CPAs, Consultants & More
Managing Security Consultant
Location
United States
Posted
4 days ago
Salary
Not specified
No structured requirement data.
Job Description
Role Description
We have a tremendous opportunity for a senior level client service professional to work as a Qualified Security Assessor in the Information Risk Management (IRM) team in Rochester, NY. This hands-on role would involve:
- Technical security assessments of applications and infrastructure
- Security design reviews
- Risk assessments
A qualified applicant would have strong technical skills from the hardware to the application layer. This is a remote position and can be located anywhere in the US.
Responsibilities
- Performing mid and large IT and information security risk and compliance assessments, PCI engagements, audits, gap analyses, and remediation
- Actively lead projects in the areas of PCI-DSS and ISO 27001
- Communicating with project stakeholders to effectively convey requirements of technical and process improvements
- Develop customized policies, procedures and controls, disaster recovery plans and technical documentation for applications, systems and infrastructure
- Possess an in-depth knowledge of IT security and various frameworks (i.e. PCI, ISO, NIST, CMMC etc.)
- Experience in managing policy exceptions, including working directly with the teams to document exceptions, identify compensating controls and remediation action plans
Qualifications
- Compliance: regulatory, privacy, international laws and statutory requirements
- Risk: risk frameworks, maturity models, and enterprise IT security risk methodologies
- Governance: vendor management, policy frameworks, control design and security design/architecture
- Security architecture: infrastructure, network and systems design
- Knowledge of and hands-on experience with PCI audits and PCI attestations
Requirements
- Communicate effectively across business and technical boundaries
- Work independently without detailed guidance
- Be proficient in writing executive level reports and technical documentation
- Frequent travel to client locations is required
- Must be PCI-QSA (Qualified Security Assessor) certified or have held the certification within the last three years
- At least one current Information Security certification (i.e. CISSP, CISM, ISO 27001:2022 Lead Implementer)
- At least one current IT Audit certification (CISA, GSNA, ISO 27001:2022 Lead Auditor, CIA)
- Minimum of an associate’s degree. BS degree is a plus
- Minimum 4 years of experience in the Cyber Security, Information Assurance, Enterprise Risk or Compliance field
Benefits
- This is a full-time remote opportunity
- Office hours are Monday through Friday from 8:00 a.m. until 5:00 p.m.
- Summer hours are Monday through Thursday from 8:00 a.m. until 5:00 p.m. and Friday from 8:00 a.m. until 12:00 p.m.
- Flexibility in working hours, with the ability to work additional hours at peak times
Job Requirements
- Compliance: regulatory, privacy, international laws and statutory requirements
- Risk: risk frameworks, maturity models, and enterprise IT security risk methodologies
- Governance: vendor management, policy frameworks, control design and security design/architecture
- Security architecture: infrastructure, network and systems design
- Knowledge of and hands-on experience with PCI audits and PCI attestations
- Communicate effectively across business and technical boundaries
- Work independently without detailed guidance
- Be proficient in writing executive level reports and technical documentation
- Frequent travel to client locations is required
- Must be PCI-QSA (Qualified Security Assessor) certified or have held the certification within the last three years
- At least one current Information Security certification (i.e. CISSP, CISM, ISO 27001:2022 Lead Implementer)
- At least one current IT Audit certification (CISA, GSNA, ISO 27001:2022 Lead Auditor, CIA)
- Minimum of an associate’s degree. BS degree is a plus
- Minimum 4 years of experience in the Cyber Security, Information Assurance, Enterprise Risk or Compliance field
Benefits
- This is a full-time remote opportunity
- Office hours are Monday through Friday from 8:00 a.m. until 5:00 p.m.
- Summer hours are Monday through Thursday from 8:00 a.m. until 5:00 p.m. and Friday from 8:00 a.m. until 12:00 p.m.
- Flexibility in working hours, with the ability to work additional hours at peak times
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Technical Writer Intern creating documentation for AI Security products
Senior security professional leading product security for autonomous aircraft at Shield AI
Senior Cybersecurity Engineer (Secret clearance)
Rise8An elite software development firm delivering a tomorrow where fewer bad things happen because of bad software.
The Senior Cybersecurity Engineer will be responsible for securing cloud-based environments by designing and implementing native security solutions and driving Continuous RMF practices through automation. Key duties include implementing security measures like firewalls and IDS/IPS, securing containerized systems, and establishing identity and access management policies.
Consumer Identity & Access Management (CIAM) Engineer II
Texas Health ResourcesAt Texas Health Resources, our mission is “to improve the health of the people in the communities we serve.” We are one of the largest faith-based, nonprofit health systems in the United States. Team of more than 23,000 employees of wholly owned/operated facilities plus 2,200 employees of consolidated joint ventures in the greater Dallas/Fort Worth area. Career growth and professional development opportunities are top-notch and benefits are equally outstanding.
CIAM Engineer II – Consumer Salesforce Bring your passion to Texas Health so we are Better + Together Work location: Texas Health Resources, Remote – Must reside in Texas or be willing to relocate. Required to attend in-person meetings at corporate office in Arlington. Work h...