Published Date
3 weeks ago
Work Arrangement
Hybrid • New York, NY
Open Positions
4 openings
Experience Level
Senior
About the opportunity
Advise multinational clients on NIST CSF, SOC 2, ISO 27001, and automated continuous compliance frameworks.
What you will do
- check_circle Conduct gap assessments and readiness audits against ISO 27001:2022, NIST SP 800-53, and SOC 2 Type II controls.
- check_circle Implement continuous compliance automation tooling (Vanta, Drata, ServiceNow GRC) for enterprise clients.
- check_circle Evaluate third-party vendor cyber risks and author Vendor Risk Management (VRM) scorecards.
- check_circle Develop enterprise information security policies, data classification schemes, and risk registers.
What we are looking for
- arrow_circle_right 4+ years in IT audit, cyber risk advisory, or enterprise GRC consulting.
- arrow_circle_right Certifications: CISA, CRISC, CISM, or ISO 27001 Lead Auditor.
- arrow_circle_right Deep familiarity with cloud security frameworks, audit evidence collection, and regulatory mandates.
Skills & Tech Stack
Why candidate applications stand out
Verified Technical Credentials
Applications include direct proof-of-work repositories and instructor verification endorsements.
Fast-Track Hiring Visibility
Direct internal referral channels through enterprise partners bypass automated resume discard filters.