Senior Security Consultant, Continuity and Compliance

JobgetherVerified source: this listing comes from the employer's official hiring system or a verified company · United States · Remote · $130,000 - $155,000/year
Listed via Lever
Posted Aug 27, 2026 · Apply by Nov 26
Recently checked

Last checked active on Aug 28, 2026.

Position Overview

Location: United States United States flag
Compensation: $130,000 - $155,000/year
Position: Senior
Type: Job
Employment: Full time
Practice Area: Compliance
Remote: Yes
Deadline: Nov 26, 2026

Job Description

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Senior Security Consultant, Continuity and Compliance based in United States.

This is a high-impact consulting role focused on helping organizations strengthen cybersecurity, compliance, and risk-management programs.
You will lead complex client engagements and act as a trusted advisor across regulatory, security, and operational challenges.
The role offers the opportunity to apply deep expertise across frameworks such as PCI DSS, NIST, HIPAA, and CMMC.
You’ll work with executive leaders, technical teams, and business stakeholders to identify gaps and develop practical remediation strategies.
Operating with significant autonomy, you’ll manage engagements from initiation through final delivery while maintaining high standards of quality.
You’ll also mentor peers, contribute technical direction, and help organizations mature their security and compliance capabilities.
This is an ideal opportunity for an experienced security professional who enjoys solving nuanced problems and delivering measurable client value.

Accountabilities

    • Lead multiple security, compliance, and advisory engagements simultaneously, managing scope, timelines, budgets, deliverables, documentation, and quality standards from kickoff through completion.
    • Conduct PCI DSS compliance assessments, including SAQs, ROCs, and other applicable validation activities in accordance with relevant requirements and assessment standards.
    • Serve as a subject matter expert on PCI DSS, NIST, HIPAA, CMMC, and other applicable security and regulatory frameworks, translating requirements into practical guidance.
    • Evaluate client security programs, technical controls, regulatory obligations, and operational environments to identify risks, vulnerabilities, compliance gaps, and improvement opportunities.
    • Develop actionable remediation strategies that balance regulatory requirements, security best practices, business priorities, and organizational risk.
    • Lead client interviews, workshops, advisory sessions, and executive discussions, communicating findings and recommendations effectively to both technical and non-technical stakeholders.
    • Review and advise on security policies, procedures, controls, and standard practices to support compliance, governance, and risk-management objectives.
    • Provide strategic guidance in complex or ambiguous situations, exercising sound professional judgment and acting as a trusted advisor to client organizations.
    • Provide technical direction, quality assurance, mentorship, and guidance to other consultants and peers to promote consistency and adherence to established methodologies.
    • Support initiatives that establish, develop, or mature clients’ information security and compliance programs.
    • Requirements

      • Bachelor’s degree in a relevant field combined with 5+ years of information security compliance, auditing, or assessment experience, or 7+ years of demonstrated experience in a related information security discipline.
      • Active PCI DSS Qualified Security Assessor (QSA) certification is required, along with a professional credential such as CISSP, CISA, CMMC, or an equivalent certification.
      • Strong practical knowledge of PCI DSS, NIST, HIPAA, CMMC, and related security and regulatory frameworks, with the ability to interpret requirements and apply them within diverse client environments.
      • Solid technical foundation in networking, databases, operating systems, IT infrastructure, and security controls, with the ability to evaluate technical environments from a risk and compliance perspective.
      • Demonstrated experience with critical thinking, root-cause analysis, problem-solving, and professional advisory work, including the ability to develop practical and actionable recommendations.
      • Strong consulting and engagement-management skills, with experience balancing multiple priorities and delivering high-quality work across concurrent client engagements.
      • Excellent written and verbal communication skills, with the ability to build credibility and communicate effectively with technical teams, business stakeholders, and executive leadership.
      • Strong relationship-building skills and the ability to work independently while collaborating effectively with consultants and internal subject matter experts.
      • Demonstrated leadership, mentoring, and quality-review capabilities.
      • Experience developing or maturing information security programs is preferred.
      • Must be comfortable working remotely while consistently supporting established U.S. business hours, with preference for candidates able to work Central or Eastern Time hours.
      • Benefits

        • Base salary: $130,000–$155,000 annually, with actual compensation determined by experience, technical expertise, certifications, location, and internal equity.
        • Additional compensation: Potential eligibility for bonus or other incentive compensation.
        • Healthcare coverage: Medical, dental, and vision insurance.
        • Financial benefits: 401(k) retirement plan.
        • Flexible spending and health support: FSA and HSA options.
        • Protection benefits: Disability, life, and AD&D insurance.
        • Paid time off: PTO, sick leave, holidays, and parental leave.
        • Remote flexibility: Full-time, U.S.-based remote position open to candidates in all 50 states.
        • Collaborative culture: An inclusive environment focused on teamwork, professional growth, mentorship, and meaningful client impact.
        • Career development: Opportunities to apply your expertise, take on new challenges, mentor others, and contribute to the evolution of security and compliance practices.
        • Office access: Candidates located near McLean, Virginia may have access to a local office.
How Jobgether works: We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team. We appreciate your interest and wish you the best!  Why Apply Through Jobgether?    Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.     #LI-CL1

Compensation

$130,000 - $155,000/year

Practice Area

Position

Senior

Industry

Legal

Applicant Location Requirements

Applicants must be located in: United States

Application Deadline

November 26, 2026

Employment Type

Full time

Work Arrangement

Remote/Telecommute Position

Application to Jobgether

Sign in to apply

See the complete description, requirements, and every detail of this role, then apply. Everything here is included with your account.

Apply to this job and future roles across 91 countries
Human CV / resume reviews from real experts
Application tracker, saved roles, and company watchlist
Return to this job the moment you are signed in
Report this job
Thank you. Our team will review this report.

Tell us if this listing is inaccurate, closed, fake, duplicated, or unsafe. You do not need an account to report it.