Security Advisor - Control Assessor

Soteria

$80K — $120K *
US-AnywhereRemote in Charleston, SC
Technical Services
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5+ years of cybersecurity industry experience
  • 2+ years in a cybersecurity consulting role, focusing on IT audits
  • Familiarity with frameworks like NIST CSF, CMMC, ISO 27001
  • Relevant certifications (CISSP, CISM, CISA) necessary
  • Strong proficiency in Microsoft Suite, particularly Advanced Excel

Responsibilities

  • Perform control gap assessments to identify security program weaknesses
  • Manage project tasks to ensure timely delivery of assessments
  • Identify compliance gaps and recommend solutions based on regulations
  • Review and evaluate information system security controls
  • Execute thorough audit assessments aligned with cybersecurity frameworks
  • Analyze documentation for compliance verification and standards
  • Develop and review organizational policies to ensure regulatory adherence
  • Craft clear reports detailing findings and strategic recommendations
  • Identify and strategize on cybersecurity regulatory requirements
  • Collaborate on remediation plans to align client goals with security standards
  • Present findings to clients including executives in a professional manner
  • Support quality assurance for project deliverables
  • Build client relationships post-assessment for ongoing support
  • Research and assess technologies for secure implementation
  • Adhere to integrity and confidentiality protocols

Benefits

  • Opportunity to make a significant impact on the team and client security
  • Collaborative and supportive company culture valuing authenticity and engagement
  • Exposure to complex projects in a fast-paced environment
  • Professional development opportunities with access to industry events
  • Ability to work with senior-level stakeholders and clients
Full Job Description
About the role

At Soteria, as a Security Advisor you will make an immediate and significant impact on a growing team - protecting an ever-increasing number of clients who need assistance navigating today's threat landscape. You will need to demonstrate and support the Soteria company culture and values, being authentic, engaged, investigative, and caring. This is accomplished through consulting with clients, collaborating with colleagues, clear, efficient, and timely communications, research on relevant security topics, and supporting team efforts for ongoing process and service improvements.

This person will work on complex projects to build relationships with clients, and provide detailed reports with a high level of excellence and care. In addition to the necessary technical acumen, this person must possess a multi-faceted skill set, including experience in project management, requirements gathering and analysis, key resource documentation, key performance indicator development, strategic planning, client relationship management, process improvement, and client-facing communication.

What you'll do

  • Perform control gap assessments to help organizations understand where gaps exist within client security programs.
  • Provide project management tasks to ensure assessment delivery is on time and meets the client's needs.
  • Identify gaps in desired control implements and determine appropriate recommendations for clients based on identified regulatory framework and desired controls.
  • Review information system security controls and evaluate efficacy.
  • Perform detailed audit-like assessments according to cybersecurity-related frameworks.
  • Analyze documentation and evidence provided to verify adherence to prescribed cybersecurity-related frameworks.
  • Develop and review policies, procedures, and other related documentation to ensure compliance with control frameworks.
  • Write clear and well-structured reporting to detail observations and strategic recommendations, at an appropriate level for the intended audience.
  • Identify cybersecurity-related regulatory requirements (e.g., PCI-DSS, HIPAA, CCPA, GDPR, NYDFS) as well as gaps in compliance, and develop strategic plans to achieve and maintain compliance.
  • Work closely with clients and the Soteria team to develop remediation plans to ensure clients achieve their desired outcomes.
  • Document and present findings and recommendations to clients, including C-Suite and board-level executives, in a professional manner.
  • Support project team with quality assurance review of deliverables.
  • Maintain relationships with clients post-assessment in order to assist and advise as they continue to build and improve their security.
  • Maintain competence in security trends, technologies, and practices through self-study and attendance of industry events.
  • Conduct interviews with clients and the Soteria team to evaluate a client's IT environment and security practices.
  • Assess and research common business platforms and technologies to deliver recommendations for secure configurations.
  • Maintain integrity and confidentiality for sensitive client information.

Qualifications

  • 5+ years of industry experience with an understanding of the cybersecurity space
  • 2+ years of experience in a cybersecurity consulting role; specifically conducting IT audits or assessments
  • Familiarity with cybersecurity frameworks such as NIST CSF, CMMC, ISO 27001, and CIS Controls
  • Relevant certifications such as CISSP, CISM, CISA, etc.
  • Strong knowledge of Microsoft Suite, Advanced Excel skills a plus


Candidates must be legally authorized to work full time within the United States and able to pass a background check. Some candidates may require more extensive background checks based on the project.

Similar Jobs

More Jobs at Soteria

More Technical Services Jobs

Find similar Security Advisor - Control Assessor jobs: