JobTarget Logo

Senior Cybersecurity Compliance Consultant in New York at Jobgether

NewJob Function: Consultant
Jobgether
New York, 10455, United States
Posted on
New job! Apply early to increase your chances of getting hired.

Explore Related Opportunities

Job Description

Senior Cybersecurity Compliance Consultant

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Senior Cybersecurity Compliance Consultant based in the United States.

This senior-level role combines cybersecurity compliance consulting, risk management, and client-facing security advisory responsibilities across a diverse portfolio of organizations.
You will serve as a trusted security advisor and vCISO, helping clients strengthen their security programs and navigate complex regulatory requirements.
The position focuses heavily on CMMC and NIST SP 800-171 while also supporting a broad range of cybersecurity, privacy, and governance frameworks.
You will lead high-impact compliance engagements, develop remediation strategies, and guide clients through readiness and third-party assessment processes.
Working closely with security engineers, SOC teams, coordinators, and client stakeholders, you will translate technical requirements into practical business outcomes.
As a senior member of the practice, you will handle complex, high-regulatory-risk engagements and contribute to improving delivery standards, templates, and processes.
The role offers an opportunity to influence cybersecurity programs at both the strategic and operational levels while managing multiple client relationships in a fast-paced consulting environment.

Accountabilities
  • Serve as the assigned security officer and vCISO for a portfolio of client organizations, leading recurring meetings, addressing cybersecurity concerns, and providing regular updates, metrics, findings, and recommendations.
  • Build trusted client relationships by understanding business objectives, regulatory obligations, and security priorities, then developing tailored security strategies and roadmaps.
  • Lead CMMC Level 1 and Level 2 readiness engagements, including NIST SP 800-171 assessments, System Security Plan development, POA&M creation and management, evidence collection, SPRS submission support, and preparation for third-party assessments.
  • Advise clients on Controlled Unclassified Information scoping, DFARS and FAR requirements, and secure enclave architectures, including Microsoft GCC High environments.
  • Deliver compliance engagements across frameworks such as HIPAA/HITECH, SOC 2, PCI DSS v4.0, FTC Safeguards Rule, GLBA, ISO/IEC 27001 and 27002, NIST CSF 2.0, NIST SP 800-53, CIS Controls v8, NIST AI RMF, and ISO/IEC 42001.
  • Support engagements involving privacy, sector-specific, and state or federal requirements, including NY DFS, SEC cybersecurity disclosures, CJIS, StateRAMP/FedRAMP, CCPA/CPRA, GDPR, and ISO/IEC 27701.
  • Map overlapping control requirements across multiple frameworks to create unified control matrices and reduce duplicate evidence collection.
  • Conduct comprehensive risk assessments, identify threats and vulnerabilities, develop mitigation strategies, and recommend remediation actions to address security and compliance gaps.
  • Review security tooling outputs across platforms such as Microsoft Defender XDR, Sentinel, Entra ID Protection, Intune, Purview, and Conditional Access, coordinating remediation with client IT teams and internal engineering resources.
  • Support security officer activities, cyber insurance questionnaires, attestations, security huddles, and verification of security tool functionality across assigned accounts.
  • Participate in incident response activities when required, including escalation support, stakeholder communications, playbook development, SOC coordination, and post-incident reviews.
  • Maintain accurate and timely PSA time entries and contribute to engagement health, delivery tracking, client retention, and operational performance.
  • Identify opportunities to right-size or expand security programs, proactively communicating delivery concerns and account growth recommendations to practice leadership.
  • Serve as a senior escalation resource for complex framework interpretations and control determinations, while performing quality reviews of compliance deliverables before client or assessor submission.
  • Contribute to reusable templates, standardized delivery processes, knowledge resources, and continuous improvement initiatives while staying current on emerging threats and regulatory developments, including the phased CMMC rollout.
Requirements
  • Active CISSP certification in good standing is required at the time of hire; Associate-level, lapsed, or planned credentials do not meet this requirement.
  • Active Certified CMMC Professional (CCP) certification is required at the time of hire, with Certified CMMC Assessor (CCA) certification required within the first 12 months. Registered Practitioner status alone is not sufficient.
  • Eight or more years of progressive information security experience, including at least three years delivering compliance or vCISO engagements across a multi-client portfolio within a consulting, MSP, MSSP, or similar environment.
  • Demonstrated experience completing at least two CMMC Level 2 readiness engagements or equivalent NIST SP 800-171 assessment projects, including SSP development and POA&M management through third-party assessment.
  • Proven depth of experience in at least three distinct regulatory or cybersecurity frameworks, with the ability to defend control determinations and deliverables directly to auditors, assessors, or regulators.
  • Strong knowledge of CMMC, NIST SP 800-171/800-171A, NIST SP 800-53, NIST CSF 2.0, HIPAA/HITECH, SOC 2, PCI DSS, FTC Safeguards Rule, GLBA, ISO/IEC 27001/27002, and CIS Controls v8.
  • Familiarity with DFARS 252.204-7012, 7019, 7020, and 7021; FAR 52.204-21; CUI requirements under 32 CFR Part 2002; and the phased CMMC regulatory framework.
  • Awareness of U.S. state privacy laws, GDPR, NY DFS Part 500, SEC cybersecurity disclosure requirements, CJIS, and related sector-specific compliance regimes.
  • Strong risk management capabilities, including risk assessments, control mapping, remediation planning, POA&M management, and mitigation strategy development.
  • Experience with SIEM, EDR/XDR, IDS/IPS, firewalls, and cybersecurity monitoring technologies, with Microsoft security stack experience preferred.
  • Familiarity with GRC and compliance platforms such as IntelliGRC, Vanta, Secureframe, Drata, OneTrust, or FutureFeed, as well as evidence-collection workflows.
  • Ability to manage a high volume of concurrent client engagements, typically involving 20–30 client relationships, while maintaining strong organization, prioritization, scheduling, and follow-through.
  • Excellent communication and presentation skills, with the ability to translate complex technical and regulatory findings into clear business recommendations for audiences ranging from IT professionals to executives.
  • Strong analytical and reporting capabilities, including the ability to track engagement metrics, compliance status, deliverable progress, and security program performance.
  • Ability to collaborate effectively with distributed teams, coordinators, security engineers, SOC personnel, and client stakeholders.
  • Commitment to ongoing professional development and staying current with cybersecurity threats, technologies, CMMC developments, regulatory changes, industry training, and relevant certifications.
  • U.S. person status, defined as U.S. citizen or lawful permanent resident, is required due to access to Controlled Unclassified Information under applicable DFARS requirements.
  • Ability to work reliably across U.S. business time zones and travel occasionally to client sites when assessment support is required.
  • Additional certifications such as CISM, CRISC, CISA, GIAC credentials, CompTIA Security+/SecurityX, or Microsoft SC-series certifications are considered a plus.
Benefits
  • Annual compensation ranging from $95,000 to $120,000, depending on experience and location.
  • Total compensation includes a base salary or hourly component plus a monthly delivery-based compensation bonus.
  • Monthly bonus opportunities based on delivered hours, engagement milestones, assessment readiness, client retention, and overall contract health.
  • Bonus targets and measurement criteria established at hire and reviewed annually.
  • Medical insurance plan.
  • Dental and vision coverage.
  • Life insurance and supplemental life insurance options.
  • Disability coverage.
  • Paid time off starting at 15 days per year.
  • Paid maternity and paternity leave.
  • Paid U.S. holidays.
  • Retirement plan.
  • Salary advancement/loan program.
  • Health and wellness program.
  • Company-paid training and professional certification opportunities.
  • U.S.-based remote work with flexibility across business time zones.
  • Opportunity to work on complex, high-regulatory-risk cybersecurity engagements and influence the development of scalable compliance practices.
How Jobgether works:
We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team.
We appreciate your interest and wish you the best!
Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.
#LI-CL1

Job Location

New York, 10455, United States

Frequently asked questions about this position

Similar Jobs In Other / Non-US, New York

Hot Job

Corporate Security

Atlas Security Services Inc
Goshen, New York
NewHot Job

Skate School Associate (AM Shift)

Wollman Rink NYC
New York, New York

Deputy Chief Compliance Officer

Jobgether
Other / Non-US, New York
New

Senior Associate Director, Compliance

Webull Financial
New York, New York

VP BANK SECRECY ACT (BSA) OFFICER

Walden Savings Bank
Montgomery, New York
Continue to apply
Enter your email to continue. You’ll be redirected to the employer’s application.
By clicking Continue, you understand and agree to JobTarget's Terms of Use and Privacy Policy.