Salary
💰 $86,000 - $148,000 per year
Tech Stack
AWSAzureCloudCyber SecurityGoogle Cloud Platform
About the role
- Lead audits/assessments including audit plan preparation, review of documentation and evidence, evaluation of procedures, and client interviews
- Maintain strong depth of knowledge in one or more cybersecurity frameworks
- Prepare, review and approve assessment reports
- Manage priorities, tasks and hours on projects with project manager to achieve utilization targets
- Ensure quality products and services are delivered on time
- Escalate client and project issues to management in a timely manner
- Provide mentorship to team members in audit, assessment, technical review and writing
- Interface with clients through entire engagement, interacting with all levels of client organizations
- Establish and maintain positive collaborative relationships with clients and stakeholders
- Continuous professional development and maintain industry certifications
- Collaborate with project managers, quality management, sales and other delivery team members
- Establish account relationships and identify upsell and cross sell opportunities
- Draft audit programs addressing regulatory objectives and client complexity
- Lead interview and inquiry walkthroughs with clients to determine conformity
- Assess security vulnerabilities against appropriate security frameworks
- Pursue and corroborate conclusions derived from inquiry procedures with client
- Offline and remote evidence inspection of client provided documentation
- Educate and interpret compliance activities for clients
- Apply quality standards and adhere to quality assurance benchmarks
- Provide advice to customers on issues affecting scope of work
- Develop documentation and author recommendations to improve customer security posture
- Up to 20% Travel
Requirements
- Bachelor’s degree (four-year college or university) or equivalent combination of education and work experience
- Degree preferably in Information Systems, CIS, MIS or IT
- 3-5 years of experience in security frameworks and regulatory requirements with a strong focus on SOC 2
- Strong understanding of technical and non-technical security related system controls
- Ability to evaluate the design and effectiveness of technology controls throughout the business cycle
- Demonstrated ability to structure and lead projects successfully
- Strong written and verbal communication skills
- Excellent Consulting skills
- Ability to build high-trust relationships, rapport and credibility quickly
- Strong personal initiative to manage time and others to meet deadlines
- Ability to shift focus frequently while maintaining excellent quality
- Skill and will to train and mentor junior staff
- Computer and typing skills for rapid data collection and note taking
- Ability to facilitate meetings to small or large groups
- Public speaking and executive presence
- Inquisitive and curious nature
- Diplomatic and broad minded
- Strong technical researcher
- Bonus: CSP certifications (AWS solutions architect, etc.)
- Bonus: Information security certifications (CISSP, CISM, Certified ISO 27001 Lead Implementer) or audit certification (CISA, GSNA, etc.)
- Bonus: Experience with cloud computing environments (AWS, Azure, GCP)