Cybersecurity Compliance ConsultantDOT Security's mission is to improve the security posture of client organizations by providing detection, response, risk management, and compliance services as identified and required. DOT Security will implement processes, technology, and subject matter expert personnel to monitor and respond to client needs in the cybersecurity and compliance space. Working with client organizations, DOT Security will continuously measure and improve internal processes and technology, which will translate to improved services provided to the client. DOT Security is seeking team members who are passionate about Cybersecurity, detailed-oriented, desire for continuous learning, and enjoys working in a collaborative environment. We provide our employees with a career progression path, that challenges our team to grow as cybersecurity professionals with strong cybersecurity skills.
As a member of Dot Security, you will get the opportunity to work from a brand-new, state of the art Security Operations Center (SOC) facility.What you will be doing: A Cybersecurity Compliance Consultant, internally titled as a Virtual Compliance Manager, performs point-in-time Gap Analysis & advises clients on an ongoing basis to improve or maintain their adherence to regulatory compliance requirements. This involves continuously monitoring state & federal regulations & working with clients to proactively modify their compliance programs to accommodate new regulatory requirements as they take effect. Compliance program modification entails Compliance Consultant coordination with client stakeholders to design & analyze the impact of changes & modify compliance plans in a timely manner. The Cybersecurity Compliance Consultant is not a remote position. This role is required to be on-site at the DOT Security- Security Operations Center.ResponsibilitiesAct as point of contact for client resources in relation to reported compliance violationsAdvise clients on appropriate use of compliance reporting tools and related technologyAid external auditors & authorities with client compliance reviews & investigationsAssist with client business associate contract maintenance & respond if problems ariseDevelop a vision & roadmap for client compliance controls, processes, & risksFacilitate allocation of appropriate resources for effective compliance policy implementationPerform periodic gap analysis & ongoing compliance monitoring for client organizationsRemain up-to-date on compliance laws, rules, & regulations & inform clients about changesSupport the development & implementation of written compliance policies & proceduresTrack client compliance documents & support the filing of compliance reports as neededAct with a sense of urgency, identify alternatives, & set realistic timeframes for resolutionComplete work based on priority, follow through as promised, & set expectationsContribute to & perform both new & pre-existing plans, instructions, & proceduresDemonstrate active listening & critical thinking skills & comprehend received informationInterpret & understand complex & evolving concepts in a dynamic, fast-paced environmentMaintain awareness of technology advancements & their cybersecurity implicationsUnderstand & present technical concepts to non-technical audiencesProvide exceptional customer service & remain calm under pressureResolve problems in early stages & ticket labor, notes, & details in a ticketing systemQualifications & ExperienceClient relationship management (listening, setting expectations, delivering results)Feedback interpretation for process, product, & service improvementPolicy, process, & procedure writing & review conceptsProject Management principles & techniquesRisk assessment methodologies & management processes (scoring, mitigation)Supply chain risk management standards, processes, & practicesAbility to work independently & as part of a teamAdaptability to situations in which data is incomplete or where no precedent existsCommunicate & collaborate in a clear, professional, & concise manner using technology, tools, & workspacesCritical thinking, customer service skills, & passion for cybersecurityDocumenting & communicating complex technical concepts, incidents, problems, & eventsKnowledge of IT assets (apps/data/devices/networks/users) & related security concepts (monitoring/hardening)Preparation & delivery of reports, plans, & briefings using presentation technologySystem administration and cybersecurity theories, concepts, & methodsSystem resiliency, redundancy, continuity, & disaster recovery conceptsThe ability to work ethically & with integrityOther Desire AttributesPublic Trust background check (Limited Requirement)Relevant work experience in managed services industryCyber community participation (conferences/groups/tool authoring/CTFs)Understanding of CIS Controls, CMMC, NIST 800-171, NIST 800-53, FedRAMPRelevant college degreesCertifications including GRCP, CRISC, Cyber-AB CCP, Cyber-AB CCA, IAPP CIPP/US, IAPP CIPMCompensationThe typical base salary for this role is $100,000-$140,000.
Actual compensation packages are based on several factors that are unique to each candidate, including but not limited to skillset, experience and training, licensures and/or certifications, and other organizational needs. DOT Security may offer applicable incentive compensation plans depending on role and/or department. Full compensation details can be discussed with an Impact Talent Acquisition team member at the start of the interview process.BenefitsUp to 20 days of PTOUp to 7 Paid Sick Days12+ paid holidaysPaid Parental LeaveComprehensive Health, Disability Life, Dental and Vision Plans401(K) & retirement plansTenure incentives at 5- (Tiffany & Co. Gift Card), 10- (Rolex watch), and 20- ($20,000 check) year mark(s)Continued education reimbursementOn-going training & development opportunitiesWork Authorization & Immigration SponsorshipCandidates must be authorized to work in the United States at the time of application. Immigration sponsorship may be considered in limited circumstances based on business need, cost, workforce planning, and applicable government requirements.
DOT Security does not guarantee sponsorship for any visa category and may decline certain petitions based on associated costs or regulatory requirements. Certain positions within Impact may involve access to information, technology, software, or technical data that is subject to U.S. export control laws and regulations, including the International Traffic in Arms Regulations (ITAR) and the Export Administration Regulations (EAR). Where required by applicable law based on the nature of the role, individuals in such positions must qualify as a "U.S. Person," as defined by law, or otherwise be eligible to obtain any required government authorizations.