Security Consultant with security assessments/control review and NIST exp. (Remote)
LTM · New York, NY · 1 wk ago
On-siteInformation TechnologyFull-time
Key Responsibilities
- Conduct end-to-end security design reviews and related validation/verification tasks for 50 applications across SaaS, on-premises, and IaaS environments.
- Conduct full-stack security assessments and provide control requirements based on the applications' activity scope, capabilities, and boundaries with focus areas including:
- Frontend/Client-side security
- Backend/Platform security
- Identity & Access Management (IAM)
- Encryption in transit and at rest
- Network security
- Data security
- Logging, monitoring, and SIEM integration
- Evaluate security controls against each application's activity scope, capabilities, and trust boundaries.
- Document findings, control gaps, and recommendations in standardized Word or Excel templates.
- Identify, track, and maintain the status of critical security controls for each application in scope.
- Apply security standards and control frameworks (e.g., NIST, CIS, ISO 27001) to rationalize and map control requirements.
- Maintain accurate and up-to-date deliverable tracking in Asana across all active reviews.
- Identify and engage application owners using the enterprise application management portfolio or through direct outreach.
- Interview application owners and obtain necessary access to assess current security posture.
- Provide clear, prioritized mitigation guidance for identified gaps aligned to enterprise policies and standards.
- Engage third-party application vendors as required to support assessment activities.
- Serve as a direct point of contact for application owners and cross-functional enterprise teams seeking guidance or information.
- Participate in weekly check-ins to report on assessment progress, blockers, and completed reviews.
- Report directly to the VP of Information Security.
- Communicate findings and recommendations in a clear, business-appropriate manner to both technical and non-technical stakeholders.
Required Qualifications
- 5+ years of experience in information security with a focus on application security architecture or security assessments.
- Demonstrated experience conducting security design reviews or threat modeling for enterprise applications, SaaS, IaaS, and on-premises environments.
- Strong working knowledge of security control frameworks (NIST CSF, NIST SP 800-53, CIS Controls, ISO 27001).
- Familiarity with full-stack application security concepts including authentication, authorization, encryption, API security, network segmentation, and data protection.
- Experience working directly with application owners, product teams, and vendors in an enterprise environment.
- Strong written communication skills with ability to produce clear, structured assessment documentation in Word and Excel.
- Highly organized with demonstrated ability to manage multiple concurrent assessments and track deliverables (Asana or similar project management tools).
Preferred Qualifications
- Relevant certifications: CISSP, CCSP, CISM, CSSLP, or equivalent.
- Familiarity with cloud security principles across AWS, Azure, or GCP.
- Experience applying security standards to vendor/third-party risk assessments.
- Prior experience working within media, entertainment, or large-scale enterprise environments.
What Success Looks Like
- 50 completed security design reviews and validation/verification tasks with documented control assessments and findings.
- A maintained, up-to-date control tracking register across all applications in scope.
- Mitigation guidance provided to application owners with clear, actionable remediation steps.
- All deliverables logged and tracked in Asana with review documentation available in Word or Excel.
Pay
Actual compensation within the range will be dependent upon the individual's skills, experience, performance and internal equity. This position includes a bonus or variable payout component based on individual and organizational performance.
Benefits
- Comprehensive Medical Plan covering Medical, Dental, Vision
- Short Term and Long-Term Disability Coverage
- 401(k) Plan with Company match
- Life Insurance
- Vacation Time, Sick Leave, Paid Holidays
- Paid Paternity and Maternity Leave