Security Advisor - GRC

Soteria

$80K — $135K *
US-AnywhereRemote in Charleston, SC
Business Services
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5+ years of industry experience in cybersecurity
  • 2+ years in a cybersecurity consulting role, especially conducting IT audits
  • Familiarity with cybersecurity frameworks (NIST CSF, CMMC, ISO 27001, CIS Controls)
  • Strong knowledge of Microsoft Office, advanced Excel skills preferred
  • Relevant certifications (CISSP, CISM, CISA)

Responsibilities

  • Perform control gap, risk, and compliance assessments to identify security program gaps
  • Develop and conduct social engineering simulations and training for clients
  • Manage project tasks to ensure timely assessment delivery
  • Identify control gaps and provide regulatory framework-based recommendations
  • Conduct interviews to evaluate client IT environments and security practices
  • Create various deliverables including reports and presentations for clients
  • Support and guide Advisory team members in multiple security disciplines
  • Document and present findings clearly to C-Suite and board-level executives
  • Maintain post-assessment client relationships for ongoing support
  • Assess cybersecurity technologies and recommend secure configurations

Benefits

  • Flexible remote work environment
  • Opportunity for professional growth in a dynamic field
  • Engagement with a diverse client roster
  • Support for continuous learning and industry event attendance
  • Guidance from experienced team members in various cybersecurity domains
Full Job Description
About the role

As a Security Advisor at Soteria, you will join a fast-paced GRC team supporting a growing roster of clients navigating today's threat landscape. This role calls for authenticity, engagement, curiosity, and care reflected in every client interaction. You will assess risk, evaluate controls, guide clients toward stronger security postures, delivering clear, timely, well-documented findings.

Success here requires solid technical grounding, paired with strong project management, requirements gathering, and client communication skills. You will juggle multiple engagements at once, adapting quickly, maintaining high quality under tight deadlines.

What you'll do

  • Perform control gap, risk, and compliance/regulatory assessments to help organizations understand where gaps exist within client security programs.
  • Develop and perform social engineering simulations (phishing, vishing) and present social engineering training to organizations to improve their security awareness programs.
  • Provide project management tasks to ensure assessment delivery is on time and meets the client's needs.
  • Identify gaps in desired control implements and determine appropriate recommendations for clients based on identified regulatory framework and desired controls.
  • Conduct interviews with clients and the Soteria team to evaluate a client's IT environment and security practices.
  • Work closely with clients and the Soteria team to develop deliverables to include, but not limited to:
    • executive summary reports
    • detailed findings and recommendations reports
    • presentation slide decks
    • plans of action and milestones
    • policy and procedure development
    • ad-hoc written reports
  • Provide support and guidance where necessary to Advisory team members to achieve excellence in the various business areas of Trusted Advisory and vCISO, Risk/Gap Assessments, Incident Response Readiness, Table Top Exercises, Business Continuity and Disaster Recovery Plans and Policy development.
  • Write clear and well-structured reporting to detail observations and strategic recommendations, at an appropriate level for the intended audience.
  • Identify cybersecurity-related regulatory requirements (e.g., PCI-DSS, HIPAA, CCPA, GDPR, NYDFS) as well as gaps in compliance, and develop strategic plans to achieve and maintain compliance.
  • Work closely with clients and the Soteria team to develop remediation plans to ensure clients achieve their desired outcomes.
  • Document and present findings and recommendations to clients, including C-Suite and board-level executives, in a professional manner.
  • Support project team with quality assurance review of deliverables.
  • Maintain relationships with clients post-assessment in order to assist and advise as they continue to build and improve their security.
  • Maintain competence in security trends, technologies, and practices through self-study and attendance of industry events.
  • Maintain integrity and confidentiality for sensitive client information.
  • Assess and research common business platforms and technologies to deliver recommendations for secure configurations.

Qualifications

  • 5+ years of industry experience with an understanding of the cybersecurity space
  • 2+ years of experience in a cybersecurity consulting role; specifically conducting IT audits or assessments
  • Familiarity with cybersecurity frameworks such as NIST CSF, CMMC, ISO 27001, and CIS Controls
  • Strong knowledge of Microsoft Suite, Advanced Excel skill a plus
  • Relevant certifications such as CISSP, CISM, CISA, etc.

Hours of Operation:

  • Soteria is a remote workforce with flexibility in scheduling. The majority of work time will be 9:00 AM EST to 5:00 PM EST.

This is a remote position; however, occasional travel may be required for client engagements, team meetings, or other business needs.

The pay range for this role is:

80,000 - 135,000 USD per year (Remote)

Similar Jobs

More Jobs at Soteria

  • Security Engineer
    $120K — $150K *
    Remote
    Information Technology
    Remote in Charleston, SC

More Business Services Jobs

Find similar Security Advisor - GRC jobs: