The Bonadio Group has a tremendous opportunity for a Director level client service professional to help lead our FoxPointe Solutions team. This hands-on role would involve technical security assessments of applications and infrastructure, security design reviews as well as risk assessments. A qualified applicant would have strong audit and technical skills from the hardware to the application layer. This is a remote position and may be located anywhere in the US.
Responsibilities:- Lead projects throughout the client acquisition to final project delivery process
- Oversee the efforts of client service teams on multiple client engagements
- Manage, develop, train and mentor staff
- Develop effective working relationships with internal and external clients
- Recognize the opportunity of providing new and innovative services and demonstrates the ability to pursue such opportunities
- Retain and develop new clients, including cultivate opportunities to cross-sell the firm's full range of client services
- Communicating with project stakeholders to effectively convey requirements of technical and process improvements
- Possess an in-depth knowledge of IT security and various frameworks (i.e, NIST, ISO, PCI DSS, HIPAA, CMMC, FFIEC, etc.)
- Performing mid and large IT and information security risk and compliance assessments, PCI engagements, IT audits, Cybersecurity testing, operational gap analyses, and supply effective and reasonable remediation recommendations
Requirements:- At least one Security, Risk or IT certification (i.e. CRISC, CISA, CISM, CISSP, or ISO 27001) achieved
- A minimum of an associate's degree (AS)
- A minimum of eight years of experience in the Cyber Security, Information Assurance, IT Audit areas
- Experience in the Enterprise Risk or Compliance fields
- Self-starter with the ability to handle and manage multiple priorities
- Ability to provide mentoring and leadership to junior staff
- Compliance Expertise: regulatory, privacy, international laws and statutory requirements
- Risk Management Expertise: risk frameworks, maturity models, and enterprise IT security risk methodologies
- Governance Expertise: vendor management, policy frameworks, control design and security design/architecture
- Excellent knowledge of and detailed, documented hands-on experience with various audits and attestation engagements such as PCI DSS, SSAE18, CMMC, NIST CSF, ISO27001, etc.
Preferred requirements:- Experience with Board level presentations including public speaking and presentations on IT and Cybersecurity topics
- Proficiency with writing executive level reports and technical documentation
The salary range for this role is
: $180,000 to $230,000 and is commensurate with experience.
Hours of Operation:- Our office hours are from 8:00 a.m. until 5:00 p.m. Monday through Friday
- Our summer hours are from 8:00 a.m. until 5:00 p.m. Monday through Thursday, with Flex Friday scheduling available in accordance with firm policy and business needs
- We pride ourselves on our flexibility; however, at peak times additional hours may be required