Position Category: A1-A2
Salary Range: $100,000 - $150,000 depending upon experience and technical skillset
About 38North
38North Security is the world’s most experienced, technical-expert cloud advisory team. Since the inception of cloud computing, we have helped organizations around the world take secure, compliant advantage of the cloud to power modern business. From tech start-ups to Fortune 500 companies, our impressive client portfolio includes government, major healthcare organizations, cloud service providers, and security vendors, with many at the forefront of innovation and disruptive technology.
Our goal is to become the preeminent cloud security engineering and compliance advisory team, in the US and internationally, trusted by the world’s most demanding cloud centric organizations. At 38North, you will work with the most elite, experienced FedRAMP and cloud security experts in the world. You will be expected to continuously advance your technical and consulting skills while contributing to corporate initiatives that support our rapid growth.
In exchange, we offer competitive salaries (commensurate with experience), a fully remote, flexible work environment, and unlike larger companies in this space, reasonable billable hour expectations. Most importantly, you’ll be joining a team-focused organization, helmed by leaders who have worked together for decades to advance security and compliance initiatives.
About the Role
We seek cloud security advisors with at least five years’ consulting or assessment experience. Ideal candidates will combine security knowledge with proven experience independently supporting large clients. Strong written and verbal communication skills are a must, as our advisors work directly with our clients’ senior leadership to balance business and security needs in the context of tolerable organizational risk.
You should be a seasoned security consultant with at least 5 years’ experience with the NIST Risk Management Framework, in either an assessment or advisory role.
Your job will be to advise and/or assess 38North clients based on security best practices driven by security regulations and compliance including FedRAMP, DoD CC SRG, FISMA, NIST 800-171, NIST Cybersecurity Framework, SOC I/II, HIPAA and ISO27000. We are not a cookie-cutter organization, we tailor our solutions for every client, and so analytical thinking is a must.
This is a great opportunity for home-based job seekers who want flexibility in their schedule. We’re based in Washington, DC, but you can be based anywhere in the continental US. Modest travel in the US and internationally may be required (about 1 week every 3 months).
Job Responsibilities
Independently serve as a Cloud Security Advisor supporting clients across diverse cloud models and platforms
Support clients as they navigate security and compliance challenges
Conduct gap analyses against various US and international cloud security and compliance standards
Develop documentation to meet security and compliance requirements
Support the security assessment and authorization process for clients
Serve as an expert in various cloud platforms and maintain a working knowledge of Cloud Service Provider tools and functionality
Conduct testing and data reviews to evaluate the effectiveness of current security measures
Provide support to the security program assessment and authorization processes
Authoring and peer review of detailed design documentation, including security documentation and inclusive of vendor best practices
Contribute to corporate thought leadership and marketing initiatives
Provide mentorship and training to more junior personnel
Qualifications & Experience
The ideal candidate is a self-starter, technically competent, able to communicate clearly and persuasively at all levels, works well with others, and takes the initiative to grow a client through awesome customer relationship management skills. Here’s your punch list:
A four-year degree or comparable experience
At least 5 years progressive experience in information security
Knowledge of cloud security technologies and major services offered by one or more major cloud providers such as AWS, Microsoft Azure, Google Cloud, and IBM Cloud
At least one current security industry-recognized professional certification e.g. CISSP, CISM, CCSP, etc.
Desired Qualifications
Detailed knowledge and application of NIST-based security compliance frameworks and standards including FedRAMP, DoD CC SRG, FISMA, NIST Cybersecurity Framework, and NIST 800-171
Experience with international security baselines (e.g., Protected B, ACSC/IRAP, etc.)
At least 2 years supporting FedRAMP Cloud Service Providers in either an assessment or advisory role
Consulting experience
Cloud certifications from AWS, Azure or Google
Experience working in-house for a major CSP
3PAO assessment experience
Here's how to apply
Submit the following to recruiting@38northsecurity.com
Resume: hopefully self-explanatory
Cover Letter: no rules, just make it something we actually want to read
Candidates will be asked to supply 3 references and undergo a background check prior to employment. Candidates must be US citizens. Learn more about 38North at www.38northsecurity.com.