Assessing and reporting on customer business and technical environments, operations/procedures, administration of infrastructure
Consult both onsite and remotely with customers to collect, review, and analyze data
Performing gap analyses of current environments, controls, and programs
Make recommendations for remediation steps required to achieve information security and compliance objectives
Review customer-prepared documents and reports, and provide feedback/guidance
Participate in sales calls as a subject matter expert and attend conferences as appropriate
Prepare and perform industry-related presentations and/or webcasts
Requirements
Bachelor’s degree or 5 years’ experience in information security or privacy
Must possess at least one of the following industry-recognized audit and information security certifications: Certified Information System Security Professional (CISSP), Certified Information Systems Auditor (CISA), Certified Information Security Manager (CISM), Certified Internal Auditor (CIA), GIAC Systems and Network Auditor (GSNA)
Understanding of and familiarity with information security, compliance, and privacy frameworks and standards including NIST SP 800-171, NIST CSF, ISO 27000, GLBA, GDPR, and PCI DSS
Understanding of information systems, networks, and related security issues
Understand core compliance program elements such as policies, procedures, training, third-party oversight, device protection, inventory/scope verification, and incident response
Understanding of risk assessments and targeted risk analyses
Technical understanding of foundational IT models, such as the OSI Model, is highly desirable
Expertise in modern technologies such as networking protocols, system architecture, cloud computing platforms, virtualization, cybersecurity principles, and emerging IT trends
Creating high-quality deliverables using appropriate business and technical language