Consultant - SOC2, PCI Assessment
At Coalfire as a Consultant you will work as part of a team assessing the security and compliance of client firms against regulatory and industry requirements and standards, and against security best practice frameworks. You will have a strong understanding of framework requirements, perform audit/assessments, and develop reports for clients. You will also get to work closely with Project Managers, Directors and other Delivery team members to effectively manage project timelines and deliverables
This is a great opportunity as a Security Consultant to make an impact and enhance clients security posture and business processes affecting information security and data privacy through technical evaluation of governance programs. You will regularly interact with peers and clients as both an auditor and assessor, depending on the engagement. As a Consultant you will evaluate the design and operating effectiveness of controls supporting management systems and will help to identify improvement opportunities. You will test technical controls, policies and procedures, laws, regulations, and industry best practices.
In this role, as a Consultant you facilitate Security Control Assessments and other advanced-level monitoring activities, often within cloud-based environments. To succeed, you will need a strong understanding of technical and non-technical security related system controls and an understanding of the various testing methods utilized to ascertain the effectiveness of those controls. Our consultants works in a team atmosphere with an experienced Technical Project Lead, and is assigned technical sections and expected to create client-ready deliverables.
A Security Consultant on the SOC/PCI team helps to enhance clients’ security posture and ensure that business and customer data is properly protected. This role will evaluate the design and effectiveness of technology controls throughout the business cycle and will help identify performance improvement opportunities.
This position is a remote position that must be located in the United Kingdom (England, Scotland, Wales, and/or Northern Ireland). Coalfire has an office in Manchester, UK so there is opportunity to work in the office in a hybrid capacity if preferred.At Coalfire as a Consultant you will work as part of a team assessing the security and compliance of client firms against regulatory and industry requirements and standards, and against security best practice frameworks. You will have a strong understanding of framework requirements, perform audit/assessments, and develop reports for clients. You will also get to work closely with Project Managers, Directors and other Delivery team members to effectively manage project timelines and deliverables
This is a great opportunity as a Security Consultant to make an impact and enhance clients security posture and business processes affecting information security and data privacy through technical evaluation of governance programs. You will regularly interact with peers and clients as both an auditor and assessor, depending on the engagement. As a Consultant you will evaluate the design and operating effectiveness of controls supporting management systems and will help to identify improvement opportunities. You will test technical controls, policies and procedures, laws, regulations, and industry best practices.
In this role, as a Consultant you facilitate Security Control Assessments and other advanced-level monitoring activities, often within cloud-based environments. To succeed, you will need a strong understanding of technical and non-technical security related system controls and an understanding of the various testing methods utilized to ascertain the effectiveness of those controls. Our consultants works in a team atmosphere with an experienced Technical Project Lead, and is assigned technical sections and expected to create client-ready deliverables.
A Security Consultant on the SOC/PCI team helps to enhance clients’ security posture and ensure that business and customer data is properly protected. This role will evaluate the design and effectiveness of technology controls throughout the business cycle and will help identify performance improvement opportunities.
This position is a remote position that must be located in the United Kingdom (England, Scotland, Wales, and/or Northern Ireland). Coalfire has an office in Manchester, UK so there is opportunity to work in the office in a hybrid capacity if preferred.What You'll Do
What You'll Bring
- 2+ years of experience as an IT Consultant, IT auditor, Business Analyst, or similar role
- Bachelor's degree (four-year college or university) or equivalent combination of education and work experience. Degree preferably in related field (CIS, MIS, or IT)
- General knowledge of IT audit procedures and cyber security best practices
- Experience and demonstrated ability to independently research a technical topic and develop logical testing approaches
- Experience and demonstrated ability to lead testing sessions for assigned controls.
- Demonstrated experience reading and interpreting security framework criteria
- Strong personal initiative to appropriately manage time and meet deadlines
- Strong Consulting skills; ability to advise and challenge the status quo while building strong relationships
- Ability to build high-trust relationship and credibility quickly
- High attention to detail
- Ability to facilitate meetings to small or large groups
- Diplomatic and broad minded
- Strong written and verbal communication skills including quick response time the ability to explain technical matters to a non-technical audience
- Has a sense of urgency and ability to multi-task
- Public speaking and executive presence that solicits attention
- Inquisitive and curious nature with the ability to effectively probe for deeper information
- Strong technical researcher
Bonus Points
- Cloud experience (AWS, GCP, Azure)
- Assessment and compliance experience related to the financial services industry, fintech, insurance, banking, and/or B2B enterprise experience
- CCSK, CCP, Security + certifications
- AQSA certification
- One of the following Information Security certifications required or ability to obtain: CISSP, CISM or ISO 27001 Lead Implementer.
- One of the following Audit certifications required or ability to obtain: CISA, GSNA, CIA, IRCA ISMS Auditor or higher, or ISO 27001 Lead Auditor.