Senior Information Security Consultant

Heartland Technology Group Inc.
West Des Moines, IA, United States
3 days ago
Apply on www.jofdav.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
3 years minimum
Compensation
$55,307.0 - $69,222.0
Working hours
Regular working hours
Job source

Tech stack

Business Systems Cyber Security Information Technology

Job description

The Senior Information Security Consultant is responsible for providing cybersecurity and risk assessment services, subject matter expert support and solutions for Heartland Business Systems’ (HBS) customers. Deliverable areas could include, but are not limited to, Risk & Security Assessments, Remediation and Mitigation Recommendations, Strategic Roadmaps, Privacy and Security Policy, Procedure and Program development, Awareness and Education, and SME support. Senior Information Security Consultants at HBS provide strategic guidance to our clients and serve as the virtual Chief Information Security Officer for multiple organizations. This position is also responsible for collaborating with sales and marketing to ensure proposed deals include technical solutions that accurately address client needs.

Roles and Responsibilities/ Essential Functions:

  • Work as a member of the cybersecurity team providing consultative and proactive risk & security related support to HBS’ account base.
  • Assist clients with identifying gaps within existing risk & security programs and designing solutions to address those challenges.
  • Support clients with the identification, development, and implementation of technological and organizational controls to support risk and security programs.
  • Deliver leadership services in support of security remediation or mitigation.
  • Responsible for overall project management of many large projects and may work directly with other engineering resources in addition to the client.
  • Lead work in all phases of the engagement, including project planning, developing project plans, leading teams in completing tasks, client status reporting, and presenting project results to the client.
  • During the entire sales process, provide sales consultants and other HBS staff with assistance, review, validation, and optimization of privacy and security solutions.
  • Maintain a high level of knowledge related to privacy and security regulations (i.e. HIPAA, CMMC, PCI, GDPR, etc.) and standards best practices (NIST 800, ISO 2700X, CIS, etc.), OCR enforcement trends, HHS/OCR guidelines, and state-specific consumer-protection rules.
  • Prepare articles, whitepapers, blogs and speak at industry conferences to create awareness of our brand/services as it relates to privacy, security, and risk management.
  • Conduct a variety of risk assessments and provide guidance on improving processes, creating policies & procedures, and working with other HBS teams when necessary, on solution sets.
  • Present educational and information sessions with clients and other staff, as appropriate.
  • Develop information security programs and provide strategic guidance to clients while serving as vCISO.
  • Build and further develop client relationships.
  • Work in a team atmosphere as both a leader and contributor as assigned. At all times maintaining a professional and respectful demeanor.
  • Provide input on the improvement of customer facing documentation such as proposals, statements of work, status reports, reports, marketing materials, etc.
  • Provide input on the improvement of risk and cybersecurity products and services offered to clients.
  • Work to attain and maintain relevant cybersecurity and risk certifications.
  • Minimum of 1350 hours, or equivalent vCISO work, billed per fiscal year prorated based on start date. These charge hour requirements will be balanced against professional development and on the job training.

Requirements

How to qualify:

  • 5+ years of related experience
  • 5+ years implementing Cybersecurity Programs
  • 3+ years implementing Compliance and Governance Programs
  • CISSP or other current industry standard certifications in areas of security expertise
  • Significant experience as a security consultant, analyst, engineer, system administrator, IT lead, or similar role focused on information security responsibilities
  • Proven experience recommending and delivering cybersecurity, compliance, and risk management services
  • Ability to identify and evaluate risk to IT systems and associated business processes and communicate risks to management
  • Demonstrated experience with regulatory/compliance requirements (e.g., PCI, HIPAA/HITRUST, SOX, FISMA), information security frameworks and controls (e.g., NIST, ISO, CIS)
  • Demonstrated experience reviewing and recommending appropriate technical, administrative, and physical controls
  • Demonstrated experience selecting and implementing appropriate risk mitigation strategies to ensure IT systems remain within established risk tolerance levels
  • Ability to develop policies, standards, and baseline configurations
  • Strong attention to detail and ability to document findings and convey information
  • Ability to manage project deliverables and deadlines
  • Ability to provide superior customer service via phone and email
  • Excellent professional verbal and written communication skills
  • Strong listening and presentation skills
  • Ability to clearly communicate with co-workers, management, clients, and vendors
  • Maintain an professional appearance and vocabulary
  • Ability to multi-task, prioritize, and manage time effectively
  • Maintain an outcome focused mindset
  • Have strong prioritization skills
  • Always be a team player
  • Carry a professional attitude and respectful demeanor

Benefits & conditions

  • Competitive Compensation Package (May include but not limited to: Bonus, Incentive, Commission, Fair Wage, Retirement Plans, Benefits with HSA Compatible Plans)
  • Growth Opportunities
  • Community Involvement
  • Personal Development
  • Employee and Family Celebrations
  • Green Initiatives
  • Personal Time Off
  • Work Life Balance
  • Recognition and Awards

Day in and day out, you will be a part of a collaborative, innovative and award-winning team that will make you a better professional. Choose HBS today!

Heartland Business Systems is an Equal Opportunity Employer - Including Disabled and Veterans.

Equal employment opportunity, including veterans and individuals with disabilities.

About the company

Heartland Business Systems is one of THE LARGEST technology VARs or Value-Added Resellers in the Midwest. Anything that happens with computers - we do it! We PRIDE ourselves on our Core Values of:

Performance - HBS is driven to achieve exceptional results in all aspects of our business.

Respect - HBS Team Members demonstrate personal integrity and professionalism when dealing with all internal and external contacts.

Innovation - HBS is passionate to serve our internal and external customers with innovative solutions to enhance their success.

Development - HBS is committed to developing ourselves and each other in ways that support and improve the performance of ourselves and our business.

Excellence - HBS takes great pride in all we do and strive for excellence always.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.jofdav.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

4:30 min

Solving impossible enterprise problems instead of retrofitting applications

Dona Sarkar +1 · Coffee With Developers

42 sec

Energy forecasts and resource demands of information technology

Marjolein Pordon · LIVE

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

2:46 min

Missing equipment retrieval processes for departing employees

Jasmin Azemović Jasmin Azemović · World Congress 2026 Europe

5:42 min

Identifying ideal use cases and incremental technology adoption strategies

Marco Otte-Witte · World Congress 2023

Videos

See all

Related articles

See all