Cybersecurity Risk & Compliance Consultant
POSITION OVERVIEW The Cyber Security Risk and Compliance Consultant is responsible for conducting Cybersecurity gap assessments and ongoing consulting with our clients daily in Huntsville, Alabama. The Cybersecurity Risk and Compliance Consultant should be familiar with multiple security frameworks such as National Institute of Standards (NIST 800-171), Risk Management Framework (RMF), Cybersecurity Framework (CSF), CIS Critical Security Controls (CIS Controls), Defense Federal Acquisition Regulation Supplement (DFARS), and Cybersecurity Maturity Model Certification (CMMC). In this position, you will conduct gap assessments through interviews and asking questions to determine the state of an environment while capturing evidence and artifacts to support the assessment results and effectively measure our client’s security posture and compliance.
Primary Duties ● Conduct Cybersecurity gap assessments and provide resulting reports ● Conduct Cybersecurity consulting engagements to assist with and partner on clients’ POA&M remediation efforts ● Manage and execute project-level tasks and milestones ● Educate clients on information security and applicable control requirements ● Baseline existing risks, exposure, framework, and compliance levels ● Advise on risk mitigation and remediation plans
Required Qualifications ● SOC (Security Operations Center) knowledge and understanding of services within ● 2 or more (2+) years of experience in the information security field ● Experience leading information security engagements with a preference for DFARS, NIST, and CMMC assessments, as well as reporting ● Experience authoring cybersecurity policies, and procedures (to include Incident response, business continuity, disaster recovery, and more) ● One (1) or more of the following: Certified CMMC Professional (CCP), Certified CMMC Assessor (CCA), Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified Information Systems Auditor (CISA), Security+, or equivalent certification● Good time management, project management and problem-solving skills ● A desire to take on roles of increasing responsibility including defining services, managing teams, and coordinating resources ● Integrity: Ethical and respectful to clients and team ● Grit: Ability to self-motivate, self-manage, and meet deadlines when faced with competing priorities ● Customer-centric: Understand that partnership with our clients is a “win-win” scenario ● Selfless: Understand that when one team member succeeds, we all succeed ● Ability to review security architecture and advise on security requirements Supervisor Responsibilities
Knowledge, Skills, and Abilities 10 Characteristics of Every Professional at MAD Security
Physical Demands The physical demands described herein are representative of those which much be met by an employee to perform the Primary Duties of this Job Description successfully.
Travel Occasional travel may be required.
Other Duties Please note this Job Description is intended to describe the general nature and level of work to be performed by the employee(s) assigned to this Job Title. It is not designed to contain nor be interpreted as a comprehensive and/or all-inclusive list of duties, responsibilities, and qualifications. MAD Security, LLC reserves the right to amendand/or change responsibilities to meet business and organizational needs, as necessary, with or without notice. About MAD Security, LLC
MAD Security, LLC, founded in 2010, is a veteran-owned cybersecurity provider dedicated to safeguarding business and simplifying the cybersecurity challenge by delivering compliance through cost-effective, results-driven solutions. Headquartered in Huntsville, Alabama, and recognized as a Top 250 MSSP by MSSP Alert, MAD Security delivers world-class, industry-leading managed services and technology solutions regularly to defense industry-based providers including aviation and aerospace, government contractors, financial institutions, technology services providers, higher education institutions, and manufacturing to manage risk, meet compliance requirements, and reduce costs.