Job Summary:The
CyberAdvisory Senior Associate will be responsible for leading the day-to-day execution and delivery of cybersecurity compliance and advisory engagements focused on
HIPAA, HITRUST, PCI DSS, CMMC, NIST, and other cybersecurity frameworks. This role works directly with clients to assess security and privacy programs, identify compliance gaps, validate control effectiveness, and provide practical recommendations that strengthen cybersecurity and regulatory compliance.
Our Cyber Advisory practice is experiencing significant growth due to increasing regulatory requirements and demand for trusted compliance partners. We are seeking a self-motivated professional with strong assessment experience, excellent communication skills, and a passion for helping organizations improve their cybersecurity posture.
Duties & Responsibilities:- Lead the day-to-day execution of cybersecurity assessment engagements, including HIPAA, HITRUST, PCI DSS, CMMC, and other cybersecurity compliance engagements.
- Perform interviews with client personnel to understand business processes, security practices, and control implementation.
- Review policies, procedures, system configurations, technical evidence, and operational processes to evaluate compliance with applicable frameworks.
- Perform detailed testing of cybersecurity controls, including identity and access management, vulnerability management, logging and monitoring, encryption, incident response, business continuity, third-party risk management, and endpoint security.
- Identify compliance gaps, control deficiencies, and cybersecurity risks while developing practical, risk-based remediation recommendations.
- Assist clients in understanding assessment findings and support remediation planning through collaborative discussions with technical and executive stakeholders.
- Prepare high-quality workpapers, assessment documentation, observations, and client deliverables that clearly communicate risks, compliance status, and recommended corrective actions.
- Contribute to engagement planning, scoping, evidence collection, and project management activities.
- Mentor, coach, and review the work of junior team members to support their technical and professional development.
- Maintain a strong understanding of emerging cybersecurity threats.
- Support business development activities by participating in client presentations, proposal development, webinars, conferences, and thought leadership initiatives.
- Build and maintain strong client relationships while delivering exceptional client service throughout the engagement lifecycle.
- Manage multiple engagements simultaneously while meeting project deadlines and maintaining high-quality standards.
Education & Experience: - Bachelor's degree in Information Systems, Cybersecurity, Computer Science, Accounting, Management Information Systems (MIS), or a related field required.
- 3-6+ years of experience performing cybersecurity assessments, compliance audits, or information security consulting engagements.
- Experience performing assessments against one or more of the following:
- HIPAA Security Rule
- HITRUST CSF
- PCI DSS
- CMMC
- NIST SP 800-171
- NIST Cybersecurity Framework (CSF)
- ISO/IEC 27001
- Experience working in a public accounting, cybersecurity consulting, or professional services environment preferred.
- Experience conducting client interviews, evidence reviews, technical control testing, and report writing.
Ability to manage multiple concurrent engagements and work effectively in a client-facing environment.
Preferred CertificationsOne or more of the following certifications preferred:
- CISA
- CISSP
- HITRUST Certified CSF Practitioner (CCSFP)
- HITRUST Certified CSF Assessor (CCA)
- PCI Qualified Security Assessor (QSA)
- Certified CMMC Professional (CCP)
- Certified CMMC Assessor (CCA)
- CRISC
- Security+
#LI - hybrid