I've used a virtual DPO, which worked out okay, as we could leave the usual staff to handle the routine and only make the call when we had something challenging and unusual to deal with.
In your case, it depends very much on what the scope of the CISO service is. Would the CISO act as line manager to a security team within your SME? Would the CISO recommend other products and services to the board? Or would the CISO responsible for overall security strategy? Or maybe the CISO is just there to be the public face of security. In the UKs financial services market you'd probably need to check with the FCA first that the CISO didn't need to be an approved person.
I know of organizations that do this. If you can give me come additional context I'd be happy to help/point you in the right direction.
Cheers,
Jim Kinsman
404-226-8258