Commercial Assurance Senior Consultant
About the role
Fortreum is a trusted leader in cloud and cybersecurity services, ranked among the Top 5 FedRAMP Third Party Assessment Organizations (3PAO). With the addition of Kovr.AI, we have expanded our capabilities to include advanced cyber risk quantification and analytics, enabling organizations to better understand, measure, and communicate risk. Together, we deliver independent, third-party, vendor-agnostic regulatory assessment and advisory services, alongside advanced cybersecurity offensive and compliance technical solutions.
This Senior Security Consultant role offers a unique chance to work with the best and brightest in the field, supporting major cloud providers and gaining invaluable insights from industry experts. The position specializes in conducting security assessments for complex cloud-based systems, particularly within SOC 1, SOC 2, and ISO/IEC 27001, 27017, 27018, and 27701 frameworks. This role is vital to accommodate our expanding client base and service lines by leading SOC and ISO security assessments.
This is a customer-facing role. Travel is expected to be limited in nature; however, you may be required to travel to client locations to deliver professional services.
Responsibilities
- Independently conduct control assessments on all relevant SOC 2 Categories and associated criteria, identify and understand SOC 1 control objectives, as well as audit ISO/IEC 27001 Management Clauses 4-10 and Annex A controls.
- Review, understand, and evaluate information system boundaries based on interviews, descriptions, and diagrams.
- Develop engagement testing plans (interview schedule, requests for information, and workpapers).
- Complete AICPA required documents and workpapers in support of SOC engagements.
- Complete ISO/IEC 27001 required audit documentation.
- Conduct interviews of key stakeholders and technical personnel.
- Record meeting minutes and maintain work papers.
- Develop final SOC reports as well as ISO certification audit deliverables.
- Manage priorities, tasks, and assigned hours on projects to achieve delivery utilization targets.
- Perform project out briefs with clients to notify them of the outcome of their compliance activities.
- Establish and maintain positive collaborative relationships with clients and stakeholders.
- Mentor junior staff members on appropriate interviewing, examination, and testing techniques to meet SOC and ISO requirements.
- Pursue industry-specific certifications and seek continuous professional development.
Requirements
- Bachelor’s Degree or equivalent job experience.
- 5+ years of professional services experience.
- 3+ years of consulting experience assessing systems against SOC and ISO.
- Strong technical acumen with regards to cloud security.
- Familiarity with IaaS providers such as AWS, GCP, and Azure.
- Deep understanding of all SOC 2 Categories and associated criteria, as well as ISO/IEC 27001 Management Clauses 4-10 and Annex A controls.
Skills
- Ability to be self-directed with little oversight.
- Ability to manage multiple priorities simultaneously.
- Proven analytical and problem-solving skills.
- Ability to develop and maintain strong relationships with team members and clients.
- Comfortable supporting fast-paced team environments.
Benefits
- Medical, dental, and vision insurance.
- 401K plan with a 4% match.
- Company-paid short-term disability, long-term disability, AD&D, and life insurance.
- Flex time off.
- Annual bonuses.
- Training stipends and certification reimbursements.
- Access to over 30,000 free online training courses.
- Personal cell phone allowance.
- New hire and annual home office stipend.
- Spot awards.
- Eleven paid holidays.
Pay
Posted salary range: $140,000 - $160,000 annual salary.