Senior Cybersecurity Consultant

Gray Analytics

$130K — $175K *
US-AnywhereRemote in Huntsville, AL
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Certified CISSP, CEH, CGRC required
  • Expertise in at least one compliance framework (NIST CSF, RMF, etc.)
  • Strong experience conducting Risk Assessments (NIST 800-30, CIS RAM)
  • In-depth understanding of cybersecurity policies and network security design
  • Proven ability to lead cyber assessments and project manage compliance initiatives

Responsibilities

  • Lead NIST 800-53 advisory work and FedRAMP compliance guidance
  • Design and review incident response/disaster recovery programs
  • Develop strategic compliance roadmaps for organizations
  • Mentor junior consultants in cybersecurity best practices
  • Prepare detailed reports and presentations for senior stakeholders

Benefits

  • Opportunities for ongoing education and professional development
  • Significant interaction with internal and external stakeholders
  • Path to leadership in projects related to cybersecurity
  • Exposure to diverse compliance frameworks and practices
  • Flexible work environment promoting independent project management
Full Job Description
Description

Lead NIST 800-53 advisory work. Support FedRAMP-related compliance guidance. Design and review IR/DR programs. Provide strategic compliance roadmaps. Participate in CMMC advisory engagements. Mentor junior consultants. KEY COMPETENCIES: Advanced NIST 800-171A interpretation. 800-53 control depth. FedRAMP familiarity. Advanced IR/DR program design. Strategic compliance advisory. Executive briefing capability.

Other duties may include:
  • Prepare for comprehensive assessments of organizational networks and systems to identify any vulnerabilities and to confirm they meet the necessary Cyber Security level requirements.
  • Work with organizations to design and implement security measures and controls, in line with Cyber Security standards, to protect sensitive data and systems from infiltration and cyber-attacks.
  • Coordinate with various teams within an organization to develop and implement the action plans necessary to achieve Cyber Security compliance.
  • Assist organizations with the review and update of existing security policies and procedures to align with evolving Cyber Security requirements and best practices in cybersecurity.
  • Prepare detailed reports on the status of an organization's Cyber Security compliance.
  • Keep abreast of the latest cybersecurity threats and trends, as well as updates to the Cyber Security framework.
  • Achieve utilization targets, complete projects on time and budget, and meet quality standards.
  • Study, learn, test, document, execute and seek to continuously improve scalable consulting services processes to effectively deliver customer engagements while achieving a high level of customer satisfaction.
  • Execute project planning, scheduling, and other coordination of internal and customer resources to conduct interviews, meetings, and presentations.
  • Prepare and deliver thoughtful, insightful, and professional presentations to customers and internal Gray Analytics stakeholders.
  • Create, review and edit findings, observations, and recommendations reports.
  • Become knowledgeable of Gray Analytics service offerings, sales process, marketing materials, contract and SOW structure, methodologies, delivery standards, work tools, and processes.
  • Pursue additional education and stay current on best practices, technical skills, and tools related to the position's duties.
  • This position has significant interaction with internal and external stakeholders, including colleagues, customers, partners, subcontractors, and potential investors. This position requires a strong customer service orientation and the ability to:
  • Work independently on a variety of projects simultaneously,
  • Exercise good judgment and initiative to manage priorities,
  • Quickly develop trusting relationships with a variety of compliance and information system professionals,
  • Pose questions and listen to customer responses effectively to draw out essential facts, data, business process descriptions, sensitivities, and perspectives, and
  • Demonstrate strong organizational abilities, effective writing skills, and communications skills.
  • Develop presentations with clear messages, and effective slides, and deliver these presentations to senior executives
  • Lead teams of internal and external stakeholders to drive security projects forward
  • Identify and manage client engagement risks and issues

Budgeted salary for this role is estimated to be between $130,000-$175,000 per year.

Requirements

Required Qualifications:

Must be a Certified CISSP, CEH, CGRC
  • Strong understanding and experience with Cybersecurity Risk Management principles with an emphasis on Framework Adoptions.
  • Specific expertise in at least one of the below frameworks required:
    • NIST Cybersecurity Framework (NIST CSF)
    • NIST Risk Management Framework (NIST RMF)
    • DoD Cybersecurity Policies including DFARS 7012, NIST 800-171 and CMMC
    • HIPAA Security Rule / HITRUST
    • ISO 27001 o System and Organizational Controls (SOC)
    • Center for Internet Security (CIS)
  • Ability and experience conducting Risk Assessments to include NIST 800-30 and/or CIS RAM methodologies.
  • In-depth understanding of cyber security policy, tools, threat mitigation techniques, network topologies, and secure network design.
  • Ability to identify project requirements, develop project costs/schedules, coordinate technical activities, and implement risk mitigation activities.
  • Experience leading or conducting cyber assessments.
  • Experience in designing and reviewing system architecture designs.
  • Excellent technical writing and verbal communication skills.
  • Ability to present findings and recommendations to an executive team or board.


Preferred Qualifications:
  • CMMC Provisional Assessor (PA)
  • Certified Information Systems Security Professional (CISSP)
  • Certified Information Systems Auditor (CISA)
  • Certified Information Security Manager (CISM)
  • Certified Information Privacy Professional (CIPP)
  • Certified Ethical Hacker (CEH) or equivalent
  • Certified Incident Handler (ECIH) or equivalent
  • COMPTIA Security+, GIAC Security Essentials (GSEC), or equivalent

Similar Jobs

More Jobs at Gray Analytics

  • DevSecOps Engineer
    $95K — $115K *
    Huntsville, AL 35810 (Madison County)
    Information Technology
    In-Person
  • EO Product Owner
    $100K — $130K *
    Huntsville, AL 35810 (Madison County)
    Aerospace & Defense
    In-Person

More Information Technology Jobs

Find similar Senior Cybersecurity Consultant jobs: