Security Compliance Consultant (SOC 2, PCI DSS, HIPAA, NYDFS 500), Contract
This job is no longer listed
The source has removed this listing — applying via the original link is no longer possible.
Must-have:Security
Nice-to-have:HealthTechRemote
Invadel is a New York City penetration testing firm. Every engagement is fixed-scope and fixed-price, agreed in writing, with public prices at invadel.com/pricing and a free retest. This is a contract role, remote within the United States, paid per engagement; work is typically one to three days per client engagement, attached to a penetration test, plus occasional readiness reviews.
What you will do:
- produce the framework mapping section of each report and the attestation letter clients hand to auditors and customers;
- review client scope against the requirement that drives the test (for example PCI DSS 11.4 segmentation testing or NYDFS 500.5) and flag gaps before testing starts;
- answer auditor and customer security questionnaire follow-ups with the client;
- run readiness reviews for clients preparing for a first SOC 2 Type II or PCI DSS assessment;
- keep the compliance mapping templates current.
What we need:
- four or more years in security compliance, audit or GRC with direct experience of SOC 2 and at least one of PCI DSS, HIPAA, ISO 27001, NYDFS 500 or CMMC;
- enough technical grounding to read a penetration test finding and explain what it means for a control;
- clear writing for auditors, executives and engineers;
- based in the United States with authorization to work here;
- two professional references.
Nice to have:
- time on the assessor side (QSA, SOC 2 audit team, C3PAO) or inside a compliance automation platform;
- experience with New York financial services or healthcare clients.
Full description, pay range and application:
Originally posted on Himalayas