Key Responsibilities
- Collaborate with clients, stakeholders, and technical leads to align on security compliance processes for system go-live.
- Work with project managers to monitor staffing allocation for compliance review and assessment processes.
- Provide guidance on baseline security requirements to solution architects during requirements gathering.
- Support security documentation reviews, including justifications, waivers, and extensions.
- Prepare and review technical slide decks and compliance templates for projects.
- Maintain centralized security guides, templates, and compliance documentation.
- Conduct security briefings and awareness sessions for project teams.
Core Skills
Security Compliance & Governance
- Knowledge of standards such as ISO 27001, NIST CSF, and CIS Controls.
- Familiarity with government frameworks (e.g., IM8).
- Experience in audits, assurance, and compliance reviews.
Technical Security Knowledge
- Understanding of security architecture, system hardening, and cloud security controls.
- Exposure to vulnerability management and secure SDLC practices.
- Ability to translate technical assessments into compliance actions.
Stakeholder Engagement
- Strong communication skills for working with project managers, architects, and clients.
- Experience in handling security waivers, risk acceptance, and compliance justifications.
- Skilled at delivering security briefings and workshops.
Documentation & Process Management
- Ability to develop compliance templates and reports.
- Experience preparing technical and executive-level documentation.
Experience
- 5-7 years in cybersecurity, with at least 3-5 years in compliance, governance, or assurance roles.
- Hands-on experience in managing compliance for IT or cloud transformation projects.
- Worked closely with cross-functional teams in regulated environments.
- Exposure to highly regulated industries such as finance, healthcare, government, or critical infrastructure.
Qualifications
- Degree in Computer Science, Cybersecurity, or related fields.
- Preferred certifications: CISSP, CISM, CISA, ISO 27001 Lead Auditor/Implementer, CCSP, CCSK, AWS/Azure/GCP Security, ITIL, PMP.
EA License: R1873481
Company EA License: 11C4879