Relomote
Remote JobsRelocation Jobs
Add companySaved
Relomote

Relomote is a job board for remote, hybrid, and relocation jobs — every listing AI-classified for the countries it actually hires from, or the visa and relocation support it offers.

LinkedInCrunchbase

Remote jobs by category

  • Remote Engineering & Development jobs
  • Remote Customer Support jobs
  • Remote Design jobs
  • Remote Marketing jobs
  • Remote Sales jobs
  • Remote Product jobs
  • Remote Data & Analytics jobs
  • Remote People & Talent jobs
  • Remote Writing & Content Creation jobs
  • Remote Finance jobs
  • Remote Legal & Compliance jobs
  • Remote Operations & Admin jobs
  • Remote Data Entry jobs
  • Remote Virtual Assistant jobs
  • Remote Education/Training jobs
  • Remote Healthcare/Clinical jobs
  • Remote Other jobs

Remote jobs by location

  • Work from anywhere jobs
  • Remote jobs in Africa
  • Remote jobs in Asia
  • Remote jobs in Europe
  • Remote jobs in Latin America
  • Remote jobs in Middle East
  • Remote jobs in North America
  • Remote jobs in Oceania
  • All remote jobs →

Relocation & visa sponsorship

  • Visa sponsorship jobs
  • Relocation package jobs
  • Relocate to Europe
  • Relocate to Germany
  • Relocate to Netherlands
  • Relocate to Spain
  • Relocate to Portugal
  • Relocate to Greece
  • Relocate to United Kingdom
  • Relocate to Canada
  • Relocate to Australia
  • Relocate to Sweden
  • Relocate to Switzerland
  • Relocate to Japan
  • Relocate to United Arab Emirates
  • All relocation jobs →

© 2026 RelomoteAboutPrivacyTerms

Contact [email protected] · Built by Mahmoud

Relomote
Remote JobsRelocation Jobs
Add companySaved
Cyberleaf logo

Professional Services Specialist

Cyberleaf
Posted 1 hour ago
🇺🇸United States🏠Remote📁Engineering & Development
Is this job info correct?

About the Role Waterleaf International, an engineering, cybersecurity and science-based defense and networking contractor, is seeking an experienced, client-focused Cybersecurity GRC & Advisory Consultant to deliver professional services across the following delivery areas: Governance, Risk, and Compliance, Assessments, and Advisory/Consulting services. Waterleaf offers a forward leaning culture – that means our focus and direction is on people, intellect, process and deliverables. Our people include employees, contractors, and customers, all of whom have inherent value and contributions to not only our mission in defending our country but to the community we each live in. We support professional and individual growth and provide dynamic, fascinating, and supportive work environments. Talk to us about the ability to have great financial and personal gains in a thriving and vital environment. A seasoned candidate operates like a trusted senior IT consultant: equally comfortable running a NIST CSF assessment, authoring a policy stack, briefing a board on risk posture, and validating that documented controls hold up. This role is strategic and advisory in nature. It is not a hands-on offensive or operational security position (see What This Role Is Not , below). Primary Duties and Responsibilities: Governance, Risk & Compliance (GRC) Evaluate client governance structures, policies, procedures, and controls against the frameworks most relevant to their industry - NIST CSF, NIST 800-171, CMMC, SOC 2, HIPAA, PCI DSS, and ISO 27001. Conduct GRC assessments that identify gaps, quantify risk, and map findings across multiple standards simultaneously. Produce risk-ranked findings, executive summaries written for leadership and board audiences, and prioritized remediation roadmaps. Support clients in maintaining compliance over time, including post-certification continuity of controls. Advisory & Consulting Serve in an advisory capacity, providing strategic security leadership without the cost of a full-time executive hire. Help clients answer the questions their boards and auditors are asking: What is our risk exposure? Are we compliant? Where should we invest next? Develop multi-year cybersecurity roadmaps that benchmark current maturity, define a target future state, and sequence initiatives to balance near-term risk reduction with long-term resilience. Facilitate stakeholder workshops to calibrate strategy to each client’s risk tolerance and business goals. Present findings, roadmaps, and progress through clear executive-level reporting and regular reviews. Building Security Programs Through Policy Development Stand up information security programs from the ground up for clients with little or no existing structure. Author and mature policies, procedures, charters, RACI matrices, and escalation paths that are internally consistent and built to survive audits and personnel changes. Translate overlapping regulatory obligations into a single, coherent policy and control stack rather than a patchwork of one-off documents. Define decision rights, control ownership, and the operating model that keeps a program running after the engagement ends. NIST CSF Assessments Lead NIST Cybersecurity Framework assessments across all six core functions: Govern, Identify, Protect, Detect, Respond, and Recover. Establish a current-state profile, identify gaps, and build a target-state roadmap with clear milestones and assigned ownership. Apply structured, repeatable assessment methodology so results are actionable rather than academic. Technical Validation (Controls Assurance) Conduct technical validation engagements that confirm documented controls work as described - moving beyond policy and documentation review to verify real-world control effectiveness. Conduct a comprehensive assessment of the Client’s Cloud environment to identify vulnerabilities, enhance overall security posture, and ensure compliance. Map validated control coverage back to the relevant framework subcategories for traceable, audit-ready results. Note: “technical validation” here refers to assurance that a client’s existing IT and Cybersecurity stack is properly configured to reduce the risk of a cyberattack by an external party. What This Role Is Not To set clear expectations, this engagement does not include hands-on delivery of: Penetration testing, red teaming, or offensive security Digital forensics and incident response (DFIR) 24/7 SOC monitoring, managed detection and response (MDR), or SIEM operations Other purely technical / operational security services This is a GRC, advisory, and program-build role. When a client’s needs fall into the categories above, the individual is expected to recognize it and coordinate a referral or hand-off rather than deliver it personally. How You Work (Consulting Mindset) Client-focused first. You tailor every engagement to the client’s industry, risk profile, and regulatory obligations. Actionable, not academic. Your deliverables are built for execution, with business context attached to every finding. End-to-end ownership. You don’t hand over a finding list and walk away - you help operationalize the recommendations. Trusted advisor’s presence. You can move a client from reactive firefighting to a proactive, framework-aligned program, and explain the journey in plain language. Required Qualifications 3+ years in cybersecurity, IT risk, audit, or compliance consulting, with demonstrated client-facing delivery. Hands-on experience conducting framework-based assessments (NIST CSF and/or SOC 2 strongly preferred). Demonstrated ability to author security policies, procedures, and program documentation from scratch. Working fluency across multiple compliance frameworks (e.g., SOC 2, HIPAA, PCI DSS, ISO 27001, CMMC). Strong written communication: the ability to produce executive summaries, findings reports, and remediation roadmaps that leadership can act on. Comfort presenting to and advising senior stakeholders, including boards and auditors. Preferred Qualifications Relevant certifications such as CISSP, CISA, CISM, CRISC, ISO 27001 Lead Auditor/Implementer, or NIST-focused credentials. Industry depth in one or more regulated sectors - Defense Industrial Base, Financial Services, Healthcare, Manufacturing, or Technology/SaaS. Experience supporting cyber-insurance readiness or M&A diligence from a GRC standpoint. Engagement Details Equipment: Cyberleaf will provide a corporate laptop and additional equipment as needed. Scheduling: Flexible, scoped to engagement milestones and deliverable timelines. Travel: Primarily remote; limited client-site work may be requested for certain assessments or workshops. Reporting: This position reports to the Director of Professional Services. This position does not have any direct reports. Come grow with us!

Similar jobs

Similar jobs

Munson Healthcare logo

Senior Medical Staff Services Specialist

Munson Healthcare

🇺🇸United States6 hours ago
CA

Executive Services Specialist, Essex

Career.io

🇺🇸United States9 hours ago
Cox logo

Remote Dealer Services Specialist II - Manheim (Syracuse / Rochester Region)

Cox

🇺🇸United States12 hours ago
Cox logo

Remote Dealer Services Specialist II (Manheim Riverside)

Cox

🇺🇸United States12 hours ago
Insightec logo

Field Service Specialist - North California

Insightec

🇺🇸United States12 hours ago
Gdit logo

Member Services Processing Specialist

Gdit

🇺🇸United States16 hours ago