Opportunity
East Palo Alto Municode #EPA vCISO Support Services
City of East Palo Alto Seeks vCISO Professional Services for Five-Year Contract
Posted
July 31, 2026
Respond By
August 27, 2026
Identifier
EPA vCISO Support Services
NAICS
541690
The City of East Palo Alto is seeking a qualified firm to provide virtual Chief Information Security Officer (vCISO) professional services under a five-year contract. - Government Buyer: - City of East Palo Alto, Information Technology Division - City Manager's Office is the primary contracting office - Scope of Services: - Establish and maintain a cybersecurity governance program aligned with NIST CSF 2.0 - Conduct ongoing risk assessments and update cybersecurity policies - Oversee technical and administrative safeguards - Advise on monitoring tools and develop/test incident response and business continuity plans - Assess vendor cybersecurity posture and provide regular reporting to city leadership - Evaluate employee cybersecurity training and conduct biweekly security governance meetings - All deliverables become property of the City - Requirements: - Firms must demonstrate experience in public sector technology consulting, preferably with California local government - Proposals must include firm qualifications, engagement approach, team structure, relevant experience, and detailed cost proposal (hourly and retainer options) - Consultant must be registered with the California Secretary of State and hold a current City business license - Insurance and conflict of interest requirements apply - No specific OEMs or hardware/software products are named; the focus is on professional cybersecurity consulting services - Estimated contract value is not specified, but the City has a $40.4 million annual budget for FY 2026-27
Description
The City of East Palo Alto is seeking proposals from qualified firms to provide virtual Chief Information Security Officer (vCISO) professional services. The contract is for five years and requires expertise in public sector technology consulting, preferably with experience in California local government. The scope includes establishing cybersecurity governance, conducting risk assessments, updating policies, overseeing safeguards, advising on monitoring tools, and developing incident response and business continuity plans. The deadline for proposal submission is August 26, 2026, at 4:00 pm PDT.