Lead Consultant, Sensitive Data Compliance
About the role
This position works with the Sensitive Data Cyber Compliance leadership to define, refine, and expand the firm's practice areas and service offerings. The role is primarily focused on supporting PCI DSS projects with clients of all sizes, complexities, and industries, including international and Fortune 1000 companies, and U.S. Department of Defense contractors.
Responsibilities
- Lead and execute PCI compliance-related assessments and sensitive data compliance assessments for enterprise clients by identifying key risks and gaps and documenting clear reporting with proof-of-concept and recommendations.
- Execute information security risk and compliance assessments against federal and other government-required cyber frameworks, including NIST 800-171, NIST 800-53, FedRAMP, and the NIST Cybersecurity Framework.
- Assess IT environments and identify gaps and vulnerabilities that impair compliance with required standards; assist with documenting clear reporting with proof-of-concept and recommendations.
- Help the IT Risk & Compliance team maintain industry-leading solutions for PCI and other evolving cybersecurity compliance frameworks through continuing education.
- Participate on consulting teams with large enterprise clients in multiple industries to:
- Assist organizations with defining boundaries of in-scope systems.
- Assist clients with documentation development, including system security plans (SSP), policies/procedures, strategy development, and plans of action and milestones (POAMs).
- Define and integrate solutions, including tools, processes, and data flows to maintain required compliance obligations and reduce cyber risk.
- Effectively manage multiple projects concurrently, helping define and drive project management to keep projects on schedule and within budget.
Requirements
- Bachelor's Degree in Cybersecurity, MIS, Computer Science, or a similar discipline.
- Payment Card Industry Qualified Security Assessor (PCI QSA) credential.
- Cybersecurity and/or privacy-related certifications (e.g., CISSP, CISA, CISM, preferred).
- Experience providing consulting, assessment, or implementation services associated with federal cyber compliance frameworks, including NIST 800-171, FISMA, or FedRAMP.
- Working knowledge of cyber risk management frameworks (CMMC / NIST 800-171, FISMA, FedRAMP, NIST Cybersecurity Framework, NIST SP 800-53).
Qualifications
- At least 5 years of experience in cybersecurity, IT audit, or governance, risk, and compliance, including 1-2 years of experience with at least one of the following frameworks:
- Payment Card Industry Data Security Standard (PCI DSS)
- NIST Cybersecurity Framework (CSF)
- ISO 27001 / 27002
- FedRAMP / StateRAMP
- FISMA and NIST SP 800-53
- CIS Critical Security Controls
About Forvis Mazars
Forvis Mazars, LLP is an independent member of Forvis Mazars Global, a leading global professional services network. Ranked among the largest public accounting firms in the United States, our 7,000+ team members deliver assurance, tax, and consulting services to clients in all 50 states and internationally. With a legacy spanning more than 100 years, we focus on delivering an Unmatched Client Experience® while fostering a workplace where relationships matter, learning fuels growth, and every person feels valued and supported.
Benefits
Our robust total rewards program and flexible work environment reflect our commitment to people, careers, and well-being—empowering our team to grow and thrive while delivering exceptional service.