Information Security Consultant
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for an Information Security Consultant based in the United States.
This is an analyst-level Governance, Risk, and Compliance (GRC) consulting role supporting day-to-day information security programs for a diverse client base.
You will work under the guidance of experienced security leaders while gaining hands-on exposure to assessments, compliance, risk management, and security documentation.
The role is highly delivery-focused, requiring strong organization, dependable execution, and careful attention to quality and deadlines.
You will contribute to policies, procedures, security plans, business impact analyses, incident response, disaster recovery, and third-party risk documentation.
As you gain experience, you will take on increasing client interaction and greater independence in research, analysis, and problem-solving.
The environment emphasizes practical cybersecurity, professional client service, continuous learning, and meaningful opportunities for growth.
This is an excellent opportunity for a cybersecurity professional looking to deepen their GRC expertise while building toward broader security leadership responsibilities.
Accountabilities:
- Execute assigned GRC service and security planning activities under the direction of senior security and GRC leadership.
- Support security assessments by identifying risks, issues, control gaps, and basic remediation opportunities under appropriate supervision.
- Maintain and contribute to core GRC deliverables, including policies, procedures, standards, business impact analyses, incident response and disaster recovery documentation, system security plans, vulnerability management plans, and third-party risk documentation.
- Facilitate client meetings, document discussions, track follow-up actions, and maintain clear and professional communication with clients and internal stakeholders.
- Progress toward independently interacting with clients following appropriate training and guidance, without requiring continuous senior-level intervention.
- Support audit and compliance activities by preparing documentation, participating in audit defense activities as directed, and helping develop remediation plans under leadership guidance.
- Customize and deliver client security awareness training within established guidelines and approved platforms.
- Manage assigned deadlines and quality expectations while consistently following established review and quality-control processes.
- Conduct independent research and analysis to resolve questions, close knowledge gaps, and develop informed recommendations before escalating issues.
- Demonstrate reliable follow-through on assigned instructions while maintaining a high standard of accuracy, documentation quality, and client service.
- Approximately 3–5 years of relevant experience in cybersecurity, GRC, information security, risk, compliance, or audit.
- Meaningful hands-on experience working with at least one recognized regulatory or security framework, such as NIST 800-53, HIPAA, or PCI DSS, with working familiarity with additional frameworks.
- Strong working knowledge of NIST 800-53, including familiarity with the AC, IA, CM, SI, SC, AU, SA, and AT control families.
- Demonstrated experience maintaining, updating, or helping develop GRC deliverables such as policies, procedures, standards, business impact analyses, incident response and disaster recovery documentation, system security plans, vulnerability management plans, and third-party risk documentation.
- Ability to take direction from senior professionals and consistently carry assigned tasks through to completion.
- Strong writing, documentation, analytical, and organizational skills, with an ability to produce clear and accurate security deliverables.
- Excellent verbal communication and client-facing skills, with the professionalism and confidence to participate in stakeholder meetings.
- Strong intellectual curiosity and a willingness to research unfamiliar topics and independently investigate problems before seeking escalation.
- Familiarity with SEC530 and Virginia public-sector compliance requirements is preferred.
- Foundational understanding of how IT, HR, Finance, and other business functions intersect with information security planning and documentation is preferred.
- Previous audit support experience beyond evidence collection, including planning, remediation, and documentation ownership, is preferred.
- Comfort communicating with clients and diverse stakeholders in professional meetings is preferred.
- Opportunity to develop hands-on expertise across cybersecurity GRC, risk, compliance, audit, and security program management.
- Progressive exposure to client-facing responsibilities and increasingly independent security consulting work.
- Practical experience working with recognized cybersecurity and regulatory frameworks.
- Opportunities to expand knowledge across security policies, risk assessments, business continuity, incident response, vulnerability management, third-party risk, and compliance.
- Support and mentorship from experienced security and GRC professionals.
- A collaborative environment focused on professional development, practical cybersecurity, and long-term career growth.
- The opportunity to work with organizations seeking practical, real-world security guidance rather than purely theoretical or compliance-driven solutions.
Requirements
Benefits
Skills
As published by lever
Resume/CV, Full name, Email, Phone, Current location, Current company