Senior Cybersecurity Compliance Consultant (US Remote)
Job Summary
The Security Advisor (Senior Cybersecurity Compliance Consultant) delivers active security practice management engagements, serving as the assigned security officer (vCISO) for a portfolio of client organizations. The role combines hands-on compliance delivery with client relationship ownership, risk management, and ongoing security advisory work. The role requires subject matter expertise across regulatory compliance frameworks, strong client-facing communication, and organizational discipline to manage a high volume of concurrent engagements. This position sits at the senior end of the practice: it carries the most complex and highest-regulatory-risk engagements in the portfolio and sets the technical standard for the practice's compliance deliverables.
Reports to: Security Practice Management Team Lead (Cybersecurity Department)
Direct Reports: None
Works with: Practice coordinators, security engineers, SOC personnel, and department leadership supporting assigned engagements
Job Responsibilities
1. Client Advisory & vCISO Delivery:
- Serve as the assigned security officer (vCISO) for a portfolio of client engagements: lead recurring meeting cadences, act as the primary point of contact for clients' cybersecurity concerns and provide regular updates and reports on the status of security initiatives, including performance metrics, findings, and recommendations for improvement.
- Build strong client relationships, understand each client's unique regulatory and business requirements, and address their needs with tailored strategies and security roadmaps.
- Identify above-contract demand and security program growth opportunities within assigned accounts, surfacing right-sizing and expansion recommendations to practice leadership ahead of contract renewal.
- Track and maintain contract health ensuring that issues with delivery are communicated early.
2. Compliance Program Delivery:
- Lead CMMC Level 1 and Level 2 readiness engagements: NIST SP 800-171 control assessments, System Security Plan (SSP) development, POA&M creation and management, SPRS score submission support, evidence collection, and client preparation for third-party assessment.
- Advise clients on CUI scoping, DFARS 252.204-7012 and FAR 52.204-21 obligations, and enclave architectures, including Microsoft GCC High environments.
- Deliver compliance engagements across additional frameworks as assigned, including HIPAA / HITECH, SOC 2 (Types I and II), PCI DSS v4.0, FTC Safeguards Rule, GLBA, ISO/IEC 27001 and 27002, NIST Cybersecurity Framework 2.0, NIST SP 800-53, CIS Critical Security Controls v8, and AI governance (NIST AI RMF, ISO/IEC 42001).
- Advise on sector- and state-specific regimes as engagements require, including NY DFS 23 NYCRR Part 500, SEC cybersecurity disclosure rules, CJIS Security Policy, StateRAMP / FedRAMP readiness, and U.S. state privacy laws (CCPA/CPRA and successors) alongside GDPR and ISO/IEC 27701 where clients have international exposure.
- Map overlapping control sets across frameworks to build unified control matrices, eliminating duplicate evidence collection across a client's concurrent compliance obligations.
3. Security Assessment & Engineering Support:
- Conduct comprehensive risk assessments to identify potential threats and vulnerabilities, develop and implement mitigation strategies to enhance clients' security postures, and monitor compliance with regulatory requirements and industry standards, recommending remediation actions to address gaps or deficiencies.
- Oversee data collection efforts to verify compliance and gather critical security information within client infrastructures, ensuring accuracy and reliability.
- Review and interpret security tooling outputs across the Microsoft security stack (Defender XDR, Sentinel, Entra ID Protection, Intune, Purview, Conditional Access) and coordinate remediation with client IT teams and internal engineers.
4. Other Responsibili