Position Summary
Reporting to our Managing Director, Head of Cyber Operations and partnering with key stakeholders across the firm, the Associate Managing Director, Principal Cybersecurity Consultant, is responsible for evolving service offerings, driving repeatable delivery methodologies, and serving as a senior client advisor. This position is execution-focused, and accountable for the quality, consistency, and strategic impact of proactive security services delivered across multiple, complex, and concurrent client engagements, ensuring cybersecurity programs align with each client's business objectives, market dynamics, and risk tolerance.
This is a player-coach role; sufficiently hands-on to guide technical assessments and steer high-stakes deliverables, while demonstrating the ability to shape practice strategy and develop the next generation of consulting leaders.
What You'll Do:
- Own delivery quality, consistency, and strategic impact across a portfolio of concurrent client engagements.
- Serve as a senior client advisor/vCISO on complex, multi-stakeholder engagements requiring executive-level presence and technical depth.
- Standardize delivery methodologies and enforce quality controls across all team engagements.
- Guide technical assessments, incident response program development, tabletop exercises, and security architecture reviews for enterprise clients.
- Drive repeatable engagement frameworks that align cybersecurity programs with each client's business objectives, regulatory environment, and risk tolerance.
- Ensure engagements consistently deliver business-aligned cyber outcomes for clients.
- Contribute to thought leadership, methodology documentation, and practice intellectual property that strengthen the Company's market position.
- Represent the practice in cross-functional planning and discussions with peer leadership across business units.
- Assist with the recruiting, retention, and development of teammates.
Who You Are:
- Bachelor's degree in information technology, cybersecurity, or a related discipline, or equivalent professional experience; advanced degree preferred.
- Minimum of 15 years of experience in information security, IT operations, or security consulting.
- Demonstrated success managing a portfolio of concurrent complex confidential client engagements with accountability for delivery quality, utilization, and margin.
- Track record of building and scaling consulting teams, including hiring, performance management, and career development of directors and senior individual contributors.
- Proven ability to act as a trusted advisor to CISOs, CIOs, and other senior client executives across diverse industries.
- Strong project and program management discipline, with the ability to standardize delivery methodologies and enforce quality across a team.
- Deep understanding of technical and threat trends and their security implications, including cloud migration, identity, OT/IoT, and emerging adversary tradecraft.
- Experience defining security requirements based on business strategy and the regulatory environment, including NIST, ISO 27001, PCI, applicable state laws, and industry best practices.
- Experience leading the development of incident response programs, tabletop exercises, and security architecture reviews for enterprise clients.
- Experience contributing to pre-sales activity, scoping, proposal development, and executive presentations.
- Excellent written and verbal communication skills with the ability to explain complex issues clearly to clients and key internal stakeholders.
- A collaborative, entrepreneurial mindset to support business development and a record of demonstrating credibility, discretion, risk management awareness, sound judgment, integrity, and ethical conduct.
Preferred Qualifications:
- Relevant security certifications such as CISSP, CISM, CCISO, GSLC, GCIH, or equivalent.
- Prior experience in a cybersecurity consultancy and/or an enterprise security leadership role.
- Familiarity with managed security services, delivery models, and how proactive services integrate with detection and response, as well as supply chain risk offerings.
- Demonstrated knowledge of adversary tactics, techniques, and procedures and how they inform proactive controls.
- Experience presenting at industry conferences, contributing to thought leadership, or publishing security research.
Nardello & Co. offers a competitive total compensation and benefits pay package.
Work Conditions:
- Professional office environment.
- Hybrid working arrangement.
- Some travel required.