Senior Consultant, Human Threats

🔥 14 hours ago

🇺🇸 United States – Remote

💵 $146k - $180k / year

⏰ Full Time

🟠 Senior

💼 Consultant

🦅 H1B Visa Sponsor

infoinfo

👻 Ghost score 0%

infoinfo
Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Coalfire

Coalfire

1001 - 5000 employees

Founded 2001

💼 Consulting

🏥 Healthcare

📦 Logistics

Consulting • Healthcare • Logistics

Coalfire is a cybersecurity services provider that helps businesses improve their security resilience and streamline regulatory compliance. The company offers expert-led services, including threat-focused cybersecurity programs, compliance automation, risk management, and security advisory services across various industries such as financial services, healthcare, retail, and technology. Coalfire is known for its hacker and defender expertise, and its platforms are designed to fortify clients' cyber resilience, reduce attack surfaces, and accelerate the achievement of compliance objectives like FedRAMP and HITRUST.

📋 Description

• Conduct human threat engagements, including social engineering, phishing, vishing, authorized physical security assessments, and human risk evaluations • Plan, scope, and execute physical security assessments across facilities, offices, campuses, and client locations under approved rules of engagement • Evaluate perimeter protections, entry points, locks, badges, visitor management, reception procedures, secure areas, and employee access practices • Perform onsite testing and walkthroughs to identify unauthorized access opportunities, control bypasses, tailgating, weak access governance, and other exposures • Develop assessment scenarios, pretexts, and test plans combining physical and social engineering techniques • Coordinate onsite logistics, client communications, safety considerations, evidence collection, and testing activities within authorized scope • Document observations and evidence through notes, timestamps, photographs, interviews, and other assessment records • Analyze results, assign risk-based findings, and recommend improvements to facility security, access management, detection, response, and resilience • Prepare, review, and approve Human Threat reports • Deliver client briefings and debriefs communicating security gaps, social engineering results, business impact, and remediation actions • Manage priorities and tasks to meet delivery utilization targets and timely deliverables • Advise clients and build collaborative relationships with clients and stakeholders • Maintain industry certifications and knowledge of emerging physical security, social engineering, and human threat trends • Identify up-sell and cross-sell opportunities and escalate them to sales • Collaborate with project managers, quality management, sales, and delivery team members • Mentor junior consultants in physical assessment techniques, social engineering, client communications, reporting, and engagement execution • Develop and refine Human Threat methodologies, tooling, playbooks, and service offerings • Contribute to thought leadership through research, blogs, whitepapers, webinars, and conference presentations • Support Human Threat practice development through research, service innovation, and external industry content • Represent Coalfire at industry events, client briefings, and conferences • Contribute to other offensive security engagements as needed • Perform other responsibilities supporting client delivery, practice development, and team success

🎯 Requirements

• 5–8 years of client-facing consulting experience • 3–5 years of experience in social engineering, red team, insider risk, or physical security • Expertise in social engineering principles and techniques • Experience with phishing, vishing, smishing, and other communication-based attack methods • Pretext development and adversary emulation against human targets • Human risk assessments and behavior-based security evaluations • Report writing and client presentation delivery • Knowledge of current threat actor tactics, techniques, and procedures involving human targets • Knowledge of physical security concepts and badge/access control weaknesses • Knowledge of email security controls, identity-based attacks, and user-targeted attack paths • Knowledge of security awareness, culture, and behavior change principles • Ability to travel up to 75% • Strong writing skills, personal accountability, and ability to complete work to established standards without direct supervision • Experience planning and conducting authorized physical security assessments, facility walkthroughs, access control reviews, and onsite testing • Working knowledge of physical security principles and controls, including perimeter security, entry points, locks, badges, visitor management, reception procedures, secure areas, and employee access practices • Ability to develop assessment plans, scenarios, pretexts, rules of engagement, and safety procedures • Strong situational awareness, sound judgment, discretion, and professionalism • Ability to identify, document, risk-rate, and communicate physical and human-centered security vulnerabilities with practical remediation recommendations • Ability to communicate complex security concepts through written content, client presentations, executive briefings, and public speaking • Excellent communication, collaboration, and presentation skills • Strong time management and ability to manage multiple priorities, engagements, deadlines, and onsite requirements • Ability to protect sensitive client information and maintain accurate assessment evidence and engagement records • Willingness and ability to travel to client sites and participate in onsite assessments as required • ASIS Certified Protection Professional certification or comparable physical security credential is a bonus • Knowledge of physical red team tactics and techniques is a bonus • Executive protection or executive-targeted social engineering experience is a bonus • Behavioral science, psychology, or influence-based training is a bonus • Threat intelligence related to social engineering campaigns and threat actor tradecraft is a bonus • Insider risk program development is a bonus • Training content development and workshop facilitation is a bonus • Hardware, badge, or access-control related social engineering experience is a bonus • Published research, blogs, whitepapers, or conference presentations related to social engineering, human threat, or offensive security is a bonus

🏖️ Benefits

• Flexible work model allowing work from home or an office • Employee resource groups • In-person and virtual events • Paid parental leave • Flexible time off • Certification and training reimbursement • Digital mental health and wellbeing support membership • Comprehensive insurance options • Annual incentive, commission, and/or recognition program eligibility

Apply Now

Similar Jobs

🔥 14 hours ago

MVB

51 - 200

📣 Marketing

💼 Consulting

📱 Media

Fintech integrations consultant designing complex payment, data, and core banking integrations for MVB Financial. Translating non-standard requirements into documented, supportable solutions.

🔥 15 hours ago

Zurich Insurance

10,000+ employees

💼 Consulting

🏥 Healthcare

⚖️ Legal

Senior DFIR consultant leading forensic investigations and cyber incident response for Zurich’s insurance clients. Guiding executives, containment, recovery, and client engagements.

🔥 16 hours ago

ArcLight Consulting

51 - 200

💼 Consulting

☁️ SaaS

🏢 Enterprise

Senior Oracle SCM Cloud Consultant delivering Oracle supply-chain transformations for ArcLight Consulting. Configuring solutions, guiding clients, and supporting implementations across SCM modules.

🔥 18 hours ago

Mercer Advisors

501 - 1000

🛡️ Insurance

💼 Consulting

💳 Fintech

Senior Portfolio Consultant implementing complex portfolio transitions and investment strategies for Mercer Advisors’ high net worth clients. Supporting advisors, acquired firms, and prospective-client deliverables across the investment platform.

🔥 18 hours ago

Savista

1001 - 5000

💼 Consulting

📦 Logistics

🏥 Healthcare

Senior auditing consultant auditing hospital outpatient and physician coding for Savista, a healthcare revenue cycle improvement partner. Educating coders and identifying improvement opportunities.