Cybersecurity & Compliance Specialist

FISCH SOLUTIONS, INC.
New Windsor, NY, United States
12 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Compensation
$49,920.0 - $54,080.0
Working hours
Regular working hours
Job source

Tech stack

Microsoft Windows CompTIA Security+ Cyber Security Network Security PCI Data Security Standards Security Information and Event Management Gsuite CIS Benchmarks Software Version Control

Job description

We are building out a dedicated compliance function. This person owns our compliance run books, both internal and client facing, and makes sure they are documented, implemented, and actually followed. You will also own our incident response plans and run them live when an incident hits, for us and for our clients.

This is a hands-on role for someone who can work independently, write clearly, and hold both our team and our clients accountable to the standards we sell.

What You’ll Own

Compliance Run Books and Documentation

  • Build, maintain, and version control compliance run books for Fisch and for client engagements
  • Map client environments to the applicable framework, including HIPAA, PCI DSS, CMMC, NIST 800-171, NY SHIELD, and cyber insurance attestation requirements
  • Verify that documented controls are actually implemented in the environment, not just written down
  • Maintain evidence libraries, policy sets, and system security plans so clients are audit ready at any time
  • Track remediation items to closure with named owners and due dates

Incident Response

  • Own and maintain Fisch’s IR plan and client specific IR plans
  • Act as incident commander during live incidents, coordinating our SOC, engineering team, client leadership, insurance carriers, and outside counsel where needed
  • Drive containment, eradication, and recovery decisions alongside the technical team
  • Produce post incident reports, root cause findings, and corrective action plans
  • Run tabletop exercises with our team and with clients at least annually

Client Advisory

  • Conduct risk assessments, gap analyses, and readiness reviews
  • Translate findings into plain language for owners, boards, and non technical stakeholders
  • Support clients through cyber insurance applications and renewals
  • Assist with client audits, questionnaires, and vendor security reviews
  • Partner with our vCIO cadence so compliance status shows up in quarterly business reviews

Internal Program

  • Maintain Fisch’s own security policies, awareness training program, and control documentation
  • Support internal SOC 2 readiness work as the program matures
  • Keep leadership informed on regulatory changes that affect our clients or our business

Requirements

  • 3+ years in cybersecurity, IT compliance, audit, or a closely related role
  • Working knowledge of at least two of: HIPAA, PCI DSS, CMMC or NIST 800-171, SOC 2, CIS Controls, NYS Breach/Shield Act, Cybersecurity Insurance Compliance Requirements
  • Real incident response experience, ideally in an MSP, MSSP, or multi client environment
  • Strong technical writing skills, since documentation is a core deliverable here, not an afterthought
  • Comfortable with Microsoft 365/ GSuite security, EDR and SIEM tooling, backup and recovery concepts, and network security fundamentals
  • Able to hold a client accountable politely and hold your ground when the answer is no
  • Clean background check, since some client work requires it

Nice to Have

  • CISSP, CISA, CISM, Security+, CCP or CCA, HCISPP, or equivalent
  • Prior MSP experience
  • Experience with defense contractors, healthcare practices, or municipal government
  • Familiarity with IR and Compliance tooling like PO&EMs.

About the company

Fisch Solutions is one of the largest and fastest growing managed IT and cybersecurity providers in the Hudson Valley. We support SMB, municipal, healthcare, and defense-adjacent clients with managed IT, security operations, AI enablement, and compliance advisory. We are a 2026 Channel Futures MSP 501 company (Top 501 MSPs List Globally), a CRN Magazine Top 500 MSP (National ranking of Top MSPs), a three time Inc. 5000 honoree, and we hold a 99.2 percent client satisfaction rating with 80+ five star Google reviews.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

2:15 min

Auditing container configurations against CIS benchmark security standards

Madhu Akula · LIVE

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · WWC 2022

5:03 min

Navigating new cybersecurity compliance frameworks and laws

Kurt Eder · LIVE

3:39 min

Validating data queries and infrastructure security configurations

Philipp Krenn · WWC 2023

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

Videos

See all

Related articles

See all