Invadel

Security Compliance Consultant (SOC 2, PCI DSS, HIPAA, NYDFS 500), Contract

United States full-time Mid $130,000 - $210,000
full-time Mid level Technology & IT Salary listed Curated
Sign in to apply Free account — we bring you straight back to this role.

About the role

Invadel is a New York City penetration testing firm. Every engagement is fixed-scope and fixed-price, agreed in writing, with public prices at invadel.com/pricing and a free retest. This is a contract role, remote within the United States, paid per engagement; work is typically one to three days per client engagement, attached to a penetration test, plus occasional readiness reviews.
What you will do: produce the framework mapping section of each report and the attestation letter clients hand to auditors and customers; review client scope against the requirement that drives the test (for example PCI DSS 11.4 segmentation testing or NYDFS 500.5) and flag gaps before testing starts; answer auditor and customer security questionnaire follow-ups with the client; run readiness reviews for clients preparing for a first SOC 2 Type II or PCI DSS assessment; keep the compliance mapping templates current.
What we need: four or more years in security compliance, audit or GRC with direct experience of SOC 2 and at least one of PCI DSS, HIPAA, ISO 27001, NYDFS 500 or CMMC; enough technical grounding to read a penetration test finding and explain what it means for a control; clear writing for auditors, executives and engineers; based in the United States with authorization to work here; two professional references.
Nice to have: time on the assessor side (QSA, SOC 2 audit team, C3PAO) or inside a compliance automation platform; experience with New York financial services or healthcare clients.
Full description, pay range and application:
Originally posted on Himalayas

Interview prep

Walk in with sharper answers.

Use this as a quick practice sheet before you speak with the employer.

Mid
Technology & IT Remote Collaboration Writing Security Compliance Consultant Mid level

Likely questions

  1. Tell us about work you have done that is close to the Security Compliance Consultant (SOC 2, PCI DSS, HIPAA, NYDFS 500), Contract role.
  2. How would you approach your first 30 days at Invadel?
  3. Which of Remote Collaboration, Writing and Security have you used recently, and what did it help you achieve?
  4. Describe a time you solved a problem without waiting to be told exactly what to do.
  5. How do you handle busy days, changing priorities, or pressure at work?

Prepare before the call

  • A recent example that proves your experience with Remote Collaboration, Writing and Security.
  • One short story with a problem, your action, and the result.
  • Two examples that show the strengths listed on your CV.
  • A clear reason why this role and company interest you.
  • Your availability, preferred work style, and salary expectations.

Ask them

  • What would success look like in the first 90 days?
  • What are the main problems this hire should help solve?
  • How does the team give feedback and measure good work?
  • What does a normal working week look like for this role?
Practice line

I am interested in the Security Compliance Consultant (SOC 2, PCI DSS, HIPAA, NYDFS 500), Contract role because I can bring practical experience in Remote Collaboration, Writing and Security, learn the team quickly, and contribute to the outcomes Invadel needs from this hire.

Related jobs.

More roles from this company or category.