The Bonadio Group

CPAs, Consultants & More

Managing Security Consultant

Security EngineerSecurity EngineerFull TimeRemoteTeam 501-1,000H1B No SponsorCompany SiteLinkedIn

Location

United States

Posted

4 days ago

Salary

Not specified

No structured requirement data.

Job Description

This description is a summary of our understanding of the job description. Click on 'Apply' button to find out more.

Role Description

We have a tremendous opportunity for a senior level client service professional to work as a Qualified Security Assessor in the Information Risk Management (IRM) team in Rochester, NY. This hands-on role would involve:

  • Technical security assessments of applications and infrastructure
  • Security design reviews
  • Risk assessments

A qualified applicant would have strong technical skills from the hardware to the application layer. This is a remote position and can be located anywhere in the US.

Responsibilities

  • Performing mid and large IT and information security risk and compliance assessments, PCI engagements, audits, gap analyses, and remediation
  • Actively lead projects in the areas of PCI-DSS and ISO 27001
  • Communicating with project stakeholders to effectively convey requirements of technical and process improvements
  • Develop customized policies, procedures and controls, disaster recovery plans and technical documentation for applications, systems and infrastructure
  • Possess an in-depth knowledge of IT security and various frameworks (i.e. PCI, ISO, NIST, CMMC etc.)
  • Experience in managing policy exceptions, including working directly with the teams to document exceptions, identify compensating controls and remediation action plans

Qualifications

  • Compliance: regulatory, privacy, international laws and statutory requirements
  • Risk: risk frameworks, maturity models, and enterprise IT security risk methodologies
  • Governance: vendor management, policy frameworks, control design and security design/architecture
  • Security architecture: infrastructure, network and systems design
  • Knowledge of and hands-on experience with PCI audits and PCI attestations

Requirements

  • Communicate effectively across business and technical boundaries
  • Work independently without detailed guidance
  • Be proficient in writing executive level reports and technical documentation
  • Frequent travel to client locations is required
  • Must be PCI-QSA (Qualified Security Assessor) certified or have held the certification within the last three years
  • At least one current Information Security certification (i.e. CISSP, CISM, ISO 27001:2022 Lead Implementer)
  • At least one current IT Audit certification (CISA, GSNA, ISO 27001:2022 Lead Auditor, CIA)
  • Minimum of an associate’s degree. BS degree is a plus
  • Minimum 4 years of experience in the Cyber Security, Information Assurance, Enterprise Risk or Compliance field

Benefits

  • This is a full-time remote opportunity
  • Office hours are Monday through Friday from 8:00 a.m. until 5:00 p.m.
  • Summer hours are Monday through Thursday from 8:00 a.m. until 5:00 p.m. and Friday from 8:00 a.m. until 12:00 p.m.
  • Flexibility in working hours, with the ability to work additional hours at peak times

Job Requirements

  • Compliance: regulatory, privacy, international laws and statutory requirements
  • Risk: risk frameworks, maturity models, and enterprise IT security risk methodologies
  • Governance: vendor management, policy frameworks, control design and security design/architecture
  • Security architecture: infrastructure, network and systems design
  • Knowledge of and hands-on experience with PCI audits and PCI attestations
  • Communicate effectively across business and technical boundaries
  • Work independently without detailed guidance
  • Be proficient in writing executive level reports and technical documentation
  • Frequent travel to client locations is required
  • Must be PCI-QSA (Qualified Security Assessor) certified or have held the certification within the last three years
  • At least one current Information Security certification (i.e. CISSP, CISM, ISO 27001:2022 Lead Implementer)
  • At least one current IT Audit certification (CISA, GSNA, ISO 27001:2022 Lead Auditor, CIA)
  • Minimum of an associate’s degree. BS degree is a plus
  • Minimum 4 years of experience in the Cyber Security, Information Assurance, Enterprise Risk or Compliance field

Benefits

  • This is a full-time remote opportunity
  • Office hours are Monday through Friday from 8:00 a.m. until 5:00 p.m.
  • Summer hours are Monday through Thursday from 8:00 a.m. until 5:00 p.m. and Friday from 8:00 a.m. until 12:00 p.m.
  • Flexibility in working hours, with the ability to work additional hours at peak times

Related Categories

Related Job Pages

More Security Engineer Jobs

Security Engineer4 days ago
InternshipRemoteTeam 51-200Since 2022H1B No Sponsor

Technical Writer Intern creating documentation for AI Security products

United States
Security Engineer4 days ago
Full TimeRemoteTeam 501-1,000Since 2015H1B No Sponsor

Senior security professional leading product security for autonomous aircraft at Shield AI

Texas
$138K - $207K / year

Senior Cybersecurity Engineer (Secret clearance)

Rise8

An elite software development firm delivering a tomorrow where fewer bad things happen because of bad software.

Security Engineer4 days ago
Full TimeRemoteTeam 51-200H1B No Sponsor

The Senior Cybersecurity Engineer will be responsible for securing cloud-based environments by designing and implementing native security solutions and driving Continuous RMF practices through automation. Key duties include implementing security measures like firewalls and IDS/IPS, securing containerized systems, and establishing identity and access management policies.

United States
$163K - $203K / year

Consumer Identity & Access Management (CIAM) Engineer II

Texas Health Resources

At Texas Health Resources, our mission is “to improve the health of the people in the communities we serve.” We are one of the largest faith-based, nonprofit health systems in the United States. Team of more than 23,000 employees of wholly owned/operated facilities plus 2,200 employees of consolidated joint ventures in the greater Dallas/Fort Worth area. Career growth and professional development opportunities are top-notch and benefits are equally outstanding.

Security Engineer4 days ago
Full TimeRemoteTeam 10,001

CIAM Engineer II – Consumer Salesforce Bring your passion to Texas Health so we are Better + Together Work location: Texas Health Resources, Remote – Must reside in Texas or be willing to relocate. Required to attend in-person meetings at corporate office in Arlington. Work h...

United States