FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates expertise in cybersecurity assessments, risk management, and compliance with standards such as NIST CSF and ISO/IEC 27001. Proficient in drafting security policies, conducting vendor reviews, and managing documentation for audits while ensuring confidentiality and effective communication.
Highest-signal resume keywords
NIST CSFCIS ControlsCybersecurity Risk ManagementIncident Response PlanningSecurity Documentation
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
Cybersecurity AssessmentsControl AssessmentsRisk AssessmentsTechnical Configuration ReviewIdentity and Access ManagementEndpoint SecurityEmail SecurityCloud ServicesAudit Evidence CollectionData Inventory Management
Soft Skills
Strong Writing SkillsAttention to DetailProfessional CommunicationOrganizational SkillsIndependent Work
Tools & Technologies
Microsoft 365Entra IDIntuneAI ToolsEndpoint/Security Management Tools
Certifications & Qualifications
Security+CGRCCISAISO/IEC 27001
Industry Keywords
SOC 2 Type IIISO/IEC 27001 AuditSEC Regulation S-PFTC Safeguards RuleFINRA RequirementsHIPAACJISNIST SP 800-53CMMCFedRAMP
Tech Stack
Tools & technologiesAndroidCloudCyber SecurityiOS
About the role
Key responsibilities & impact- Support current-state and target-state cybersecurity assessments using NIST CSF, CIS Controls, and Xantrion standards
- Review IT configurations and evidence against templates and control requirements; document gaps and findings for vCIO review
- Draft and maintain incident response plans, business continuity plans, written information security programs, policies, and procedures
- Support business impact analyses, risk and gap assessments, cybersecurity risk registers, and risk-acceptance records
- Prepare control crosswalks, remediation roadmaps, executive risk summaries, and reporting scorecards under vCIO direction
- Conduct vendor cybersecurity risk reviews using questionnaires, audit reports, security documentation, and evidence
- Maintain software, vendor, and data inventories, data-flow documentation, and evidence indexes
- Maintain annual testing schedules and track documentation, review dates, and follow-up items
- Translate technical findings into clear risk descriptions, supporting evidence, and recommended actions
- Improve reusable templates and assessment procedures for consistent client delivery
- Use Xantrion-approved AI tools for research, analysis, and documentation while protecting confidential information
- Coordinate evidence collection and auditor requests for Xantrion's SOC 2 Type II examination and ISO/IEC 27001 audit activities
- Organize audit documentation, maintain request trackers, and follow up with internal control owners
- Review evidence for completeness and consistency and identify missing or outdated documentation
- Provide seasonal support during internal audit preparation and review periods
- Follow company policies, procedures, applicable laws, confidentiality requirements, and dress code
Requirements
What you’ll need- Three or more years of combined experience in IT operations, cybersecurity, IT audit, or compliance
- At least one year supporting control assessments, audit evidence collection, or security documentation
- Practical understanding of identity and access management, endpoint security, email security, backups, networking, and cloud services
- Experience reviewing technical configurations or administrative reports against documented standards
- Working knowledge of NIST CSF and CIS Controls
- Familiarity with NIST SP 800-53 and ISO/IEC 27001 control concepts
- Strong writing skills for policies, procedures, assessment findings, and client documentation
- Ability to distinguish documented policies from evidence that controls are implemented and operating
- Strong organization and attention to detail
- Ability to manage deliverables across multiple clients
- Ability to work independently, identify questions or evidence gaps, and incorporate vCIO feedback
- Professional communication skills and sound judgment with confidential client information
- Preferred: experience supporting registered investment advisers or financial services organizations
- Preferred: familiarity with SEC Regulation S-P, FTC Safeguards Rule under GLBA, and applicable FINRA requirements
- Preferred: experience with managed service providers or multiple client environments
- Preferred: familiarity with Microsoft 365, Entra ID, Intune, and endpoint/security management tools
- Preferred: experience conducting vendor cybersecurity reviews and evaluating SOC 2 reports
- Preferred: experience supporting SOC 2 Type II examinations or ISO/IEC 27001 audits
- Preferred: familiarity with HIPAA, CJIS, NIST SP 800-171, CMMC, or FedRAMP
- Preferred: Security+, CGRC, CISA, or ISO/IEC 27001 credential
- Preferred: familiarity with AI governance, acceptable-use policies, and vendor data handling/access-permission risks
- Must have an existing cell phone running current Android or iOS
- Must have reliable, high-speed internet for remote work
- Must have a dedicated, secure, and private workspace
- Must use Xantrion-provided PC and headset
- Willingness and ability to travel to Xantrion's office or shared workspace as needed
- A relevant degree or certification is welcome but not required; equivalent practical experience considered
Benefits
Comp & perks- 100% of medical, dental, and vision coverage for you and your family
- 401K with company match up to 4% of salary
- Certification reimbursement
- Annual training budget
- 17 days PTO per year
- Paid training days
- Bonuses for referring new clients or employees
- Flexibility and hybrid work arrangement
- Cell phone, internet connection, and home office equipment allowance if applicable
- Xantrion-provided PC and headset
- Opportunity to acquire additional certifications
- Promotion-from-within opportunities
