Cybersecurity Senior Consultant
At Crowe, you can build a meaningful and rewarding career. With real flexibility to balance work with life moments, you’re trusted to deliver results and make an impact. We embrace you for who you are, care for your well-being, and nurture your career. Everyone has equitable access to opportunities for career growth and leadership. Over our 80-year history, delivering excellent service through innovation has been a core part of our DNA across our audit, tax, and consulting groups. That’s why we continuously invest in innovative ideas, such as AI-enabled insights and technology-powered solutions, to enhance our services.
About the Role
Consulting at Crowe is a dynamic business focused on solving problems for our clients and serving our core markets through innovative solutions. As technology and AI continue to reshape the consulting landscape, we are looking for individuals who are curious, adaptable, and eager to learn. In this role, you will build both technical and transferable skills, think critically, and use technology to solve real business problems. You will continuously learn, collaborate across teams, and explore how tools, including emerging AI capabilities, can improve efficiency, insights, and client outcomes.
As a Cybersecurity Senior Consultant, you will work directly with client stakeholders to understand cybersecurity and operational resilience needs; collaborate with engagement team members to plan and execute assessments; and deliver actionable findings and recommendations that enhance security posture, regulatory compliance, and business continuity.
Responsibilities
- Plan and execute cybersecurity and resilience assessments across technology and operational domains, including:
- Data protection and information governance
- HIPAA Security and Privacy Rule assessments
- Third-party and vendor risk management
- Incident response, cyber resilience, and disaster recovery
- Business continuity and operational resilience
- Infrastructure and application security controls
- Assess the design and operating effectiveness of cybersecurity and resilience controls against applicable regulatory requirements and industry frameworks (e.g., HIPAA, NIST CSF, NIST SP 800-53, ISO 27001, etc.).
- Support integrated assessments that evaluate how cybersecurity controls enable broader business and operational resilience objectives.
- Act as a strategic advisor to client security and risk functions, helping to build, enhance, and operationalize cybersecurity programs across domains such as governance, risk, and compliance (GRC) and business resiliency.
- Serve as an extension of client teams to lead or support program execution activities, including control implementation, metrics/reporting, issue remediation, and continuous improvement initiatives.
- Mentor and supervise junior consultants; contribute to team development and internal knowledge-sharing.
- Prepare clear, thorough documentation, reports, and deliverables independently and on schedule.
- Communicate assessment scope, procedures, findings, and recommendations to both technical and non-technical client stakeholders.
- Maintain engagement quality and responsiveness throughout the delivery lifecycle, ensuring client confidence and satisfaction.
Requirements
- Minimum of 3 years of total professional experience.
- 2+ years of hands-on experience delivering cybersecurity or IT risk assessments.
- Strong working knowledge of:
- Cybersecurity operations and controls
- Data protection principles
- HIPAA Security and Privacy Rule requirements
- Demonstrated ability to independently manage engagements from planning through reporting with limited oversight.
- Strong written and verbal communication skills, particularly in documenting observations and explaining results to diverse audiences.
- Bachelor’s degree.
Preferred Qualifications
- One or more relevant professional certifications (e.g., CISSP, CISA, HCISPP, or equivalent).
- Experience assessing or advising on:
- HIPAA compliance
- Cybersecurity programs
- Business continuity and disaster recovery
- Operational or cyber resilience initiatives
- Prior experience at a public accounting or advisory firm delivering cybersecurity, privacy, or resilience services to healthcare or life sciences organizations.
We expect the candidate to uphold Crowe’s values of Care, Trust, Courage, and Stewardship. All persons hired will be required to verify identity and eligibility to work in the United States and complete the required employment eligibility verification form upon hire. Crowe is not sponsoring work authorization at this time.
Pay
The wage range for this role takes into account the wide range of factors that are considered in making compensation decisions including but not limited to skill sets; experience and training; licensure and certifications; and other business and organizational needs. The disclosed range estimate has not been adjusted for the applicable geographic differential associated with the location at which the position may be filled. A reasonable estimate of the current range is $80,500.00 - $159,300.00 per year.
Benefits
At Crowe, we know that great people are what makes a great firm. We care about our people and offer employees a comprehensive total rewards package.