Cybersecurity Senior Consultant
About the Role
We are seeking a Cybersecurity Senior Consultant to join our growing team of professionals focused on evaluating cybersecurity and resilience capabilities and supporting the maturity of programs across clients’ environments. As a Senior Consultant, you will work directly with client stakeholders to understand cybersecurity and operational resilience needs, collaborate with engagement team members, and deliver actionable findings and recommendations that enhance security posture, regulatory compliance, and business continuity.
Responsibilities
- Planning and executing cybersecurity and resilience assessments across technology and operational domains, including:
- Data protection and information governance
- HIPAA Security and Privacy Rule assessments
- Third-party and vendor risk management
- Incident response, cyber resilience, and disaster recovery
- Business continuity and operational resilience
- Infrastructure and application security controls
- Assessing the design and operating effectiveness of cybersecurity and resilience controls against applicable regulatory requirements and industry frameworks (e.g., HIPAA, NIST CSF, NIST SP 800-53, ISO 27001, etc.)
- Supporting integrated assessments that evaluate how cybersecurity controls enable broader business and operational resilience objectives
- Acting as a strategic advisor to client security and risk functions, helping to build, enhance, and operationalize cybersecurity programs across domains such as governance, risk, and compliance (GRC) and business resiliency
- Serving as an extension of client teams to lead or support program execution activities, including control implementation, metrics/reporting, issue remediation, and continuous improvement initiatives
- Mentoring and supervising junior consultants; contributing to team development and internal knowledge-sharing
- Preparing clear, thorough documentation, reports, and deliverables independently and on schedule
- Communicating assessment scope, procedures, findings, and recommendations to both technical and non-technical client stakeholders
- Maintaining engagement quality and responsiveness throughout the delivery lifecycle, ensuring client confidence and satisfaction
Qualifications
- Minimum of 3 years of total professional experience
- 2+ years of hands-on experience delivering cybersecurity or IT risk assessments
- Strong working knowledge of:
- Cybersecurity operations and controls
- Data protection principles
- HIPAA Security and Privacy Rule requirements
- Demonstrated ability to independently manage engagements from planning through reporting with limited oversight
- Strong written and verbal communication skills, particularly in documenting observations and explaining results to diverse audiences
- Bachelor’s degree
Preferred Qualifications
- One or more relevant professional certifications (e.g., CISSP, CISA, HCISPP, or equivalent)
- Experience assessing or advising on:
- HIPAA compliance
- Cybersecurity programs
- Business continuity and disaster recovery
- Operational or cyber resilience initiatives
- Prior experience at a public accounting or advisory firm delivering cybersecurity, privacy, or resilience services to healthcare or life sciences organizations
We expect the candidate to uphold Crowe’s values of Care, Trust, Courage, and Stewardship. These values define who we are. We expect all of our people to act ethically and with integrity at all times.
Pay
A reasonable estimate of the current range is $80,500.00 - $159,300.00 per year. The wage range for this role takes into account the wide range of factors that are considered in making compensation decisions including but not limited to skill sets; experience and training; licensure and certifications; and other business and organizational needs. The disclosed range estimate has not been adjusted for the applicable geographic differential associated with the location at which the position may be filled. At Crowe, it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case.