Senior Cybersecurity Compliance Consultant
$95k - $120kjobgether
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Senior Cybersecurity Compliance Consultant based in the United States.
This senior-level role combines cybersecurity compliance consulting, risk management, and client-facing security advisory responsibilities across a diverse portfolio of organizations.
You will serve as a trusted security advisor and vCISO, helping clients strengthen their security programs and navigate complex regulatory requirements.
The position focuses heavily on CMMC and NIST SP 800-171 while also supporting a broad range of cybersecurity, privacy, and governance frameworks.
You will lead high-impact compliance engagements, develop remediation strategies, and guide clients through readiness and third-party assessment processes.
Working closely with security engineers, SOC teams, coordinators, and client stakeholders, you will translate technical requirements into practical business outcomes.
As a senior member of the practice, you will handle complex, high-regulatory-risk engagements and contribute to improving delivery standards, templates, and processes.
The role offers an opportunity to influence cybersecurity programs at both the strategic and operational levels while managing multiple client relationships in a fast-paced consulting environment.
Accountabilities
- Serve as the assigned security officer and vCISO for a portfolio of client organizations, leading recurring meetings, addressing cybersecurity concerns, and providing regular updates, metrics, findings, and recommendations.
- Build trusted client relationships by understanding business objectives, regulatory obligations, and security priorities, then developing tailored security strategies and roadmaps.
- Lead CMMC Level 1 and Level 2 readiness engagements, including NIST SP 800-171 assessments, System Security Plan development, POA&M creation and management, evidence collection, SPRS submission support, and preparation for third-party assessments.
- Advise clients on Controlled Unclassified Information scoping, DFARS and FAR requirements, and secure enclave architectures, including Microsoft GCC High environments.
- Deliver compliance engagements across frameworks such as HIPAA/HITECH, SOC 2, PCI DSS v4.0, FTC Safeguards Rule, GLBA, ISO/IEC 27001 and 27002, NIST CSF 2.0, NIST SP 800-53, CIS Controls v8, NIST AI RMF, and ISO/IEC 42001.
- Support engagements involving privacy, sector-specific, and state or federal requirements, including NY DFS, SEC cybersecurity disclosures, CJIS, StateRAMP/FedRAMP, CCPA/CPRA, GDPR, and ISO/IEC 27701.
- Map overlapping control requirements across multiple frameworks to create unified control matrices and reduce duplicate evidence collection.
- Conduct comprehensive risk assessments, identify threats and vulnerabilities, develop mitigation strategies, and recommend remediation actions to address security and compliance gaps.
- Review security tooling outputs across platforms such as Microsoft Defender XDR, Sentinel, Entra ID Protection, Intune, Purview, and Conditional Access, coordinating remediation with client IT teams and internal engineering resources.
- Support security officer activities, cyber insurance questionnaires, attestations, security huddles, and verification of security tool functionality across assigned accounts.
- Participate in incident response activities when required, including escalation support, stakeholder communications, playbook development, SOC coordination, and post-incident reviews.
- Maintain accurate and timely PSA time entries and contribute to engagement health, delivery tracking, client retention, and operational performance.
- Identify opportunities to right-size or expand security programs, proactively communicating delivery concerns and account growth recommendations to practice leadership.
- Serve as a senior escalation resource for complex framework interpretations and control determinations, while performing quality reviews of compliance deliverables before client or assessor submission.
- Contribute to reusable templates, standardized delivery processes, knowledge resources, and continuous improvement initiatives while staying current on emerging threats and regulatory developments, including the phased CMMC rollout.
Requirements
- Active CISSP certification in good standing is required at the time of hire; Associate-level, lapsed, or planned credentials do not meet this requirement.
- Active Certified CMMC Professional (CCP) certification is required at the time of hire, with Certified CMMC Assessor (CCA) certification required within the first 12 months. Registered Practitioner status alone is not sufficient.
- Eight or more years of progressive information security experience, including at least three years delivering compliance or vCISO engagements across a multi-client portfolio within a consulting, MSP, MSSP, or similar environment.
- Demonstrated experience completing at least two CMMC Level 2 readiness engagements or equivalent NIST SP 800-171 assessment projects, including SSP development and POA&M management through third-party assessment.
- Proven depth of experience in at least three distinct regulatory or cybersecurity frameworks, with the ability to defend control determinations and deliverables directly to auditors, assessors, or regulators.
- Strong knowledge of CMMC, NIST SP 800-171/800-171A, NIST SP 800-53, NIST CSF 2.0, HIPAA/HITECH, SOC 2, PCI DSS, FTC Safeguards Rule, GLBA, ISO/IEC 27001/27002, and CIS Controls v8.
- Familiarity with DFARS View phone number on us.fitly.work, 7019, 7020, and 7021; FAR 52.204-21; CUI requirements under 32 CFR Part 2002; and the phased CMMC regulatory framework.
- Awareness of U.S. state privacy laws, GDPR, NY DFS Part 500, SEC cybersecurity disclosure requirements, CJIS, and related sector-specific compliance regimes.
- Strong risk management capabilities, including risk assessments, control mapping, remediation planning, POA&M management, and mitigation strategy development.
- Experience with SIEM, EDR/XDR, IDS/IPS, firewalls, and cybersecurity monitoring technologies, with Microsoft security stack experience preferred.
- Familiarity with GRC and compliance platforms such as IntelliGRC, Vanta, Secureframe, Drata, OneTrust, or FutureFeed, as well as evidence-collection workflows.
- Ability to manage a high volume of concurrent client engagements, typically involving 20–30 client relationships, while maintaining strong organization, prioritization, scheduling, and follow-through.
- Excellent communication and presentation skills, with the ability to translate complex technical and regulatory findings into clear business recommendations for audiences ranging from IT professionals to executives.
- Strong analytical and reporting capabilities, including the ability to track engagement metrics, compliance status, deliverable progress, and security program performance.
- Ability to collaborate effectively with distributed teams, coordinators, security engineers, SOC personnel, and client stakeholders.
- Commitment to ongoing professional development and staying current with cybersecurity threats, technologies, CMMC developments, regulatory changes, industry training, and relevant certifications.
- U.S. person status, defined as U.S. citizen or lawful permanent resident, is required due to access to Controlled Unclassified Information under applicable DFARS requirements.
- Ability to work reliably across U.S. business time zones and travel occasionally to client sites when assessment support is required.
- Additional certifications such as CISM, CRISC, CISA, GIAC credentials, CompTIA Security+/SecurityX, or Microsoft SC-series certifications are considered a plus.
Benefits
- Annual compensation ranging from $95,000 to $120,000 , depending on experience and location.
- Total compensation includes a base salary or hourly component plus a monthly delivery-based compensation bonus.
- Monthly bonus opportunities based on delivered hours, engagement milestones, assessment readiness, client retention, and overall contract health.
- Bonus targets and measurement criteria established at hire and reviewed annually.
- Medical insurance plan.
- Dental and vision coverage.
- Life insurance and supplemental life insurance options.
- Disability coverage.
- Paid time off starting at 15 days per year.
- Paid maternity and paternity leave.
- Paid U.S. holidays.
- Retirement plan.
- Salary advancement/loan program.
- Health and wellness program.
- Company-paid training and professional certification opportunities.
- U.S.-based remote work with flexibility across business time zones.
- Opportunity to work on complex, high-regulatory-risk cybersecurity engagements and influence the development of scalable compliance practices.
How Jobgether works:
We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team.
We appreciate your interest and wish you the best!
Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.
#LI-CL1
We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.
- ...shaping the future direction of BCBSA's cybersecurity program. -Assess internal and third-... ...Authorization Management Program (FedRAMP) compliance strategy by building and scaling an AI-... ...for providing status updates to Senior/Executive management. Responsible for escalating...SeniorFull timeShift work
$160k - $190k
...Job Description Job Description Senior Federal Cybersecurity & Compliance Consultant (Expert in CMMC, NIST, FedRAMP, and Cyber Security Regulatory Compliance) Remote / Full-Time Are you a brilliant, self-managed cybersecurity expert with deep federal compliance...SeniorFull timeRemote workFlexible hours$95k - $120k
...Job Description Job Description Job Summary The Security Advisor (Senior Cybersecurity Compliance Consultant) delivers active security practice management engagements, serving as the assigned security officer (vCISO) for a portfolio of client organizations. The...SeniorHourly payPermanent employmentContract workFixed term contractRemote work$90k - $140k
...strategic accounts. Develop cybersecurity strategy, governance frameworks... ...appetite.• Regulatory and compliance readiness: Conduct readiness... ...-year relationships with senior customer stakeholders. Serve... ...service offerings. Mentor junior consultants and pre-sales engineers on...Senior- ...expertise in engineering, procurement, consulting and construction, together we are... ...to use.The OpportunityThe Industrial Cybersecurity Senior Consultant manages or contributes to... ...assessments, customer relationship management, compliance and standards reviews, security...SeniorPart timeWork experience placementWork at officeVisa sponsorshipFlexible hours
- ...Job Description Job Description Apogee is seeking an experienced Senior Cybersecurity & Compliance Advisor to provide cybersecurity governance, risk management, and compliance guidance supporting a federal simulation and analytics solution. This role will focus on...SeniorFor contractors
$130k - $152.5k
...AssociatesCharles River Associates is a leading global consulting firm that provides economic, financial,... ....Position OverviewCRA is seeking a Cybersecurity Consultant (Assessments / Due Diligence... ...level summaries. You will also support senior team members in proposal development...SeniorWork at officeWork from home3 days per week$128k
...generation, global management consulting group. Founded in 1999, we... ...transforms outcomes. Sia’s Cybersecurity team is the powerhouse of our... ...following offers: Strategy, Risk, Compliance, Operations, Data Protection... ...and relay for the Manager/Senior Manager regarding the follow...SeniorFull timeWork at officeWorldwideFlexible hours$113k - $188k
...Clearance Required:Active SecretGuidehouse is seeking a Senior Consultant to join its Cyber Team - Cybersecurity Risk Assessment Consultant. The Senior Consultant... ...Consultant should remain flexible while ensuring compliance and adapt the guidance and technical assistance to...SeniorFull timeWork at officeFlexible hours$85.91k - $162.89k
...joining one of the fastest growing consulting and accounting firms in the country?... ...joining Baker Tilly (BT) as an IT Audit, Cybersecurity & Risk Senior Consultant (SOC focus)! Our Risk... ...of risk, governance, internal audit, compliance, IT, and cybersecurity best...SeniorFull timeWork experience placementLocal areaWorldwide$100k - $140k
...Protection. DOT Security exists because businesses deserve a cybersecurity partner they can trust. As cyber threats became more... ...help define what comes next. Job Overview A Cybersecurity Compliance Consultant, internally titled as a Virtual Compliance Manager, performs...Contract workWork experience placement- ...Job Title : CMMC Level 1 Cybersecurity Compliance Consultant Location : Remote Job Type : Contract About Prestige Development Group (PDG) Prestige Development Group (PDG) specializes in providing innovative human capital management solutions...Contract workLocal areaRemote work
- ...and team-oriented individuals to work with federal government organizations in support of national cybersecurity programs. The Cybersecurity Partner Coordination Consultant helps ensure effective collaboration between industry and government partners on cyber operational...Senior
- A consulting firm is looking for a Senior Consultant for their Cybersecurity Practice in Los Angeles. This role involves providing strategic cybersecurity advisory services, conducting audits and assessments, and mentoring junior consultants. Candidates should have a Bachelor...SeniorFlexible hours
- ...Location: 8435 Stemmons Bldg. Primary Purpose The Senior Compliance Investigations Consultant is responsible for effectively carrying out investigations of internal and external reports of compliance-related allegations. MINIMUM SPECIFICATIONS Education...SeniorWork at office
$128k
A global management consulting group in New York is seeking a Cybersecurity Consultant. You will manage Cybersecurity projects, develop client relationships, and lead a team of experts. Candidates should have a degree in Cybersecurity and at least 3 years of experience...SeniorFlexible hours- Palo Alto Networks is seeking a Solutions Consultant to evolve the traditional Sales Engineering role. You will provide technical leadership, guide customers through security transformations, and define solutions that secure critical business imperatives across on-prem...SeniorRemote job
- Perform SOX IT and cybersecurity compliance testing. Identify and assess Truist’s Corporate cybersecurity legal, regulatory and industry compliance. Assist in managing cybersecurity risk and compliance functions which include establishing cyber policies and standards designed...Full timePart timeWork at officeShift workDay shift
- A leading cybersecurity company is seeking a Solutions Consultant to guide clients through their security transformation journeys. This role involves providing technical leadership, building customer relationships, and delivering impactful presentations. The ideal candidate...SeniorRemote job
- ServiceNow is seeking a Solution Consultant to support our Federal business in the Washington, DC region. You will demonstrate the Armis... ...-facing roles, a CS/MIS background, and a strong networking/cybersecurity foundation. Travel up to 40% and a competitive compensation...Senior
$77.6k - $176k
Phase2 Technology is seeking a Cybersecurity Compliance Analyst to design and manage policies ensuring software and database security. The role requires extensive experience in compliance analysis and the ability to communicate cybersecurity posture effectively. Responsibilities...Senior- Trident Consulting is seeking a " Senior Cybersecurity Consultant " for one of our client in " Rosemead, CA " A global leader in business and technology... ...CIS, ISO 27001) and experience supporting audits and compliance initiatives Strong ability to influence without authority...SeniorFull timeContract workRemote workMonday to Friday
$72k - $141k
...matter and are part of something important, ensuring the abilities of all employees are used to their fullest potential. The Compliance Senior Consultant is a strategic individual contributor role designed to lead and support Corporate Compliance operations and programs....SeniorFull timeWork experience placementWork at office- CNM LLP, a boutique consulting firm in Los Angeles, seeks a Cyber Security Senior Consultant to work with Fortune 500 clients. You will conduct security assessments, manage projects, and guide teams in an exciting environment. Qualifications include a Bachelor's degree...Senior
- ...Withum is experiencing significant growth driven by market demand for assurance services. Our team is seeking a Contract Compliance Senior Consultant with experience performing royalty audits, franchise compliance audits, revenue participation audits, lease agreement...SeniorFull timeContract workWork at officeLocal area
$110.7k - $218.3k
Position Summary Senior Consultant - Regulatory & Compliance - Enterprise Operations & Risk Our Deloitte Regulatory, Risk & Forensic team helps client leaders translate multifaceted risk and an evolving regulatory environment into defensible actions that strengthen...SeniorLocal areaVisa sponsorship$84k - $118.11k
...Description:Are you interested in joining one of the fastest growing consulting and accounting firms in the country?Would you like the... ...consider joining Baker Tilly (BT) as a Consumer Regulatory Compliance Senior Consultant! Our Risk Advisory practice provides a full...SeniorFull timeWork experience placementLocal areaWorldwide- Opportunity OverviewOur Culture of Compliance defines how we uphold the highest professional... ...Compliance, the Culture of Compliance Consultant Team partners with CACLs, Regional Leaders... ...professional and ethical standards.As a Senior Culture of Compliance Consultant, you...SeniorTemporary workInterim roleWork at officeHome officeFlexible hours
- ...Job Description Job Description Cybersecurity Risk & Compliance Consultant POSITION OVERVIEW The Cyber Security Risk and Compliance Consultant is responsible for conducting Cybersecurity gap assessments and ongoing consulting with our clients daily in Huntsville...For contractorsWork at office
- Crowe is looking for a Cybersecurity Senior Consultant in Los Angeles, CA. In this role, you will navigate an evolving threat landscape by delivering... ...advising clients on security architectures, including compliance with frameworks like NIST. Candidates should have a...Senior
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Senior Cybersecurity Compliance Consultant. Be the first to apply!
- senior cybersecurity analyst United States
- cyber security consultant United States
- cybersecurity analyst remote United States
- cyber security specialist United States
- compliance analyst United States
- tax compliance analyst United States
- quality compliance specialist United States
- junior regulatory affairs specialist United States
- regulatory compliance specialist United States
- product compliance specialist United States



