427,850open jobs
14,428companies
63,552added this week
Browse all
Salary
$95k – $120k per year
Location
Remote (United States)
Seniority
Senior · 8+ years exp
Employment
Full-Time
Overview
Company
Impact
Profile match
Jobgether is a Belgian recruitment platform built entirely around remote and flexible work, aggregating openings from thousands of employers that allow work from outside an office. Its matching engine ranks roles against a candidate's skills, seniority and stated preferences on location and flexibility, rather than leaving people to filter a keyword search, and it verifies how genuinely remote each posting is. The company also runs an AI screening layer that shortlists applicants for employers, and publishes research and guidance on distributed work practices alongside the job marketplace itself.

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Senior Cybersecurity Compliance Consultant based in the United States.

This senior-level role combines cybersecurity compliance consulting, risk management, and client-facing security advisory responsibilities across a diverse portfolio of organizations.

You will serve as a trusted security advisor and vCISO, helping clients strengthen their security programs and navigate complex regulatory requirements.

The position focuses heavily on CMMC and NIST SP 800-171 while also supporting a broad range of cybersecurity, privacy, and governance frameworks.

You will lead high-impact compliance engagements, develop remediation strategies, and guide clients through readiness and third-party assessment processes.

Working closely with security engineers, SOC teams, coordinators, and client stakeholders, you will translate technical requirements into practical business outcomes.

As a senior member of the practice, you will handle complex, high-regulatory-risk engagements and contribute to improving delivery standards, templates, and processes.

The role offers an opportunity to influence cybersecurity programs at both the strategic and operational levels while managing multiple client relationships in a fast-paced consulting environment.

Accountabilities

    • Serve as the assigned security officer and vCISO for a portfolio of client organizations, leading recurring meetings, addressing cybersecurity concerns, and providing regular updates, metrics, findings, and recommendations.
    • Build trusted client relationships by understanding business objectives, regulatory obligations, and security priorities, then developing tailored security strategies and roadmaps.
    • Lead CMMC Level 1 and Level 2 readiness engagements, including NIST SP 800-171 assessments, System Security Plan development, POA&M creation and management, evidence collection, SPRS submission support, and preparation for third-party assessments.
    • Advise clients on Controlled Unclassified Information scoping, DFARS and FAR requirements, and secure enclave architectures, including Microsoft GCC High environments.
    • Deliver compliance engagements across frameworks such as HIPAA/HITECH, SOC 2, PCI DSS v4.0, FTC Safeguards Rule, GLBA, ISO/IEC 27001 and 27002, NIST CSF 2.0, NIST SP 800-53, CIS Controls v8, NIST AI RMF, and ISO/IEC 42001.
    • Support engagements involving privacy, sector-specific, and state or federal requirements, including NY DFS, SEC cybersecurity disclosures, CJIS, StateRAMP/FedRAMP, CCPA/CPRA, GDPR, and ISO/IEC 27701.
    • Map overlapping control requirements across multiple frameworks to create unified control matrices and reduce duplicate evidence collection.
    • Conduct comprehensive risk assessments, identify threats and vulnerabilities, develop mitigation strategies, and recommend remediation actions to address security and compliance gaps.
    • Review security tooling outputs across platforms such as Microsoft Defender XDR, Sentinel, Entra ID Protection, Intune, Purview, and Conditional Access, coordinating remediation with client IT teams and internal engineering resources.
    • Support security officer activities, cyber insurance questionnaires, attestations, security huddles, and verification of security tool functionality across assigned accounts.
    • Participate in incident response activities when required, including escalation support, stakeholder communications, playbook development, SOC coordination, and post-incident reviews.
    • Maintain accurate and timely PSA time entries and contribute to engagement health, delivery tracking, client retention, and operational performance.
    • Identify opportunities to right-size or expand security programs, proactively communicating delivery concerns and account growth recommendations to practice leadership.
    • Serve as a senior escalation resource for complex framework interpretations and control determinations, while performing quality reviews of compliance deliverables before client or assessor submission.
    • Contribute to reusable templates, standardized delivery processes, knowledge resources, and continuous improvement initiatives while staying current on emerging threats and regulatory developments, including the phased CMMC rollout.
    • Requirements

      • Active CISSP certification in good standing is required at the time of hire; Associate-level, lapsed, or planned credentials do not meet this requirement.
      • Active Certified CMMC Professional (CCP) certification is required at the time of hire, with Certified CMMC Assessor (CCA) certification required within the first 12 months. Registered Practitioner status alone is not sufficient.
      • Eight or more years of progressive information security experience, including at least three years delivering compliance or vCISO engagements across a multi-client portfolio within a consulting, MSP, MSSP, or similar environment.
      • Demonstrated experience completing at least two CMMC Level 2 readiness engagements or equivalent NIST SP 800-171 assessment projects, including SSP development and POA&M management through third-party assessment.
      • Proven depth of experience in at least three distinct regulatory or cybersecurity frameworks, with the ability to defend control determinations and deliverables directly to auditors, assessors, or regulators.
      • Strong knowledge of CMMC, NIST SP 800-171/800-171A, NIST SP 800-53, NIST CSF 2.0, HIPAA/HITECH, SOC 2, PCI DSS, FTC Safeguards Rule, GLBA, ISO/IEC 27001/27002, and CIS Controls v8.
      • Familiarity with DFARS 252.204-7012, 7019, 7020, and 7021; FAR 52.204-21; CUI requirements under 32 CFR Part 2002; and the phased CMMC regulatory framework.
      • Awareness of U.S. state privacy laws, GDPR, NY DFS Part 500, SEC cybersecurity disclosure requirements, CJIS, and related sector-specific compliance regimes.
      • Strong risk management capabilities, including risk assessments, control mapping, remediation planning, POA&M management, and mitigation strategy development.
      • Experience with SIEM, EDR/XDR, IDS/IPS, firewalls, and cybersecurity monitoring technologies, with Microsoft security stack experience preferred.
      • Familiarity with GRC and compliance platforms such as IntelliGRC, Vanta, Secureframe, Drata, OneTrust, or FutureFeed, as well as evidence-collection workflows.
      • Ability to manage a high volume of concurrent client engagements, typically involving 20-30 client relationships, while maintaining strong organization, prioritization, scheduling, and follow-through.
      • Excellent communication and presentation skills, with the ability to translate complex technical and regulatory findings into clear business recommendations for audiences ranging from IT professionals to executives.
      • Strong analytical and reporting capabilities, including the ability to track engagement metrics, compliance status, deliverable progress, and security program performance.
      • Ability to collaborate effectively with distributed teams, coordinators, security engineers, SOC personnel, and client stakeholders.
      • Commitment to ongoing professional development and staying current with cybersecurity threats, technologies, CMMC developments, regulatory changes, industry training, and relevant certifications.
      • U.S. person status, defined as U.S. citizen or lawful permanent resident, is required due to access to Controlled Unclassified Information under applicable DFARS requirements.
      • Ability to work reliably across U.S. business time zones and travel occasionally to client sites when assessment support is required.
      • Additional certifications such as CISM, CRISC, CISA, GIAC credentials, CompTIA Security+/SecurityX, or Microsoft SC-series certifications are considered a plus.
      • Benefits

        • Annual compensation ranging from $95,000 to $120,000, depending on experience and location.
        • Total compensation includes a base salary or hourly component plus a monthly delivery-based compensation bonus.
        • Monthly bonus opportunities based on delivered hours, engagement milestones, assessment readiness, client retention, and overall contract health.
        • Bonus targets and measurement criteria established at hire and reviewed annually.
        • Medical insurance plan.
        • Dental and vision coverage.
        • Life insurance and supplemental life insurance options.
        • Disability coverage.
        • Paid time off starting at 15 days per year.
        • Paid maternity and paternity leave.
        • Paid U.S. holidays.
        • Retirement plan.
        • Salary advancement/loan program.
        • Health and wellness program.
        • Company-paid training and professional certification opportunities.
        • U.S.-based remote work with flexibility across business time zones.
        • Opportunity to work on complex, high-regulatory-risk cybersecurity engagements and influence the development of scalable compliance practices.
Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
427,850 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
In your city
In office • Full-Time • Pune
Java
Java
Spring Boot
Mobile
MVC
Dependency Injection
DevOps
Azure DevOps
Azure
Jenkins
AWS
Bamboo
API Gateway
Cybersecurity
Checkmarx
PCI DSS
Veracode
JFrog Xray
Apply
Product Engineer 2 hours ago
$23k – $54k per year (Estimated) • In office • Full-Time • Hefei
Cybersecurity
GDPR
Apply
$22k – $52k per year (Estimated) • In office • Full-Time • 5+ years exp • Master's Degree • Shanghai
Cybersecurity
GDPR
Apply
$45k – $83k per year (Estimated) • In office • Full-Time • Bachelor's Degree • Italy
Cybersecurity
GDPR
Apply
$30k – $87k per year (Estimated) • Remote/Hybrid • Full-Time • Bachelor's Degree • Budapest
DevOps
Azure
Cybersecurity
Microsoft Defender
Microsoft Defender for Cloud
Apply
$155k – $175k per year • Equity • Remote • Full-Time • 5+ years exp
AI/ML
LLM
LLM Guardrails
DevOps
Terraform
GCP
Azure
AWS
Platform Engineering
Apply
$43k – $102k per year (Estimated) • In office • Full-Time
Apply
$111k – $160k per year • Remote • Full-Time • 8+ years exp • Bachelor's Degree
Apply
$130k – $150k per year • Remote • Full-Time • 12+ years exp • Bachelor's Degree
Apply
$90k – $110k per year • Remote • Full-Time • 5+ years exp • Bachelor's Degree
Apply
See all jobs
This is one of many
427,850 more open roles from verified company boards, updated every day.