Max HumphreyFractional CTO, GRC & PMO
Book a call LinkedIn ↗
Services Experience Case Studies Free Assessment Contact LinkedIn Book a call →
Fractional CTO, GRC & PMO Advisor

Technology leadership, risk governance, and project delivery, without the full-time overhead.

I help growing companies run secure, well-governed technology operations — stepping in as a fractional CTO to lead infrastructure and IT strategy, or as a fractional GRC lead to build out risk, compliance, and third-party vendor programs.

Editorial illustrated portrait of Max Humphrey, fractional CTO, GRC & PMO advisor
Verified practitioner — CTO, GRC, and PMO — certified CISSP, CompTIA Security+, Network+, and PenTest+
Max Humphrey
What I Do

Three disciplines. One accountable partner.

Engage me for ongoing fractional support or a defined-scope project — whichever matches where your organization is today.

Fractional CTO

IT & Infrastructure Leadership

Hands-on technology leadership for companies that need senior direction without a full-time executive hire.

  • IT strategy, roadmap, and budget ownership
  • Data center, cloud, and infrastructure operations oversight
  • Business continuity & disaster recovery planning
  • Vendor, MSP, and internal team management
  • Capacity planning and system reliability (uptime, monitoring, redundancy)
  • Technology due diligence for M&A and vendor consolidation
Learn more →
Fractional GRC

Governance, Risk & Compliance

Practical GRC programs built around recognized frameworks — sized to your team, not a Fortune 500 department.

  • Third-party / vendor risk management program design
  • SOC 2, ISO 27001, NIST 800-53 & NIST CSF control mapping
  • Security questionnaires, SIG assessments & residual risk reporting
  • Executive and board-level risk reporting
  • Policy, process & procedure development
  • GRC tooling: ServiceNow VRM, OneTrust, RiskRecon, BitSight
Learn more →
Fractional PMO

Project & Program Delivery

Standing up or right-sizing a PMO so projects ship on time, on budget, and with visibility leadership can actually use.

  • PMO framework design — intake, prioritization, and governance cadence
  • Project & program charters, scope, and stakeholder alignment
  • Portfolio-level risk, issue, and change management
  • Resource and capacity planning across concurrent initiatives
  • Executive and steering-committee reporting (status, RAID, roadmaps)
  • PMO tooling: Smartsheet, MS Project, Jira, Asana, monday.com
Learn more →
How I Work

Built for accountability, not busywork

Max Humphrey laughing, illustrated portrait
Framework §1

Executive-ready reporting

Risk and operational posture communicated in language business stakeholders and boards can act on, not just technical teams.

Framework §2

Metrics over meetings

Programs are run against clear SLAs and measurable outcomes: risk closure rates, uptime targets, and backlog reduction — not status theater.

Framework §3

Framework-grounded

Every engagement maps to recognized standards — NIST 800-53, NIST CSF, FFIEC, PCI, ISO 27001, SOC 2 — so controls hold up to audit and stakeholder scrutiny.

Background

Experience

Track record leading IT operations and third-party risk programs at a global SaaS platform and a $1B+ financial institution.

Max Humphrey, confident illustrated portrait

Third-Party Risk Manager

Autodesk

Led combined US/India teams to close 100% of open vendor risk items within SLA; built Autodesk's third-party AI risk criteria and 3-year TPRM strategy; delivered quarterly risk reporting to the executive committee.

Associate Vice President, IT Service Delivery

San Francisco Fire Credit Union

Owned all data center operations and cybersecurity programs for a $1B+ credit union; maintained 99.99% uptime; managed six internal and external teams; built the credit union's first secure ACH transmission room and 24/7 incident response operation.

IT Service Delivery Manager & IT Operations Manager

San Francisco Fire Credit Union

Wrote the credit union's first disaster recovery plan, led a 50+ application data center migration, deployed its first Web Application Firewall, and migrated critical infrastructure from Windows Server 2003 to 2016.

Questions

Before you book a call

Fractional CTO, GRC, and PMO leadership — three disciplines few providers combine under one relationship.

What does a fractional CTO do?

A fractional CTO owns technology strategy and infrastructure decisions the way a full-time CTO would: IT roadmap, budget, vendor management, business continuity. It's sized to what your organization needs right now, not a full-time seat.

What does a fractional GRC advisor do? Is that the same as a virtual CISO (vCISO)?

A fractional GRC advisor builds and runs your governance, risk, and compliance program: third-party risk, SOC 2/ISO 27001/NIST control mapping, policy development, board-level risk reporting. It overlaps with what's often called a virtual CISO, though GRC is the more accurate term for the scope — program and controls ownership, not incident response or managing a security team.

What does a fractional PMO do, and do I need one?

A fractional PMO builds the project-management function itself: intake, prioritization, governance cadence, executive reporting. That's different from staffing one project manager. If you're running multiple initiatives at once and nobody above the project level has real visibility into risk or status, that's usually the sign you need one.

How is this different from hiring a consultant who writes a report and leaves?

Every engagement starts with your own framing of the problem you're trying to solve, not a standard package, and is judged on the deliverables and outcomes that move the needle, not hours logged. I own the program the way an in-house hire would, for as long as the engagement runs.

How much does a fractional engagement cost?

It depends on scope, not a fixed menu — a narrowly-defined project and an ongoing fractional seat are priced very differently. Book an introductory call and I'll give you a straight answer once I understand what you're trying to solve.

Do you work with companies outside Asheville, NC?

Yes. I'm based in Asheville, NC and available remotely for organizations anywhere.

Let's Talk

Ready to bring senior IT and GRC leadership in-house — fractionally?

I take on a limited number of clients at a time so every engagement gets real attention. Reach out to discuss scope, cadence, and fit.

Asheville, North Carolina and Remotely available · max.humphrey@gmail.com