ATALAIA
  1. Home
  2. Resources
  3. Blog
  4. What a fractional security lead does in a month
Program · Guide

What a fractional security lead does in a month

The weekly rhythm, rituals and deliverables of a part-time security lead, and how the role is designed from day one to hand over to a full-time hire.

4 min readAtalaia team

Fractional leadCadenceHandover

Fractional security leadership sounds vague until you see the calendar. A senior person works a few days a month inside your organisation, owns security direction and decisions, and makes sure the work gets done by the teams who already do the engineering. The value comes from rhythm: the same rituals, at the same times, producing the same artefacts.

This guide describes a typical month, the deliverables you should expect from it and how the engagement ends with a handover to a full-time hire.

The cadence

A part-time lead cannot be everywhere, so the week is designed around a few fixed points rather than an open inbox.

WhenRitualWhoOutput
Week 1, day 1Planning day on site or on callLead, engineering leadershipPriorities for the month, agreed in writing
Weekly, 30 minutesSecurity check-inLead, champions, platform ownerBlockers cleared, backlog reordered
Weekly, 30 minutesOffice hoursAny engineerDesign questions answered, reviews booked
As neededAsync review queueLeadComments on design docs and risky pull requests
Last weekMonthly reviewLead, CTO or VP EngineeringOne-page report, decisions logged

Between those points the lead is reachable for incidents and urgent decisions, with an agreed response window. Everything else waits for the next check-in, which is what keeps the role sustainable on a few days a month.

A month, week by week

  1. Week 1: planReview last month's report, update the risk register, agree three to five priorities with engineering leadership.
  2. Week 2: designRun a threat modelling session on the riskiest change in flight, and review open design documents.
  3. Week 3: lineCheck the build and release stations: scanner coverage, triage queue, pipeline permissions, exceptions near expiry.
  4. Week 4: reportWrite the monthly report, hold the review, record decisions and answer outstanding customer or audit questions.

The order matters. Planning first means the in-between weeks are spent on agreed work, and reporting last means the report reflects what actually happened.

Deliverables you should expect

Each month should leave the same small set of artefacts, so that progress is visible and the eventual handover is easy.

  • Risk register update. New risks, changed ratings, owners and next actions. Short enough to read in the monthly review.
  • Security backlog. Ordered work items in the teams' own trackers, not a separate security list.
  • Decision log. Each significant call, such as accepting a risk, granting an exception or choosing a tool, with the reasoning and who agreed.
  • One-page report. Priorities, what moved, the few program measures you track, and what needs a decision.
  • Customer and audit answers. Questionnaire responses and evidence prepared from the same sources, so answers stay consistent.
# decision-log.md entry format
## 2026-09-18  Accept: legacy admin panel without SSO until Q1
Context:  panel is internal-only, behind VPN, five named users
Decision: accept risk until 2027-01-31, add access review monthly
Owner:    platform lead
Agreed:   CTO, security lead
Review:   2027-01-15

Who does what

The most common failure is a fractional lead who quietly becomes the only person doing security work. That does not scale and makes handover painful. The split we recommend:

  • The lead owns direction, priorities, risk decisions and the standards teams build against.
  • Engineering teams own changes to code, pipelines and infrastructure, with the lead reviewing where risk is high.
  • Security champions own day-to-day questions in their team and escalate to the lead at check-ins.
  • Leadership owns accepting residual risk, with the lead making the recommendation.

How the handover works

A fractional engagement should be designed to end. Handover usually starts once the baseline is in place and the workload clearly justifies a full-time role.

  1. Define the role. Use the decision log and backlog to write a job description grounded in the real work, and choose the right profile.
  2. Support hiring. Help design the interview loop, including a practical exercise based on your own systems, and sit on the panel.
  3. Write the state of the program. A short document covering risks, controls in place, open decisions, measures and known gaps.
  4. Overlap. Run a few cycles of the monthly rhythm together, with the new hire leading and the fractional lead reviewing.
  5. Step back. Hand over every ritual and artefact, then remain available for an agreed period for questions.

Done well, the new hire inherits a working station on the line rather than a blank page, and can spend their first quarter improving it instead of discovering it.

What to do on Monday

  • If you have a fractional lead, check that the five artefacts above exist and live in your systems.
  • If you are considering one, write down the decisions you currently have nobody to make. That list defines the engagement.
  • Agree the handover trigger now, such as the point the workload becomes full-time, so it is not left to chance.

Where this sits on the line

In the tower (in development):

Talk it through

A 30-minute call. No slides, no price list, and a next step either way.