Information Security Compliance Consultant
Location: 100% Remote. Preference will be given to local candidates who can come to the office as needed for client and departmental meetings, trainings, and other onsite activities.
Interview Process: 1-2 Rounds of Virtual Interviews. In person availability for interviews preferred.
Duration: 12 Months
Employment Type: Contract
Experience Required: 12+ Years
Project Scope:
Seeking an experienced Information Security Compliance Consultant to support statewide information security program initiatives. The consultant will assist agencies with tactical implementation of information security requirements, development and tracking of security implementation plans, compliance assessments, policy and procedure documentation, and governance activities.
The consultant will work closely with business leaders, technical teams, and third-party stakeholders to evaluate security controls, assess compliance readiness, and ensure alignment with established security frameworks and state standards. This role requires strong expertise in information security governance, risk, compliance (GRC), auditing, and regulatory frameworks.
聽
Key Responsibilities:
路聽聽聽聽聽聽聽 Support agencies with information security program implementation and compliance initiatives.
路聽聽聽聽聽聽聽 Conduct interviews with business owners, technical teams, administrators, and third-party stakeholders to gather security and compliance requirements.
路聽聽聽聽聽聽聽 Develop, document, and maintain security policies, procedures, and governance artifacts.
路聽聽聽聽聽聽聽 Track and monitor Information Security implementation plans and remediation activities.
路聽聽聽聽聽聽聽 Perform compliance assessments against established security frameworks and control standards.
路聽聽聽聽聽聽聽 Review agency documentation and provide recommendations to strengthen security posture and compliance readiness.
路聽聽聽聽聽聽聽 Analyze existing business processes and identify opportunities for improvement and risk reduction.
路聽聽聽聽聽聽聽 Assist in developing corrective action plans (CAP) and Plans of Action & Milestones (POA&M).
路聽聽聽聽聽聽聽 Support multiple concurrent security and compliance initiatives while maintaining project timelines.
路聽聽聽聽聽聽聽 Prepare reports, findings, and compliance status updates for leadership and stakeholders.
路聽聽聽聽聽聽聽 Ensure alignment with state security standards, regulatory requirements, and industry best practices.
聽
Required Skills & Experience:
路聽聽聽聽聽聽聽 10+ years of Information Security and Compliance experience.
路聽聽聽聽聽聽聽 2+ years of experience conducting security audits or serving as an Information System Security Officer (ISSO).
路聽聽聽聽聽聽聽 Strong working knowledge of NIST 800-53 security controls and compliance requirements.
路聽聽聽聽聽聽聽 Experience developing and managing POA&M and Corrective Action Plans (CAP).
路聽聽聽聽聽聽聽 3+ years of experience working with Governance, Risk, and Compliance (GRC) platforms such as Archer or similar tools.
路聽聽聽聽聽聽聽 Strong documentation, communication, and stakeholder management skills.
路聽聽聽聽聽聽聽 Experience assessing security controls and compliance programs.
聽
Preferred Skills:
路聽聽聽聽聽聽聽 Experience developing Information Security Plans (ISPs) and System Security Plan (SSP) documentation.
路聽聽聽聽聽聽聽 Experience managing multiple concurrent information security initiatives.
路聽聽聽聽聽聽聽 Knowledge of IRS 1075, HIPAA, CJIS, MARS-E, and PCI-DSS compliance frameworks.
路聽聽聽聽聽聽聽 Government or public sector experience.
路聽聽聽聽聽聽聽 Experience with process analysis, business process re-engineering, and compliance program development.
路聽聽聽聽聽聽聽 Strong project scheduling and resource planning capabilities.
聽
Education
Bachelor's Degree
聽
Preferred Certifications:
路聽聽聽聽聽聽聽 CISA
路聽聽聽聽聽聽聽 GSLC
Learn more about this Employer on their Career Site
