HamburgerMenu
hirist

Security Consultant - NIST/Cloud Security

Good Co
8 - 12 Years
Multiple Locations

Posted on: 18/09/2026

Job Description

Role & Responsibilities :

- Lead and deliver information and cybersecurity consulting engagements for clients across various industries.

- Assess clients' security posture, identify vulnerabilities, and recommend appropriate security controls and improvements.

- Conduct security risk assessments, security audits, gap assessments, and compliance reviews against standards such as ISO 27001, NIST, SOC 2, PCI DSS, or relevant regulatory requirements.

- Develop and review information security policies, standards, procedures, frameworks, and governance processes.

- Advise clients on cybersecurity strategy, risk management, security architecture, and control implementation.

- Perform security maturity assessments and develop actionable roadmaps for improving cybersecurity capabilities.

- Support third-party/vendor risk assessments, security due diligence, and supplier security reviews.

- Work with technical and business stakeholders to translate cybersecurity risks into business-impact-oriented recommendations.

- Prepare detailed assessment reports, risk registers, executive presentations, and remediation plans.

- Monitor and evaluate emerging cybersecurity threats, technologies, and regulatory requirements and advise clients accordingly.

- Support incident response, business continuity, disaster recovery, and cyber resilience initiatives where required.

- Lead client workshops, stakeholder meetings, presentations, and security awareness sessions.

- Mentor junior consultants and contribute to project planning, delivery, quality assurance, and knowledge development.

- Contribute to business development activities, including RFP/RFI responses, solution proposals, statements of work, and client presentations.

Preferred Candidate Profile :

- 7 - 12 years of experience in cybersecurity, information security, risk consulting, security governance, or a related field.

- Bachelor's degree in Computer Science, Information Technology, Cybersecurity, Engineering, or a related discipline. A master's degree is an advantage.

- Strong understanding of cybersecurity frameworks, risk management, governance, and security controls.

- Hands-on experience with one or more of ISO 27001, NIST CSF, CIS Controls, SOC 2, PCI DSS, COBIT, or similar frameworks.

- Experience in conducting security assessments, audits, risk assessments, gap assessments, and compliance engagements.

- Strong knowledge of areas such as cloud security, IAM, network security, application security, vulnerability management, data security, and incident response.

- Experience working directly with enterprise clients and senior stakeholders.

- Ability to independently manage consulting assignments from scoping and assessment through reporting and remediation.

- Strong analytical, problem-solving, documentation, and presentation skills.

- Excellent written and verbal communication skills, with the ability to explain complex cybersecurity concepts to both technical and non-technical audiences.

- Experience managing or mentoring junior team members is preferred.

- Relevant certifications such as CISSP, CISM, CRISC, ISO 27001 Lead Auditor/Implementer, CEH, CCSP, or cloud-security certifications will be an advantage.

- Willingness to travel to client locations when required.

info-icon

Did you find something suspicious?

Similar jobs that you might be interested in

Loading chat...