Security Consultant Job DescriptionJob TitleSecurity ConsultantJob Summary We are seeking an experienced Security Consultant to assess, design, and improve the organization's cybersecurity posture. The ideal candidate will identify security risks, perform security assessments, recommend remediation strategies, and work closely with IT, engineering, and business teams to implement security best practices. The Security Consultant will support compliance initiatives, conduct risk assessments, and help secure cloud, network, and application environments. Key ResponsibilitiesConduct security assessments, vulnerability assessments, and security audits across IT environments. Perform risk assessments and develop mitigation strategies aligned with business objectives. Advise on security architecture for on-premises, cloud, and hybrid infrastructures. Develop and review security policies, standards, procedures, and technical documentation. Support compliance initiatives for standards and regulations such as ISO/IEC 27001, NIST Cybersecurity Framework (CSF), PCI DSS, HIPAA, SOC 2, and GDPR, as applicable. Collaborate with infrastructure, DevOps, application development, and cloud teams to integrate security best practices. Review network, cloud, endpoint, identity, and application security controls. Coordinate and validate vulnerability remediation efforts with technical teams. Assist with incident response activities, root cause analysis, and post-incident reviews. Evaluate and recommend security technologies, tools, and architectural improvements. Deliver security awareness sessions and provide guidance to internal stakeholders. Stay informed on emerging cyber threats, vulnerabilities, and industry trends. Required SkillsStrong understanding of cybersecurity principles and risk management. Knowledge of network security, firewalls, VPNs, IDS/IPS, WAFs, and Zero Trust concepts. Experience with cloud security in AWS, Microsoft Azure, or Google Cloud Platform (GCP). Familiarity with Identity and Access Management (IAM), Privileged Access Management (PAM), and Multi-Factor Authentication (MFA). Experience with vulnerability management and security assessment tools. Understanding of endpoint security, SIEM, EDR, and XDR technologies. Knowledge of secure system architecture and security hardening. Familiarity with scripting or automation using Python, PowerShell, or Bash. Strong analytical, communication, documentation, and stakeholder management skills. Preferred QualificationsBachelor's degree in Cybersecurity, Information Security, Computer Science, Information Technology, or a related field. 4-8+ years of experience in cybersecurity consulting, security engineering, or information security. Experience supporting enterprise security programs and governance initiatives. Familiarity with DevSecOps and secure software development practices. Experience conducting security reviews for cloud and hybrid environments. Nice-to-Have SkillsThreat modeling Security architecture design Cloud security DevSecOps Infrastructure as Code (Terraform, Ansible) Kubernetes security Docker security API security Penetration testing Threat intelligence MITRE Telecommunication&CK framework OWASP Top 10 Python PowerShell Tools & TechnologiesMicrosoft Defender XDR CrowdStrike Falcon Microsoft Sentinel Splunk QRadar Tenable Nessus Qualys VMDR Rapid7 InsightVM Burp Suite Wireshark AWS Security Hub Microsoft Defender for Cloud Prisma Cloud Terraform Ansible Kubernetes Docker Git Key CompetenciesRisk assessment and decision-making Analytical and problem-solving skills Strong communication and presentation abilities Client and stakeholder management Security consulting and advisory mindset Documentation and reporting Collaboration and teamwork Continuous learning Key Performance Indicators (KPIs)Number and quality of security assessments completed Risk reduction and remediation effectiveness Vulnerability remediation closure rate Compliance audit success rate Security policy and standards adoption Incident response support effectiveness Client or stakeholder satisfaction Improvement in overall security posture Preferred CertificationsCertified Information Systems Security Professional (CISSP) Certified Cloud Security Professional (CCSP) Certified Information Security Manager (CISM) CompTIA Security+ CompTIA CySA+ GIAC Security Essentials (GSEC) ISO/IEC 27001 Lead Implementer or Lead Auditor Microsoft Certified: Cybersecurity Architect Expert AWS Certified Security - Specialty Certified Ethical Hacker (CEH) (preferred where relevant)