Company

About Eldritch Security

Boutique fractional CISO and GRC consulting, led by Stephen Zawolik.

Stephen Zawolik

Founder · Practicing vCISO · Eldritch Security (since 2022)

Stephen is a cybersecurity executive and practicing vCISO with 15+ years leading security governance, risk, identity, and operational resilience. He works with mid-market and growth organizations — especially across global financial institutions and healthcare — that need senior cyber risk leadership without standing up a full security department.

Day to day that means board-ready risk reporting, GRC programs (including Archer experience), and M&A / divestiture security and identity separation at scale — kept qualitative and practical, sized to your buyers and stage. Dual master’s degrees (MBA and M.S. in Cybersecurity & Information Assurance) sit alongside selective credentials: CISSP, CISA, CEH, and CHFI.

Eldritch Security has been operating since 2022 as a deliberately boutique practice: direct access to the person doing the work, and a clear line against MSP and monitoring theater.

Focus

  • Fractional / practicing vCISO.
  • Board-ready risk reporting.
  • GRC programs (incl. Archer).
  • Assessments & roadmaps.
  • M&A / divestiture security & identity separation.

Credentials

  • CISSP
  • CISA
  • CEH
  • CHFI
  • MBA
  • M.S. Cybersecurity & Information Assurance

Frameworks We Work In

  • NIST CSF
  • SOC 2 (advisory / prepare)
  • PCI DSS
  • HIPAA
  • Fractional CISO
  • GRC
  • GRC & Assessments

DFW-based. Offering both remote and onsite engagements.

LinkedIn →