NYDFS Cybersecurity Compliance Consultant - Remote / Telecommute

CYNET SYSTEMS INC.
Cary, NC, United States
14 days ago
Apply on www.careerjet.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Compensation
$106,080.0 - $116,480.0
Working hours
Regular working hours

Tech stack

Cyber Security Information Systems Data Auditing Data Security Information Technology Audit Information Technology

Job description

  • Perform NYDFS cybersecurity regulation assessments and Security Control Assessments.
  • Evaluate compliance with 23 NYCRR Part 500 requirements.
  • Conduct regulatory readiness and examination support reviews.
  • Assess control design and operating effectiveness.
  • Develop compliance scorecards and maturity assessments.
  • Track operational NYDFS evidence across in-scope applications with clear status and aging visibility.
  • Maintain validated and organized evidence artifacts in the agreed repository structure and naming convention.
  • Develop a prioritized list of out-of-compliance risk assessments and a remediation action plan.
  • Provide weekly status update packages covering progress, blockers, top risks, and next steps.
  • Document process improvement plans for the annual NYDFS attestation cycle including templates, cadence, and QA checks.
  • Work closely with external application vendor contacts to ensure application compliance and data security.
  • Execute risk-based IT audits.
  • Develop audit plans, audit programs, and test procedures.
  • Conduct walkthroughs and control validation.
  • Review evidence and perform sample testing.
  • Document audit observations and recommendations.
  • Prepare audit workpapers and audit reports.
  • Facilitate stakeholder workshops.
  • Present assessment findings to executive leadership.
  • Advise CISOs, CIOs, and compliance teams on NYDFS requirements.
  • Assist customers in developing target operating models.
  • Support cybersecurity program modernization initiatives.

Requirements

  • Bachelor’s degree in Cybersecurity, Information Security, Computer Science, Information Systems, or related field.
  • Strong verbal and written communication skills.
  • Ability to drive follow-ups with business stakeholders and vendor contacts.
  • Experience coordinating evidence/artifact collection for audits, attestations, or regulatory requirements.
  • Strong organization skills: tracking, repository hygiene, and maintaining audit-ready traceability.
  • Ability to validate evidence for completeness and applicability; escalate gaps and drive closure.
  • Project management fundamentals including status reporting and issue/risk escalation.
  • 5+ years of cybersecurity, risk, or compliance consulting experience.
  • Strong understanding of NYDFS Cybersecurity Regulation (23 NYCRR Part 500).
  • Experience conducting cybersecurity assessments and regulatory compliance reviews.
  • Knowledge of cybersecurity governance and risk management practices.
  • Excellent communication and client-facing skills., * NYDFS Compliance Assessments.
  • Security Control Assessments.
  • 23 NYCRR Part 500.
  • Regulatory Readiness.
  • IT Audit.
  • Risk Management.
  • Evidence Tracking.
  • Project Management.
  • Cybersecurity Governance.

Qualification And Education:

  • Bachelor’s degree in a related field.
  • 10+ years of professional experience.

About the company

Holman is a family-owned, global automotive services organization anchored by our deeply rooted core values and principles that have enabled us to continue Driving What’s Right thr…

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.careerjet.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:16 min

Advantages of reproducible configurations and instantaneous rollbacks

Álvaro Martín Lozano · LIVE

4:04 min

Embedding data security and applied ethics into developer education

Daniel Tao +3 · World Congress 2024

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

59 sec

Proving regulatory compliance to auditors and chief officers

Mike Bursell Mike Bursell · World Congress 2026 Europe

3:08 min

Conducting data audits and adversarial testing on models

Toju Duke · World Congress 2022

5:03 min

Navigating new cybersecurity compliance frameworks and laws

Kurt Eder · LIVE

Videos

See all

Related articles

See all