> Markdown version of [/jobs/ext/1840854-cybersecurity-compliance-specialist](https://www.wearedevelopers.com/jobs/ext/1840854-cybersecurity-compliance-specialist). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cybersecurity & Compliance Specialist - **Company:** FISCH SOLUTIONS, INC. - **Location:** New Windsor, NY, United States - **Experience:** Experienced - **Salary:** $49,920.0 - $54,080.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, CompTIA Security+, Cyber Security, Network Security, PCI Data Security Standards, Security Information and Event Management, Gsuite, CIS Benchmarks, Software Version Control - **Published:** July 31, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=a59e8e60d41c2c26 ## About the Role * 3+ years in cybersecurity, IT compliance, audit, or a closely related role * Working knowledge of at least two of: HIPAA, PCI DSS, CMMC or NIST 800-171, SOC 2, CIS Controls, NYS Breach/Shield Act, Cybersecurity Insurance Compliance Requirements * Real incident response experience, ideally in an MSP, MSSP, or multi client environment * Strong technical writing skills, since documentation is a core deliverable here, not an afterthought * Comfortable with Microsoft 365/ GSuite security, EDR and SIEM tooling, backup and recovery concepts, and network security fundamentals * Able to hold a client accountable politely and hold your ground when the answer is no * Clean background check, since some client work requires it Nice to Have * CISSP, CISA, CISM, Security+, CCP or CCA, HCISPP, or equivalent * Prior MSP experience * Experience with defense contractors, healthcare practices, or municipal government * Familiarity with IR and Compliance tooling like PO&EMs. ## Description We are building out a dedicated compliance function. This person owns our compliance run books, both internal and client facing, and makes sure they are documented, implemented, and actually followed. You will also own our incident response plans and run them live when an incident hits, for us and for our clients. This is a hands-on role for someone who can work independently, write clearly, and hold both our team and our clients accountable to the standards we sell. What You'll Own Compliance Run Books and Documentation * Build, maintain, and version control compliance run books for Fisch and for client engagements * Map client environments to the applicable framework, including HIPAA, PCI DSS, CMMC, NIST 800-171, NY SHIELD, and cyber insurance attestation requirements * Verify that documented controls are actually implemented in the environment, not just written down * Maintain evidence libraries, policy sets, and system security plans so clients are audit ready at any time * Track remediation items to closure with named owners and due dates Incident Response * Own and maintain Fisch's IR plan and client specific IR plans * Act as incident commander during live incidents, coordinating our SOC, engineering team, client leadership, insurance carriers, and outside counsel where needed * Drive containment, eradication, and recovery decisions alongside the technical team * Produce post incident reports, root cause findings, and corrective action plans * Run tabletop exercises with our team and with clients at least annually Client Advisory * Conduct risk assessments, gap analyses, and readiness reviews * Translate findings into plain language for owners, boards, and non technical stakeholders * Support clients through cyber insurance applications and renewals * Assist with client audits, questionnaires, and vendor security reviews * Partner with our vCIO cadence so compliance status shows up in quarterly business reviews Internal Program * Maintain Fisch's own security policies, awareness training program, and control documentation * Support internal SOC 2 readiness work as the program matures * Keep leadership informed on regulatory changes that affect our clients or our business ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [A practical guide to writing secure Dockerfiles](https://www.wearedevelopers.com/videos/109-a-practical-guide-to-writing-secure-dockerfiles) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [OPA for the cloud natives](https://www.wearedevelopers.com/videos/713-opa-for-the-cloud-natives) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)