Description
The Senior Security Consultant leads Global Compliance Advisory engagements that may include NIST 800-53, SOC2 and ISO 27001 frameworks. Engagements which may include identifying compliance gaps, advising, developing compliance documentation, and/or evaluating the security and compliance of client systems and services to meet requirements. This role will have a strong understanding of NIST 800-53, SOC2 and/or ISO 27001 framework requirements. They will collaborate with Project Managers, Directors and other Delivery team members to effectively execute project timelines and associated deliverables.
Requirements
SKILLS
Essential
– Strong written and verbal communication skills
– Strong personal initiative to appropriately manage time and meet deadlines
– Strong Consulting skills; ability to advise and challenge the status quo while building strong relationships
– Ability to build high-trust relationship and credibility quickly
– High attention to detail
– Ability to facilitate meetings to small or large groups
– Diplomatic and broad minded
– Ability to deliver feedback to junior team members
– Ability to clearly communicate tasks to team members
EXPERIENCE
Essential
– 5+ years of experience as a consultant within professional IT services
– Working knowledge of virtualization or cloud technologies
– Working knowledge of client-server and traditional on-premises architecture
– Knowledge of information security related solutions, tools, and utilities
– 4+ years of experience working on audits, readiness assessments, risk assessments, and/or policy review within one or more of the following frameworks:
* ISO/IEC 27701:2022
* System and Organization Controls (SOC) 2
* NIST 800-53 (FedRAMP, FISMA, DoD Cloud SRG, etc.)
* NIST 800-171 (CMMC)
REQUIRED CERTIFICATIONS/SKILLS
– Dependent on the framework(s) you will be supporting you must have one or more of the following
* ISO/IEC 27001 Lead Auditor
* ISO/IEC 27001 Lead Implementor
* CISA
* CISM
* CISSP
* CMMC CCP or CCA
PREFERRED CERTIFICATIONS/SKILLS (not required)
– Security+
– Certificate of Cloud Security Knowledge (CCSK)
– ISO 9001:2015 Lead Auditor
– ISO 42001:2023 Lead Auditor
– ISO 22301 Lead Auditor/Implementer
– AWS/GCP/Azure specific certifications
EDUCATION
Essential
– Bachelor’s degree in (four-year college or university) in IT or business, or equivalent combination of education and work experience
Job responsibilities
ESSENTIAL RESPONSIBILITIES
– Lead advisory projects including workshops, gap analyses, system security plan development, policies and procedures development, risk assessments, and other consulting services as required.
– Provide IT system security consultation within cloud-based and on-premises environments in accordance with NIST 800-53, SOC 2, and/or ISO 27001.
– Draft gap analysis reports and internal audit reports pertaining to NIST 800-53, SOC 2, and/or ISO 27001.
– Develop and/or review applicable framework required documentation (i.e. Systems Security Plan (SSP), ISO 27001 Statement of Applicability, and/or SOC2 System Description)
– Develop and/or review NIST 800-53, SOC 2, and/or ISO 27001 related policy and procedure documentation and prepare customers for associated assessments.
– Facilitate NIST 800-53, SOC 2, and/or ISO 27001 risk assessment engagements
– Identify and communicate NIST 800-53, SOC 2, and/or ISO 27001 gaps along with remediation recommendations.
– Oversee the collection and interpretation of information provided by clients, map to appropriate requirements and collaborate with project leads to determine overall level of compliance.
– Manage priorities and tasks to achieve delivery utilization targets.
– Ensure quality products and services are delivered on time.
– Ensure continuous professional development by maintaining industry specific certifications.
– Collaborate with project managers, quality management, sales and other delivery team members to drive customer satisfaction and meet project deliverables.
– Establish and maintain positive collaborative relationships with clients and stakeholders
WORK ENVIRONMENT/TRAVEL REQUIRED
– Travel up to 25%
– Hybrid 3 days in the office
What we offer
Exciting Projects: Come take your place at the forefront of digital transformation! With clients across all industries and sectors, we offer an opportunity to work on market-defining products using the latest technologies.
Collaborative Environment:Expand your skills by collaborating with a diverse team of highly talented people in an open, laidback environment — or even abroad in one of our global centers or client facilities!
Work-Life Balance:GlobalLogic prioritizes work-life balance, which is why we offer flexible work schedules.We offer you the best quality of work life so that you exceed the expectations of our clients, while achieving your professional and personal ambitions.
Professional Development:Our dedicated Learning & Development team regularly organizes English classes, professional certifications, and technical and soft skill trainings. We also offer the chance to travel internationally
Excellent Benefits:We provide our employees with competitive salaries, family medical insurance, extended paternity leave, annual performance bonuses, and referral bonuses.
About GlobalLogic
GlobalLogic, a Hitachi Group Company, is a trusted digital engineering partner to the world’s largest and most forward-thinking companies. Since 2000, we’ve been at the forefront of the digital revolution – helping create some of the most innovative and widely used digital products and experiences. Today we continue to collaborate with clients in transforming businesses and redefining industries through intelligent products, platforms, and services.
Apply Now
Related job openings
Read moreSoftware Engineer- Apache spark IRC303924
UkraineSenior/Principal Security Engineer IRC303167
PolandSenior/Principal Security Engineer IRC303167
RomaniaSenior/Principal Security Engineer IRC303167
UkraineLead Mobile Developer IRC304059
United StatesSenior Backend QA Automation Engineer (Node.js & Kafka) IRC303865
Load more



