Lead Consultant, Sensitive Data Compliance

FORVIS, LLP
  • Charlotte, NC
    12 days ago

    Job Description

    Description & Requirements

    The Sensitive Data Compliance Lead Consultant role at FORVIS MAZARS working with the Sensitive Data Cyber Compliance leadership to define, refine and expand the firm's practice areas and services offerings. This role will be primarily focused on supporting PCI DSS projects with clients of all size, complexity, and industry, including international and Fortune 1000 companies, and U.S. Department of Defense contractors.

    The right individual will help lead PCI DSS projects as an experienced subject matter resource with previous experience with various US federal compliance frameworks, including PCI DSS, CMMC / NIST 800-171, FISMA, FedRAMP, and NIST CSF.

    What You Will Do:

    • Lead and execute PCI compliance related assessments and sensitive data compliance assessments for enterprise clients by identifying key risks and gaps and documenting clear reporting with proof-of-concept and recommendations.
    • Help execute information security risk and compliance assessments against federal and other government required cyber frameworks, NIST 800-171, NIST 800-53, FedRAMP, and the NIST Cybersecurity Framework, among others.
    • Assesses IT environments and identifies gaps and vulnerabilities that impair compliance with required standards and assists with the documenting of clear reporting with proof-of-concept and recommendations.
    • Help the IT Risk & Compliance team maintain industry leading solutions for PCI and other evolving cybersecurity compliance frameworks but pursuing continuing education.
    • Participate on consulting teams with large enterprise clients in multiple industries to:
    • Assist organizations with defining boundaries of in-scope systems.
    • Assisting clients with documentation development, including system security plans (SSP), policies/procedures, strategy development, and plans of action and milestones (POAMs).
    • Define and integrate solutions, including tools, processes, and data flows to maintain required compliance obligations and reduce cyber risk.
    • Effectively manage multiple projects concurrently, helping define and drive project management to keep projects on schedule and within budget.

    Minimum Qualifications:

    • Bachelor's Degree in Cybersecurity, MIS, Computer Science, or a similar discipline
    • Payment Card Industry Qualified Security Assessor (PCI QSA) credential.
    • Cybersecurity and/or privacy-related certifications (e.g. CISSP, CISA, CISM, preferred).
    • Experience providing consulting, assessment, or implementation services associated with federal cyber compliance frameworks, including NIST 800-171, FISMA, or FedRAMP.
    • Working knowledge of cyber risk management frameworks (CMMC / NIST 800-171, FISMA, FedRAMP, NIST Cybersecurity Framework, NIST SP 800-53)
    • At least 5 years of experience in cybersecurity, IT audit, or governance, risk, and compliance required, including 1 - 2 of the following frameworks:
    • Payment Card Industry Data Security Standard (PCI DSS)
    • NIST Cybersecurity Framework (CSF)
    • ISO 27001 / 27002
    • FedRAMP / StateRAMP
    • FISMA and NIST SP 800-53
    • CIS Critical Security Control

    #LI-ATL, #LI-SGF, #LI-CLTSP, #LI-DFW

    #LI-GM1

    About Forvis Mazars, LLP

    Forvis Mazars, LLP is an independent member of Forvis Mazars Global, a leading global professional services network. Ranked among the largest public accounting firms in the United States, our 7,000+ team members deliver assurance, tax, and consulting services to clients in all 50 states and internationally.

    With a legacy spanning more than 100 years, we're building something different. We are guided by a shared promise: Together, we create extraordinary experiences. That means delivering an Unmatched Client Experience while creating a workplace where relationships matter, learning fuels growth, and every person feels valued and supported to thrive.

    What We Offer

    Our robust total rewards program and flexible work environment reflect our commitment to people, careers, and well-being-empowering our team to grow and thrive while delivering exceptional service. To explore what makes working at Forvis Mazars special, visit www.forvismazars.us/careers.

    Legal Notice

    Forvis Mazars, LLP is an equal opportunity/affirmative action employer in accordance with applicable law. Employment selection and related decisions are made without regard to age, race, color, sex, sexual orientation, national origin, religion, genetic information, disability, protected veteran status, gender identity, or other protected classifications.

    It is Forvis Mazars, LLP standard policy not to accept unsolicited referrals or resumes from any source other than directly from candidates.

    Forvis Mazars, LLP expressly reserves the right not to consider any unsolicited referrals, resumes or CVs from vendors including and without limitation, search firms, staffing agencies, fee-based referral services, and recruiting agencies.

    Forvis Mazars, LLP further reserves the right not to pay a fee to a recruiter or recruiting agency unless such recruiter or recruiting agency has a signed vendor agreement with Forvis Mazars, LLP. Any resume(s) or CV(s) submitted to anyone working for Forvis Mazars, LLP, or submitted to a Forvis Mazars, LLP general email, without having a Forvis Mazars, LLP vendor agreement in place, will be considered the property of Forvis Mazars, LLP.

    Numbers & Facts

    LocationCharlotte, NC

    Skills

    • Budget Managementunmatched
    • C++ Active Template Libraries (ATL)unmatched
    • CISA - Certified Information Systems Auditorunmatched
    • CISM - Certified Information Security Managerunmatched
    • CISSP - Certified Information Systems Security Professionalunmatched
    • Computer Scienceunmatched
    • Computer Securityunmatched
    • Consultingunmatched
    • Customer Experienceunmatched
    • Customer Support/Serviceunmatched
    • Data Analysisunmatched
    • Data Processingunmatched
    • Documentationunmatched
    • Employment Lawunmatched
    • FISMA - Federal Information Security Management Actunmatched
    • Federal Governmentunmatched
    • Fortune 1000 Customersunmatched
    • Geneticsunmatched
    • Government Contractsunmatched
    • ISO (International Organization for Standardization)unmatched
    • Information Technology & Information Systemsunmatched
    • Information Technology/Systems Auditunmatched
    • Information/Data Security (InfoSec)unmatched
    • Internet Securityunmatched
    • Leadershipunmatched
    • Maintain Complianceunmatched
    • Management of Information Systems/Technology (MIS)unmatched
    • Multitaskingunmatched
    • PCIunmatched
    • PCI-DSSunmatched
    • Procedure Developmentunmatched
    • Process Flowunmatched
    • Professional Servicesunmatched
    • Project Scheduleunmatched
    • Project/Program Managementunmatched
    • Proof of Conceptunmatched
    • Public Accountingunmatched
    • Recruiting/Staffing Agencyunmatched
    • Regulatory Complianceunmatched
    • Riskunmatched
    • Risk Analysisunmatched
    • Risk Managementunmatched
    • Risk Management Framework (RMF)unmatched
    • Security Analysisunmatched
    • Strategic Planningunmatched
    • Time Managementunmatched
    • U.S. National Institute of Standards and Technology (NIST)unmatched
    • United States Department of Defense (DoD)unmatched
    • Web Application Frameworkunmatched

    Be found by employers

    5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

    Level up your application

    Professional resume templates

    Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

    Free resume templates

    Free resume builder

    Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

    Free resume builder