Senior Security Consultant, Continuity and Compliance
Jobgether · United States · Yesterday
RemoteRemoteInformation Technology$130k–$155k/yrFull-time
Accountabilities
- Lead multiple security, compliance, and advisory engagements simultaneously, managing scope, timelines, budgets, deliverables, documentation, and quality standards from kickoff through completion.
- Conduct PCI DSS compliance assessments, including SAQs, ROCs, and other applicable validation activities in accordance with relevant requirements and assessment standards.
- Serve as a subject matter expert on PCI DSS, NIST, HIPAA, CMMC, and other applicable security and regulatory frameworks, translating requirements into practical guidance.
- Evaluate client security programs, technical controls, regulatory obligations, and operational environments to identify risks, vulnerabilities, compliance gaps, and improvement opportunities.
- Develop actionable remediation strategies that balance regulatory requirements, security best practices, business priorities, and organizational risk.
- Lead client interviews, workshops, advisory sessions, and executive discussions, communicating findings and recommendations effectively to both technical and non-technical stakeholders.
- Review and advise on security policies, procedures, controls, and standard practices to support compliance, governance, and risk-management objectives.
- Provide strategic guidance in complex or ambiguous situations, exercising sound professional judgment and acting as a trusted advisor to client organizations.
- Provide technical direction, quality assurance, mentorship, and guidance to other consultants and peers to promote consistency and adherence to established methodologies.
- Support initiatives that establish, develop, or mature clients’ information security and compliance programs.
Requirements
- Bachelor’s degree in a relevant field combined with 5+ years of information security compliance, auditing, or assessment experience, or 7+ years of demonstrated experience in a related information security discipline.
- Active PCI DSS Qualified Security Assessor (QSA) certification is required, along with a professional credential such as CISSP, CISA, CMMC, or an equivalent certification.
- Strong practical knowledge of PCI DSS, NIST, HIPAA, CMMC, and related security and regulatory frameworks, with the ability to interpret requirements and apply them within diverse client environments.
- Solid technical foundation in networking, databases, operating systems, IT infrastructure, and security controls, with the ability to evaluate technical environments from a risk and compliance perspective.
- Demonstrated experience with critical thinking, root-cause analysis, problem-solving, and professional advisory work, including the ability to develop practical and actionable recommendations.
- Strong consulting and engagement-management skills, with experience balancing multiple priorities and delivering high-quality work across concurrent client engagements.
- Excellent written and verbal communication skills, with the ability to build credibility and communicate effectively with technical teams, business stakeholders, and executive leadership.
- Strong relationship-building skills and the ability to work independently while collaborating effectively with consultants and internal subject matter experts.
- Demonstrated leadership, mentoring, and quality-review capabilities.
- Experience developing or maturing information security programs is preferred.
Pay
Base salary: $130,000–$155,000 annually, with actual compensation determined by experience, technical expertise, certifications, location, and internal equity.
Schedule
Remote flexibility: Full-time, U.S.-based remote position open to candidates in all 50 states.