Jobs and Careers
GU

Senior Security Consultant- Data Privacy- Remote (Anywhere in the U.S.)

GuidePoint Security LLC
United StatesRemotefull_timeVerifiedPosted 25 Feb 2023

About the role

GuidePoint Security provides trusted cybersecurity expertise, solutions and services that help organizations make better decisions and minimize risk. By taking a three-tiered, holistic approach for evaluating security posture and ecosystems, GuidePoint enables some of the nation’s top organizations, such as Fortune 500 companies and U.S. government agencies, to identify threats, optimize resources and integrate best-fit solutions that mitigate risk.

Role and Responsibilities: 

  • Deliver successful consulting engagements across multiple Governance, Risk, and Compliance offerings while maintaining high customer satisfaction.
  • Conduct gap assessments against various US-based and global data privacy frameworks, including CCPA/CPRA, GDPR, Quebec Privacy Act, and others.
  • Develop regulatory updates to keep customers up to date on the current data security and privacy landscape.
  • Research and identify applicable legal and administrative statutes/standards and other details related to customers’ Data Privacy Programs.
  • Develop policies, processes, and other documentation (e.g., checklists, guidelines, FAQs) to comply with relevant privacy regulations and frameworks.
  • Contribute to the maturation and socialization of the GuidePoint data privacy consulting practice.
  • Perform maturity assessments against NIST CSF, ISO 27001, and other best practice security frameworks.
  • Provide security and privacy-based advisory services to GuidePoint customers to help mature their security and privacy programs.
  • Establish strong relationships and trust with customers to understand customers’ business environments and requirements.
  • Work with other GuidePoint Security practices as part of a cohesive cross-functional team.

Required Experience and Position Requirements:

  • Minimum of 5 years of combined GRC experience across private/public sector, consulting and/or relevant education.
  • Minimum of 3 years of direct experience performing GRC-related consulting services for clients of various verticals, including financial and insurance, retail, healthcare, service providers (SaaS, PaaS, etc.), manufacturing, critical infrastructure/energy, etc.
  • Minimum of 3 years of data privacy experience across the private/public sector or consulting.
  • Strong understanding and working knowledge of privacy frameworks, including CCPA/CPRA, GDPR, and other equivalent data privacy standard.
  • Strong understanding and working knowledge of security frameworks, including the NIST CSF, ISO 27001, and others.
  • Strong demonstrated experience in developing information security policies, standards, plans, procedures, and other documentation to support customer-adopted frameworks and industry standards.
  • Strong understanding of all the functions within a security program, the ability to assess the maturity of a security program, and how to provide strategic recommendations and direction to senior leadership.
  • Strong written and oral communication skills, which includes articulating thoughts and distilling complex problems into digestible information to be consumed by anyone from technical resources to the highest level of management; proven experience communicating clearly to technical levels up through C-Level and Board level.
  • At least one standard industry certification is required, such as CDPSE (ISACA), CIPM (IAPP), CIPP (IAPP), CIPT (IAPP), HCISPP ((ISC)2), PECB-CDPO
  • Strong written communication skills to aid in the creation of customer deliverables.
  • Remain current on industry developments and incorporate them into service delivery.
  • Strong ability to work independently and multi-task on multiple projects simultaneously.
  • Personal drive and passion for growing themselves and the GnR Practice.

Preferred Experience and Position Requirements:

  • Juris Doctorate degree
  • Demonstrated experience with assessing, developing, and implementing data governance and protection programs, including conducting data discovery of data flows and inventories and evaluating the security and privacy controls that protect an organization’s sensitive data.
  • Experience leading the implementation of best practice frameworks for client security programs, such as ISO 27001, NIST CSF, HiTrust, and others.
  • Demonstrated experience in performing risk assessments using industry-recognized frameworks, such as ISO 27005, NIST 800-30, etc.
  • Publish content and/or perform conference speaking to demonstrate thought leadership.
  • Standard industry certifications are preferred, such as CISSP, CISA, CISM, CRISC, CBCP, GIAC, etc.
  • Publish content and/or perform conference speaking to demonstrate thought leadership
  • Conference speaking experience. 

<

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

GuidePoint Security LLC

View company profile →