Remote job
Senior Cybersecurity Compliance Consultant (US Remote)
Job details
About this role
Role overview This senior consulting position functions as a fractional Chief Information Security Officer (vCISO) for a portfolio of client organizations, leading the most complex and high-risk compliance engagements in the practice. The role blends hands-on regulatory framework delivery with client relationship ownership, risk advisory, and ongoing security program guidance. It is a US remote role suited to an experienced practitioner who can manage multiple concurrent engagements and set the technical standard for compliance deliverables.
Responsibilities - Act as the primary security point of contact for assigned clients, leading recurring meetings, presenting program status, and tailoring roadmaps to each client's regulatory and business context. - Drive CMMC Level 1 and Level 2 readiness work, including NIST SP 800-171 control assessments, System Security Plan (SSP) authorship, POA&M management, SPRS score support, evidence gathering, and third-party assessment preparation. - Deliver compliance engagements across additional frameworks as required, such as HIPAA/HITECH, SOC 2 Types I and II, PCI DSS v4.0, the FTC Safeguards Rule, GLBA, ISO/IEC 27001 and 27002, the NIST CSF 2.0, NIST SP 800-53, CIS Controls v8, and AI governance standards. - Advise on sector- and state-specific regimes including NY DFS 23 NYCRR Part 500, SEC cybersecurity disclosure rules, CJIS, StateRAMP/FedRAMP readiness, CCPA/CPRA and other U.S. state privacy laws, plus GDPR and ISO/IEC 27701 where international exposure applies. - Run risk assessments, interpret Microsoft security tooling outputs (Defender XDR, Sentinel, Entra ID Protection, Intune, Purview, Conditional Access), and coordinate remediation with client IT teams and internal engineers. - Support incident response rotations, cyber insurance questionnaires, security huddles, and quality review of compliance deliverables prior to assessor submission.
Requirements - Active CISSP credential in good standing, required at hire. - Deep subject matter expertise across multiple regulatory compliance frameworks and the ability to map overlapping control sets into unified matrices. - Demonstrated experience advising clients on CUI scoping, DFARS 252.204-7012, FAR 52.204-21, and enclave architectures such as Microsoft GCC High. - Strong client-facing communication skills and the organizational discipline to manage a high volume of concurrent engagements. - Commitment to accurate, timely time tracking in a PSA system and continuous learning across the CMMC ecosystem and broader compliance landscape.
Nice to have - Experience contributing to scalable engagement templates, playbooks, and practice knowledge bases. - Familiarity with AI governance frameworks such as NIST AI RMF and ISO/IEC 42001.
Benefits and work setup - Base pay starting between $95,000 and $120,000 annually, depending on experience and location, plus a monthly delivery-based bonus tied to hours delivered, milestone completion, and client retention. - Medical, dental, and vision insurance; life and disability coverage. - Starting paid time off of 15 days per year, paid parental leave, and paid U.S. holidays. - Retirement plan, salary advancement/loan program, and a health and wellness benefit. - Company-paid training and certification, plus optional supplemental life and health plans. - US remote work arrangement.