Information Technology Governance Consultant
Denville, New Jersey, United States · Full Time
Be the first to apply
- Experience
- 3–7 yrs
- Salary
- —
- Openings
- 1
- Posted
- منذ 4 ساعات
- Work mode
- In office
- Resume
- Required to apply
Where you'll work
Job description
About Proactive Risk
Proactive Risk is a consulting firm specializing in cybersecurity, technology risk management, and compliance services. We assist commercial, government, and regulated organizations in enhancing their cybersecurity postures through governance, risk management, compliance assessments, penetration testing, virtual CISO support, managed security consulting, and third-party risk programs.
Position Overview
We are looking for a Cybersecurity & Compliance Consultant to join our team, requiring regular client-facing work. This mid-level role involves conducting assessments, gathering evidence, identifying security gaps, and advising on improvements. The position requires office presence in Denville, NJ five days per week, with additional client site visits within Northern New Jersey.
Key Responsibilities
- Lead client meetings and workshops both on-site and remotely to gather relevant data.
- Evaluate client documentation, security policies, and technical evidence to identify risks and compliance shortcomings.
- Provide remediation strategies and develop implementation plans.
- Present findings effectively to business and technical leaders, serving as a trusted advisor.
- Conduct assessments across multiple cybersecurity frameworks including CIS Controls v8.1, NIST SP 800-171, NIST SP 800-53, CMMC, NY Shield Act, PCI DSS, and other applicable regulations.
- Assist in creating risk registers and remediation plans while supporting governance and policy development.
- Perform detailed evaluations of administrative, technical, and physical security controls including firewalls, VPNs, MFA, identity and access management, Microsoft 365 security, endpoint security, and vulnerability management programs.
- Review network and cloud infrastructure configurations, analyze security findings, and assist with mitigation planning.
- Collect and validate audit documentation for internal and external security audits, tracking compliance progress using tools such as Apptega, Virtual CISO, and HaloPSA.
- Manage multiple client projects, ensuring timely delivery and effective communication among stakeholders.
Required Qualifications
- 3 to 7 years of experience in cybersecurity, IT, risk management, compliance, or consulting.
- Proven ability in conducting audits, assessments, and security reviews.
- Strong knowledge of cybersecurity frameworks and best practices.
- Experience with Microsoft 365, Entra ID (Azure AD), Intune, and cloud environments.
- Understanding of networking fundamentals such as TCP/IP, DNS, DHCP, VPNs, firewalls, routing, and switching.
- Excellent documentation and communication skills with aptitude for professional interaction across executive and technical stakeholders.
- Capability to handle multiple projects and priorities efficiently.
- Possession of a valid driver’s license and access to reliable transportation.
Preferred Skills
- Familiarity with CIS Controls, NIST 800-171, CMMC, NIST 800-53, PCI DSS, and risk management programs.
- Knowledge of Windows Server, Linux, macOS, Microsoft Defender, and security monitoring platforms.
- Basic scripting or automation skills in PowerShell, Python, or Bash.
- Experience working in consulting, MSP, MSSP, or advisory roles.
- Professional certifications such as Security+, CISSP, CISM, CRISC, CISA, or Microsoft Security Certifications.
Work Environment
- This role is based at our Denville, NJ headquarters with mandatory attendance five days per week.
- Candidates must live within roughly 20 miles of Denville.
- Frequent travel is required to client sites across Morris, Essex, Passaic, Union and neighboring counties.
- The position combines onsite and remote consulting engagements.
What Success Looks Like
- Independently lead client assessments and perform interviews and evidence collection.
- Deliver thorough and high-quality risk and compliance documentation.
- Support the establishment and growth of client cybersecurity programs.
- Develop into a trusted advisor for multiple clients and contribute to the growth of our CyberAdvisor consulting team.