Senior Cybersecurity Compliance Consultant (US Remote)
$95k - $120kIntelligent Technical Solutions (ITS)
- Remote job
Job Description
Job Description
Job Summary
The Security Advisor (Senior Cybersecurity Compliance Consultant) delivers active security practice management engagements, serving as the assigned security officer (vCISO) for a portfolio of client organizations. The role combines hands-on compliance delivery with client relationship ownership, risk management, and ongoing security advisory work. The role requires subject matter expertise across regulatory compliance frameworks, strong client-facing communication, and organizational discipline to manage a high volume of concurrent engagements. This position sits at the senior end of the practice: it carries the most complex and highest-regulatory-risk engagements in the portfolio and sets the technical standard for the practice's compliance deliverables.
Reports to: Security Practice Management Team Lead (Cybersecurity Department)
Direct Reports: None
Works with: Practice coordinators, security engineers, SOC personnel, and department leadership supporting assigned engagements
Job Responsibilities
1. Client Advisory & vCISO Delivery:
- Serve as the assigned security officer (vCISO) for a portfolio of client engagements: lead recurring meeting cadences, act as the primary point of contact for clients' cybersecurity concerns and provide regular updates and reports on the status of security initiatives, including performance metrics, findings, and recommendations for improvement.
- Build strong client relationships, understand each client's unique regulatory and business requirements, and address their needs with tailored strategies and security roadmaps.
- Identify above-contract demand and security program growth opportunities within assigned accounts, surfacing right-sizing and expansion recommendations to practice leadership ahead of contract renewal.
- Track and maintain contract health ensuring that issues with delivery are communicated early.
2. Compliance Program Delivery:
- Lead CMMC Level 1 and Level 2 readiness engagements: NIST SP 800-171 control assessments, System Security Plan (SSP) development, POA&M creation and management, SPRS score submission support, evidence collection, and client preparation for third-party assessment.
- Advise clients on CUI scoping, DFARS View phone number on ziprecruiter.com and FAR 52.204-21 obligations, and enclave architectures, including Microsoft GCC High environments.
- Deliver compliance engagements across additional frameworks as assigned, including HIPAA / HITECH, SOC 2 (Types I and II), PCI DSS v4.0, FTC Safeguards Rule, GLBA, ISO/IEC 27001 and 27002, NIST Cybersecurity Framework 2.0, NIST SP 800-53, CIS Critical Security Controls v8, and AI governance (NIST AI RMF, ISO/IEC 42001).
- Advise on sector- and state-specific regimes as engagements require, including NY DFS 23 NYCRR Part 500, SEC cybersecurity disclosure rules, CJIS Security Policy, StateRAMP / FedRAMP readiness, and U.S. state privacy laws (CCPA/CPRA and successors) alongside GDPR and ISO/IEC 27701 where clients have international exposure.
- Map overlapping control sets across frameworks to build unified control matrices, eliminating duplicate evidence collection across a client's concurrent compliance obligations.
3. Security Assessment & Engineering Support:
- Conduct comprehensive risk assessments to identify potential threats and vulnerabilities, develop and implement mitigation strategies to enhance clients' security postures, and monitor compliance with regulatory requirements and industry standards, recommending remediation actions to address gaps or deficiencies.
- Oversee data collection efforts to verify compliance and gather critical security information within client infrastructures, ensuring accuracy and reliability.
- Review and interpret security tooling outputs across the Microsoft security stack (Defender XDR, Sentinel, Entra ID Protection, Intune, Purview, Conditional Access) and coordinate remediation with client IT teams and internal engineers.
4. Other Responsibilities:
- Perform general Security Officer duties, such as running security huddles, supporting cyber insurance questionnaires and attestations, and ensuring security tool functionality for assigned clients.
- Assist with incident response (IR) activities, including possibly participating in the on-call incident escalation rotation, supporting SOC coordinators, communicating with key stakeholders during incidents, contributing to playbooks, and conducting postmortems with clients.
- Maintain accurate, timely time entries in the PSA (ConnectWise Manage); delivered hours are the practice's operational and financial source of truth.
- Contribute to scalable templates, engagement processes, and the practice knowledge base, fostering a culture of continuous improvement and knowledge sharing.
- Serve as an escalation resource on advanced framework interpretation and control-determination questions, and support quality review of compliance deliverables prior to client or assessor submission.
- Stay informed about emerging threats, vulnerabilities, and regulatory changes — including the DoD's phased CMMC rollout — assessing their potential impact on clients and adjusting strategies accordingly.
Job Qualifications
Credentials & Eligibility:
- CISSP (active and in good standing) — required at time of hire. This is a hard requirement: commitments to obtain, lapsed or Associate-level credentials, and equivalent-experience substitutions will not be considered.
- CMMC ecosystem credentials required: CCP (Certified CMMC Professional) active at time of hire, with CCA (Certified CMMC Assessor) required within the first 12 months. Registered Practitioner (RP) status alone does not satisfy this requirement.
- Additional certifications a plus: CISM, CRISC, CISA, GIAC (GSLC, GCCC), CompTIA Security+, Security X, Microsoft SC-series.
- Minimum eight (8) years of progressive information security experience, including at least three (3) years delivering compliance or vCISO engagements across a multi-client portfolio in a consulting, MSP, or MSSP environment or something similar.
- Demonstrated ownership of at least two (2) completed CMMC Level 2 readiness engagements, or equivalent NIST SP 800-171 assessment work, including SSP authorship and POA&M management through to third-party assessment.
- Documented working depth in a minimum of three (3) distinct regulatory frameworks — surface familiarity across many frameworks is not a substitute for demonstrated depth.
- Experience defending deliverables and control determinations directly to auditors, third-party assessors, or regulators.
- U.S. person status (U.S. citizen or lawful permanent resident) required due to access to Controlled Unclassified Information (CUI) under DFARS flow-down obligations.
- U.S.-based remote with reliable availability across U.S. business time zones; occasional travel to client sites for assessment support.
Technical Skills:
Cybersecurity & Compliance Knowledge:
- Working command of cybersecurity principles and practices, including compliance standards and regulations such as CMMC / NIST SP 800-171 and 800-171A, NIST SP 800-53, NIST CSF 2.0, HIPAA / HITECH, SOC 2, PCI DSS v4.0, FTC Safeguards Rule, GLBA, ISO/IEC 27001 / 27002, and CIS Controls v8.
- Familiarity with the federal contracting compliance stack — DFARS View phone number on ziprecruiter.com, 7019, 7020 and 7021, FAR 52.204-21, CUI marking and handling per 32 CFR Part 2002, and the phased CMMC rule.
- Awareness of adjacent privacy and sector regimes: U.S. state privacy laws, GDPR, NY DFS Part 500, SEC cyber disclosure obligations, and CJIS.
- Proficiency in incident response and threat mitigation strategies.
Risk Management:
- Ability to conduct comprehensive risk assessments and map findings to security controls.
- Experience building and maintaining remediation plans (POA&Ms) and mitigation strategies.
Technical Tools:
- Familiarity with cybersecurity tools and technologies (e.g., SIEM, EDR/XDR, IDS/IPS, firewalls), with Microsoft security stack experience preferred.
- Experience with GRC and compliance platforms (e.g., IntelliGRC, Vanta, Secureframe, Drata, Onetrust, FutureFeed) and evidence-collection workflows.
Engagement Management Skills:
- Ability to manage a high volume of concurrent client engagements (20–30 relationships) with disciplined prioritization.
- Strong scheduling and follow-through; proficiency with PSA/ticketing and project tracking tools.
- Ability to work within — and improve — standardized templates and delivery processes.
Interpersonal Skills:
- Excellent communication skills for interacting with client stakeholders from IT staff to executives; ability to translate technical findings into business terms.
- Ability to build and maintain strong client relationships and work effectively with coordinators and a distributed team.
Analytical and Reporting Skills:
- Ability to track and report on engagement metrics, compliance status, and deliverable progress.
- Proficiency in generating clear client-facing and executive-level reports.
- Expertise in monitoring regulatory compliance and refining security policies and procedures based on industry best practices.
Professional Development:
- Commitment to staying current on emerging trends and technologies in cybersecurity, the CMMC ecosystem, and evolving compliance requirements.
- Participation in industry training, conferences, and credential maintenance.
Compensation
Pay rate starts at $95,000.00 up to $120,000.00 annually and may vary by experience and location.
- Total compensation for this role consists of two components: (1) a base component, paid as an hourly rate or annual salary, and (2) a delivery-based compensation bonus, paid monthly.
- Delivery bonus: paid monthly and calculated on the preceding month's delivery performance - delivered hours recorded in the PSA, engagement milestone completion (SSP delivery, POA&M currency, assessment readiness), and client retention and contract health across the assigned portfolio.
- Bonus targets and measurement criteria are established at hire and reviewed [annually]. Accurate and timely PSA time entry is a prerequisite for bonus calculation.
- Total compensation for this role is positioned above the standard Security Advisor band to reflect the credential, experience, and framework-depth requirements above.
Benefits
- Medical Insurance Plan
- Dental & Vision
- Life Insurance
- Disability Coverage
- Paid Time Off (starts at 15 days per year)
- Paid Maternity/Paternity Leave
- Paid US Holidays
- Retirement Plan
- Salary Advancement/Loan
- Health & Wellness Program
- Company-paid training and certification
- Supplemental Life Insurance (Employee-paid)
- Supplemental Health Plans (Employee-paid)
Fraud Alert – Recruitment Scams
Intelligent Technical Solutions (ITS) has been made aware of fraudulent job postings and communications misrepresenting our company. Applicants are advised to exercise caution and apply only through official ITS channels.
- ITS does not request payment or financial information at any stage of the hiring process.
- Sensitive personal information (e.g., Social Security numbers) will not be requested prior to a formal offer.
- We have become aware of fake profiles on LinkedIn, Facebook, and other social media platforms impersonating our employees and falsely claiming to represent our company. Please exercise caution when interacting with these accounts.
- If you receive suspicious messages or requests, do not engage. Report them to View email address on ziprecruiter.com.
- All verified job openings are posted here: -openings.
PRE-RECORDED VIDEO INTERVIEW
$160k - $190k
...Job Description Job Description Senior Federal Cybersecurity & Compliance Consultant (Expert in CMMC, NIST, FedRAMP,... ...Regulatory Compliance) Remote / Full-Time Are you a brilliant... ...AI Governance. Our clients value us because we don’t just deliver checklists...Remote workSeniorFull timeFlexible hours$108k - $140k
...Aspicio, you can join a leading consulting firm that specializes in... ..., innovative team.The Senior Cybersecurity and Compliance Consultant (Federal Programs... ...Aspicio DC office, and remotely. All candidates must live... ...different locationsClearance: US Citizenship only (no dual...Remote workSeniorContract workLive inWork at officeFlexible hours- Remote Senior Cybersecurity & Compliance Consultant (HIPAA, NIST & SOC 2) We are seeking a Remote Senior Cybersecurity & Compliance Consultant (HIPAA, NIST & SOC 2) to lead cybersecurity and compliance engagements for clients in healthcare, professional services, and other...Remote jobSeniorFull timeWork at office
- ...future direction of BCBSA's cybersecurity program. -Assess internal and... ...Management Program (FedRAMP) compliance strategy by building and scaling... ...providing status updates to Senior/Executive management.... ...with the law. SummaryLocation: US IL Chicago E. RandolphType: Full...SeniorFull timeShift work
$115k - $130k
Senior Security Compliance Analyst (Remote - US) Senior Security Compliance Analyst (Remote - US) Get AI-powered advice on this job and more exclusive features. This range is provided by Jobgether. Your actual pay will be based on your skills and experience — talk with...Remote jobSeniorFull timeWorldwideFlexible hours$140k - $165k
...APPROXIMATELY 60% ONSITE/40% REMOTE. AUSGAR... ...Information Assurance, Cybersecurity and Systems Engineering... ...right individual! Senior Cybersecurity Analyst... ...cybersecurity vulnerabilities and compliance issues. Work with the... .... Please e-mail us at ****@*****.*** if...Remote workSeniorFull timeContract workFor contractorsWork experience placement- Baker Tilly is seeking a Senior Payroll Consultant within our Human Resources & Payroll Consulting team... ...focused on payroll operations, compliance, and process improvement. You’ll work... ...working with clients, and building expertise across #J-18808-Ljbffr Baker Tilly USRemote jobSenior
- ...innovative solutions to complex global health challenges. Position Title : Senior Compliance Consultant Expected Duration : 11 months: Sept 2026- Aug 2027 Location : Remote / US Rate : PSI requests all consultants to submit a resume with daily rate included...Remote workSeniorDaily paidTemporary workPart timeLocal areaImmediate start
- ...Technical Group (LMR) is seeking a Senior Cyber Security Specialist.... ...is critical to ensuring compliance with DoD cybersecurity policies, standards and... ...support for network switches and remote system updates. Perform... ...process, please contact us at ****@*****.*** . EOE...Remote workSeniorFull timeTemporary work
$135k - $143k
...Work Location: Remote with occasional on-site... ...per month. The Senior Cybersecurity Analyst leads in the... ...Risk Management & Compliance: Conduct comprehensive... ...Requirements US citizenship required.... ...requirements. Gunnison Consulting Group's total compensation...Remote workSeniorFull timeContract workCasual workFlexible hours- Power your future at Qualus as a Senior Utility Compliance Consultant. In this position you will play a pivotal... ...Microsoft tools experience (MS 365, Teams, remote desktop, etc.) Experience with... ...applicable human rights legislation across Canada and the US. #J-18808-Ljbffr QualusRemote jobSeniorTemporary workWork experience placementWork from homeFlexible hours
$105k - $145k
Senior Cyber Security Specialist — Denver, Colorado... ...activities, and ensuring compliance with global cyber... ...such as NERC CIP, NIST Cybersecurity Framework, or IEC 6244... ..., and vision care for US team members starts on... ...office, Monday and Friday remote)Monthly personal phone...Remote workSeniorWork at officeLocal areaMonday to Friday$86.8k - $198k
Enterprise Cybersecurity Vulnerability Analyst, SeniorThe Opportunity:Support Booz Allen... ...KPIs to other operational teams and senior leadership.Join us. The world can't wait.You Have:4+ years... ...their cameras on during meetings.Remote: If this position is listed as remote...Remote workSeniorFull timeContract workPart timeWork at officeLocal area- ...To support a growing Cybersecurity Professional Services practice, the remote Senior Cybersecurity Consultant will serve as a trusted advisor to client leadership, providing guidance on governance, risk, and compliance (GRC), and leading client engagements focused on security...Remote workSenior
$120k - $150k
...The Senior Cybersecurity Consultant will serve as both a Virtual Chief Information Security Officer (vCISO) and CMMC Readiness Consultant. This... ...mature their cybersecurity programs, conduct security and compliance assessments, and guide organizations through CMMC...Remote workSenior$100k - $130k
...moins utilisés et pour consulter vos préférences, veuillez... ...l’identification.Sr. Compliance Officer - Monitoring &... ...Associate), TD Securities (US) page is loaded## Sr.... ...), TD Securities (US)remote type: Hybridelocations:... ...Qualifications:**This Senior Compliance Officer is a...Remote workSeniorTemporary workWork experience placementWork from homeFlexible hours$148.01k
Job Summary: As a Senior Cyber Security Manager, you’ll be leading... ...necessary. Work with outside consultants as appropriate for... ...in our office, and three days remotely. If located outside of San Antonio... ...develop world-class talent. Join us on our mission to embrace technology...Remote workSeniorFull timeWork experience placementWork at office- A leading NetSuite solution partner in the US is seeking a Senior NetSuite Consultant to lead a team and drive project delivery. The role requires 4+ years of NetSuite experience and strong communication skills. You'll mentor junior consultants and stay hands-on with clients...Remote workSenior
- ...Accountant to manage accurate financial records and support accounting functions. This fully remote role requires strong analytical skills and familiarity with eCommerce accounting, US GAAP, and financial statements. Ideal candidates have over 5 years of experience and...Remote workSenior
$99k - $225k
Cybersecurity Operations Center Analyst, SeniorThe Opportunity:Are you ready... ...and incident response. Join us as we protect clients from... ...feeds that inform briefings for senior leadership aligned to our... ...their cameras on during meetings.Remote: If this position is listed...Remote workSeniorFull timeContract workPart timeWork at officeLocal area- ...technology business is seeking an experienced Benefits Specialist to manage US benefits and leave programs. This fully remote role involves owning various employee benefit programs, ensuring compliance across multiple states, and supporting broader HR operations. Ideal...Remote workSenior
- ...VirtuHire is looking for an experienced Senior Bookkeeper to manage full-cycle bookkeeping functions for a diverse portfolio of US clients. The ideal candidate will work with QuickBooks Online, handle reconciliations, financial reporting, and maintain accurate financial...Remote workSenior
- ...while delivering secure, scalable, and future-ready cloud solutions. You will partner with sales and technical teams to drive strategy, architecture, and successful client outcomes in complex environments, ensuring long-term cloud adoption #J-18808-Ljbffr Jobleads-USRemote jobSenior
- A leading cybersecurity company is seeking a Solutions Consultant to guide clients through their security transformation journeys. This role involves providing technical leadership, building customer relationships, and delivering impactful presentations. The ideal candidate...Remote jobSenior
- ABS Consulting is seeking a Senior Consultant I in Cybersecurity to provide technical expertise across multiple engagements, including RMF and A&A. The role requires... ...(50%+) to client sites is expected as part of a remote position. The ideal candidate has a bachelor's...Remote jobSeniorWork at office
- ...advertising relationships across multiple countries, including the US and Europe. The role involves converting qualified clients to... ...search advertising and exceptional organizational skills. This fully remote position offers competitive salaries and benefits. #J-18808-...Remote jobSenior
- ...developing new business leads within the regulated payments sector in the US and Canada. The ideal candidate will have a strong background in... ...and a track record of exceeding sales targets. The position is remote, offering flexibility for candidates on the West Coast or Central...Remote jobSenior
- Syneos Health, Inc. is seeking an Experienced Clinical Project Manager - Inflammation (Sponsor Dedicated/ Remote- US only) to oversee complex trials from start-up through closeout. You will lead cross-functional teams, manage vendors, and drive study execution in a fast...Remote jobSenior
- ...Job Title : CMMC Level 1 Cybersecurity Compliance Consultant Location : Remote Job Type : Contract About Prestige Development Group (PDG) Prestige Development Group (PDG) specializes in providing innovative human capital management solutions...Remote workContract workLocal area
$2,000 - $4,500 per month
...Position: Senior Legal Compliance and Licensing Specialist (Remote) About Us We are a rapidly expanding med-spa organization operating across multiple U.S. states, including Oklahoma, Texas, Tennessee, Kentucky, Ohio, Indiana, Georgia, and Florida. As we continue...Remote workSenior
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Senior Cybersecurity Compliance Consultant (US Remote). Be the first to apply!
- cyber security specialist Washington DC
- cyber security consultant Washington DC
- senior cybersecurity analyst Washington DC
- regulatory compliance analyst Washington DC
- medicare compliance specialist Washington DC
- regulatory analyst Washington DC
- senior compliance officer Washington DC
- legal compliance officer Washington DC
- privacy compliance analyst Washington DC
- senior compliance analyst Washington DC



