Senior Security Compliance Consultant

🕒 February 25

Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of ASCERA

ASCERA

11 - 50 employees

Founded 2023

🔒 Cybersecurity

📋 Compliance

☁️ SaaS

Cybersecurity • Compliance • SaaS

ASCERA is a cybersecurity SaaS company that automates evidence collection, continuous monitoring, and status reporting to help organizations—especially those in the U. S. Defense Industrial Base—achieve and maintain compliance with CMMC, DFARS, and NIST 800-171. Its platform automates generation and collection of compliance evidence, provides built-in guidance and continuous controls monitoring, integrates with systems to detect misconfigurations and out-of-compliance devices, and includes deployment, integration, and support services to accelerate assessment readiness.

📋 Description

• __Own The Role:__112Cyber (formerly SP6 Cyber Risk & Compliance) is looking for a Compliance SME wanting to take the next step in their career! In this role, you will assist organizations in solidifying and strengthening their security posture while also conducting assessments for those pursuing certification. • Joining our Compliance team, you will see your impact across the company as you take ownership over customer projects and advising our platform team on the different compliance rules. • From there, you will be supporting Defense Industrial Base (DiB) companies to ensure they are CMMC and/or NIST 800-171 compliant. You will accomplish this through providing pre-audit readiness and GAP assessments, plans of action and milestones (POA&M) support, Compliance as a Service (CaaS), and official C3PAO assessments. • __**How You’ll Drive Success:**____Advisory Services__ • - Leading cybersecurity gap assessments aligned with NIST SP 800-171 and Cybersecurity Maturity Model Certification (CMMC). • - Supporting the day-to-day activities of engagements for external clients, as a contributing member of 112Cyber’s customer-facing Cyber Risk & Compliance practice. • - Assist external customers in their FedRAMP, DFARS 7012, CMMC, and NIST 800-171 compliance initiatives. • - Applying cyber compliance / risk management knowledge, control principles and technical knowledge across cyber risk and compliance engagements. • - Consulting with end clients to gather requirements and understand our clients' key business and security challenges. Working with team members to advise on practical and cost-effective solutions to help mitigate our clients’ cybersecurity risks and challenges. • - In depth knowledge of relevant security regulatory compliance requirements and translating those into business processes and security controls to enhance and support client’s compliance and audit capabilities. • - Articulating and defending IT controls testing approach and performing test of design and operating effectiveness. • - Develop and deliver training to internal teams and customers. • - Establishing and maintaining effective working relationships with colleagues, existing clients, and prospective client organizations. • - Supporting the ASCERA product team and advising them on NIST continuous monitoring software. • __C3PAO Assessments__ • - Conducting formal assessments of organizations’ cybersecurity practices using the CMMC assessment process (CAP). • - Collaborate with client organizations to plan assessments, develop assessment schedules, and ensure readiness • - Assess the effectiveness of security practices and ensure they align with the CMMC practices and processes. • - Interview key personnel within the organization to understand how cybersecurity practices are implemented and maintained. • - Evaluate sufficiency and adequacy of evidence to verify implementation. • - Maintain an objective and unbiased stance during the assessment process, ensuring that conclusions are based on facts and evidence. • - Ensure that all documentation is properly prepared for submission to eMASS if the organization is seeking certification.

🎯 Requirements

• __**To Be Successful:**__ • - CMMC Certified Assessor (CCA). • - Security+, CySA+, CISA, CISM, SSCP, CISSP or other related certification • - 5 minimum years of experience testing and documenting IT security controls including experience managing and facilitating external IT audits. • - 5 minimum years of experience leading external or internal audits, e.g., CMMC, FedRAMP, ISO 27001, PCI. • - 5 minimum years of experience with cybersecurity. • - Self-driven, with a strong desire to succeed. • - Ability to engage with customers/executives and foster positive relationships. • - Exceptional communicator and ability to relay complex technical concepts to non-technical audience.

🏖️ Benefits

• __**Why 112Cyber?**__ • - The chance to be part of a winning team and a premier C3PAO. • - Competitive salary. • - Quarterly Bonus plan. • - Comprehensive medical, dental, and vision plans. • - 401(k) with company match. • - 30 days annual paid time off. • - Significant Training and Development and Certification attainment. • - Opportunity for long term career advancement. • - Your contributions are felt and recognized at our growing company. • __**About 112Cyber:**__112Cyber is an industry recognized C3PAO (Certified Third-Party Assessor Organization) dedicated to assisting organizations in effectively identifying and managing cyber risks while ensuring compliance with industry standards, federal laws, and regulations.

Apply Now

Similar Jobs

🕒 February 25

SeatGeek

501 - 1000

🛍️ eCommerce

⚽ Sports

Lead Software Engineer managing security initiatives for SeatGeek's platform and products. Involved in incident response, threat hunting, and security engineering in a collaborative environment.

Cloud

Python

Go

🕒 February 25

Stone Hendricks Group

11 - 50

🎯 Recruiter

🤝 B2B

Sales Account Executive driving growth by establishing client relationships in the data-centric security domain. Focusing on F2000 technology and semiconductor firms.

SFDC

🕒 February 25

Keeper Security, Inc.

501 - 1000

🔒 Cybersecurity

☁️ SaaS

🏢 Enterprise

Senior Machine Learning Engineer developing AI-driven threat detection models at Keeper Security. Tackling cybersecurity challenges with Python in a remote role focused on model training and evaluation.

AWS

Azure

Cloud

Cyber Security

Docker

Google Cloud Platform

Python

🕒 February 25

PTC

5001 - 10000

🏢 Enterprise

Senior Director of Product Security overseeing the security strategy at PTC. Engaging with engineering and customers, leading a high-performing security team.

🕒 February 23

Aprio

1001 - 5000

💸 Finance

🤝 B2B

☁️ SaaS

Azure Security Engineer at Aprio, a top CPA firm, solving complex security and compliance challenges. Navigate cybersecurity landscapes using Microsoft tools for diverse clients.

Azure

Cyber Security