hatch I.T. logo
hatch I.T.
Posted 41 days agoVerified live 1d ago

Information Security Consultant

Brief overview

Remote
3+ yrsMinimum
NIST 800-53GRC DeliverablesSecurity Risk AssessmentsAudit and ComplianceSecurity Awareness TrainingKnowBe4SEC530Virginia Public-Sector ComplianceClient CommunicationIndependent Research and Problem-Solving

About the company

hatch I.T. logo
hatch I.T.hatchit.io

We're a specialty recruiting partner, dedicated to empowering defense-tech, dual-use tech, and cutting-edge startups with expert talent advisory and strategic technical recruiting solutions.

Job description

Summary

Assura is a cybersecurity firm focused on practical information security leadership for state, local, and education organizations. The Virtual Information Security Officer will deliver analyst-level GRC consulting services under senior direction, supporting assessments, documentation, compliance activities, client communication, security awareness training, and remediation planning.

Responsibilities

  • Perform assigned GRC service and planning tasks under the direction of a Senior VISO or GRC Director
  • Support security assessments and identify risks, issues, and basic remediation activities under supervision
  • Maintain, update, and support development of core deliverables: policies, procedures, standards, BIA documentation, incident response and disaster recovery documentation, system security plans, vulnerability management plans, and third-party risk documentation
  • Facilitate client meetings, track follow-up items, and communicate clearly and professionally with clients and Assura colleagues
  • Interact directly with clients (once trained) without requiring constant senior intervention
  • Support audit and compliance activities — preparing compliant documentation, participating in audit defense as directed, and helping develop remediation plans under leadership direction
  • Customize and deliver client security awareness training within established parameters (e.g., KnowBe4)
  • Manage deadlines and quality expectations, including adherence to review steps such as Second Set of Eyes
  • Conduct independent research and analysis to close gaps or answer questions before escalating

Skills

  • Approximately 3–5 years of relevant experience in cybersecurity, GRC, risk, compliance, audit, or information security
  • Meaningful hands-on experience with at least one regulatory framework (e.g., NIST 800-53, HIPAA, PCI DSS), with working familiarity in others
  • Strong working knowledge of NIST 800-53, with specific familiarity across the AC, IA, CM, SI, SC, AU, SA, and AT control families
  • Demonstrated experience updating or helping develop GRC deliverables (policies, procedures, standards, BIA, IR/DR docs, SSPs, VM plans, TPRM documentation)
  • Ability to take direction from senior staff and reliably carry instructions through to completion
  • Strong writing, documentation, and client communication skills
  • Intellectual curiosity and the ability to research and problem-solve independently when gaps arise
  • Familiarity with SEC530 and Virginia public-sector compliance expectations
  • Foundational understanding of how functions like IT, HR, and Finance intersect with security planning and documentation
  • Prior audit support experience beyond evidence collection (planning, remediation, documentation ownership)
  • Comfort with client-facing meetings and stakeholder communication

Qualifications

Must Haves

  • Approximately 3–5 years of relevant experience in cybersecurity, GRC, risk, compliance, audit, or information security
  • Meaningful hands-on experience with at least one regulatory framework (e.g., NIST 800-53, HIPAA, PCI DSS), with working familiarity in others
  • Strong working knowledge of NIST 800-53, with specific familiarity across the AC, IA, CM, SI, SC, AU, SA, and AT control families
  • Demonstrated experience updating or helping develop GRC deliverables (policies, procedures, standards, BIA, IR/DR docs, SSPs, VM plans, TPRM documentation)
  • Ability to take direction from senior staff and reliably carry instructions through to completion
  • Strong writing, documentation, and client communication skills
  • Intellectual curiosity and the ability to research and problem-solve independently when gaps arise

Nice to Haves

  • Familiarity with SEC530 and Virginia public-sector compliance expectations
  • Foundational understanding of how functions like IT, HR, and Finance intersect with security planning and documentation
  • Prior audit support experience beyond evidence collection (planning, remediation, documentation ownership)
  • Comfort with client-facing meetings and stakeholder communication

Benefits

  • Full Time
  • Remote work arrangement
  • People are supported, trusted, and given room to grow

More jobs like this