frameworks like NIST CSF, NIST 800-53, FFIEC, and PCI DSS, and his results are concrete: a 40% reduction in critical audit findings and a 62% cut in vulnerability backlogs through strategic remediation governance.

Beyond the technical depth, Tom is a natural leader and communicator — someone equally fluent talking to a security technician or a company president. He's built multi-year roadmaps, developed teams, and is actively consulting on the emerging frontier of AI in cybersecurity governance. As a veteran, he brings a mission-first, team-oriented mindset to the work. Externs in this externship will get direct exposure to how a top-tier security executive actually operates — the frameworks, the tradeoffs, and the strategic thinking that separates a great CISO from a good one.

Meet Your Host

Get Started Today

Join this 8-week Externship with vCISO to build a client-ready Security Risk Assessment!

This Externship has passed