
Information Security Consultant
Hatch IT
🌏 Worldwide
Remote
Manager or above
7 months ago
- Incident Response
- Disaster Recovery
- Vulnerability Management
- NIST
- HIPAA
- PCI DSS
7 months ago
Responsibilities:
- Perform assigned GRC service and planning tasks under the direction of a Senior VISO or GRC Director
- Support security assessments and identify risks, issues, and basic remediation activities under supervision
- Maintain, update, and support development of core deliverables: policies, procedures, standards, BIA documentation, incident response and disaster recovery documentation, system security plans, vulnerability management plans, and third-party risk documentation
- Facilitate client meetings, track follow-up items, and communicate clearly and professionally with clients and Assura colleagues
- Interact directly with clients (once trained) without requiring constant senior intervention
- Support audit and compliance activities — preparing compliant documentation, participating in audit defense as directed, and helping develop remediation plans under leadership direction
- Customize and deliver client security awareness training within established parameters (e.g., KnowBe4)
- Manage deadlines and quality expectations, including adherence to review steps such as Second Set of Eyes
- Conduct independent research and analysis to close gaps or answer questions before escalating
Qualifications:
- Approximately 3–5 years of relevant experience in cybersecurity, GRC, risk, compliance, audit, or information security
- Meaningful hands-on experience with at least one regulatory framework (e.g., NIST 800-53, HIPAA, PCI DSS), with working familiarity in others
- Strong working knowledge of NIST 800-53, with specific familiarity across the AC, IA, CM, SI, SC, AU, SA, and AT control families
- Demonstrated experience updating or helping develop GRC deliverables (policies, procedures, standards, BIA, IR/DR docs, SSPs, VM plans, TPRM documentation)
- Ability to take direction from senior staff and reliably carry instructions through to completion
- Strong writing, documentation, and client communication skills
- Intellectual curiosity and the ability to research and problem-solve independently when gaps arise
Preferred Skills:
- Familiarity with SEC530 and Virginia public-sector compliance expectations
- Foundational understanding of how functions like IT, HR, and Finance intersect with security planning and documentation
- Prior audit support experience beyond evidence collection (planning, remediation, documentation ownership)
- Comfort with client-facing meetings and stakeholder communication
Information Security Consultant · Hatch IT