NCC Group logo

Senior Security Consultant - Privacy and Assurance

Hiring from
United States
Work type
Hybrid
Posted
Is this job info correct?

513,132 remote jobs, straight from company career pages

100% free · New jobs every hour

Show job description
The Senior Security Consultant, US Privacy & Assurance is responsible for helping clients identify, manage, and reduce cybersecurity, privacy, and regulatory risk through advisory, assessment, and assurance services. The role provides expert guidance on US privacy regulations, healthcare and financial services requirements, security frameworks, and risk management practices, enabling organizations to protect sensitive information, strengthen governance, and demonstrate compliance with evolving legal and regulatory obligations.

The Senior Security Consultant, US Privacy & Assurance is expected to have deep experience conducting privacy-focused assessments that help organizations understand and manage privacy risk in increasingly complex regulatory environments. This includes leading Privacy Impact Assessments (PIAs) and privacy risk assessments, developing and validating data flow maps to identify how personal information is collected, used, shared, stored, and retained, and evaluating compliance with evolving US privacy requirements. The role requires a strong understanding of privacy-intensive state regulations, including CCPA/CPRA and other emerging state privacy laws, and the ability to translate regulatory obligations into practical business and technical controls. Through these assessments, the consultant helps clients strengthen privacy governance, improve transparency, reduce regulatory risk, and build sustainable privacy programs aligned with business objectives and legal requirements.

Additionally, working collaboratively with clients, technical teams, and business stakeholders, the Senior Security Consultant delivers privacy assessments, security and compliance reviews, risk assessments, and assurance engagements across frameworks and regulations such as CCPA, CMS, HIPAA, HITRUST, NIST, NYDFS, and other applicable US privacy and cybersecurity requirements. The role helps organizations build resilient security and privacy programs by translating complex regulatory and technical requirements into practical, business-focused solutions.

This position plays a key role in supporting NCC Group's mission to create a more secure digital future.

Through trusted client relationships, high-quality project delivery, and thought leadership, the Senior Security Consultant helps clients improve security maturity, manage regulatory risk, and build trust with customers, partners, and regulators. The role contributes directly to client satisfaction, revenue growth, successful engagement delivery, regulatory readiness, and the continued reputation of NCC Group as a trusted cybersecurity and risk management advisor.

Key Responsibilities

Lead and deliver client engagements across privacy, cybersecurity, risk, and assurance domains, ensuring projects are completed on time, within scope, on budget, and to a high standard of quality. This includes privacy assessments, compliance reviews, cybersecurity assessments, risk assessments, and audit support activities aligned to client requirements and regulatory obligations.

Provide subject matter expertise on US privacy regulations and data protection requirements, including CCPA/CPRA and emerging federal and state privacy laws. Monitor regulatory developments, assess their impact on clients, and deliver practical recommendations to help organizations maintain compliance and manage risk.

Deliver assurance and compliance engagements against industry standards and regulatory frameworks, including HITRUST, HIPAA, NYDFS Cybersecurity Regulation, NIST Cybersecurity Framework (CSF), NIST Risk Management Framework (RMF), and related governance, risk, and compliance requirements.

Support business development activities by assisting with the scoping, planning, and estimation of privacy, risk, and assurance engagements. Contribute to proposals, statements of work (SOWs), client presentations, and solution development to ensure client needs are accurately understood and appropriately addressed.

Support the development and enhancement of NCC Group's US privacy consulting offerings, methodologies, templates, accelerators, and intellectual property. Contribute to the growth of privacy services including CCPA/CPRA readiness assessments, privacy program development, data governance, and regulatory compliance offerings.

Advise clients on the design, implementation, and improvement of privacy and security programs, helping organizations establish effective governance, risk management, compliance, and data protection practices.

Develop and maintain trusted client relationships, serving as a strategic advisor throughout engagements. Identify opportunities to expand services, support account growth, and strengthen NCC Group's position as a trusted cybersecurity and privacy partner.

Mentor and support junior consultants and team members by providing coaching, technical guidance, quality reviews, and knowledge sharing to promote professional development and delivery excellence.

Produce high-quality client deliverables
, including assessment reports, risk analyses, audit documentation, executive presentations, remediation roadmaps, and compliance recommendations tailored to both technical and non-technical stakeholders.

Collaborate with multidisciplinary teams
across cybersecurity, privacy, assurance, healthcare, financial services, and risk management practices to deliver integrated solutions that address client and regulatory requirements.

Maintain current knowledge of evolving privacy, cybersecurity, and regulatory requirements, industry trends, emerging threats, and best practices, and apply this knowledge to client engagements, service development, and thought leadership activities.

Travel occasionally to client locations to perform assessments, audits, workshops, stakeholder interviews, and other engagement-related activities as required.

Skills, Knowledge and Expertise

Professional Knowledge & Experience
  • Practical experience delivering privacy, cybersecurity, risk, and assurance consulting engagements for clients across regulated industries.
  • Experience assessing, implementing, or advising on privacy and security programs, including governance, risk management, compliance, and data protection initiatives.
  • Knowledge of US privacy laws and regulations, including CCPA/CPRA and other state privacy requirements, and the ability to interpret regulatory changes and translate them into practical business recommendations.
  • Experience conducting privacy, cybersecurity, and compliance assessments against recognized frameworks and regulations, including:
    • HITRUST CSF
    • HIPAA
    • NIST Cybersecurity Framework (CSF)
    • NIST SP 800-53
    • NYDFS Cybersecurity Regulation
    • CIS Controls
    • ISO 27001
  • Experience performing risk assessments, developing risk treatment plans, and supporting remediation activities.
  • Experience producing clear reports, presentations, and recommendations for both technical and non-technical stakeholders.
  • Experience coordinating with legal, compliance, privacy, security, and technology teams to achieve client objectives.
Skills & Behaviours
  • Ability to analyze complex regulatory, privacy, and cybersecurity requirements and translate them into actionable business guidance.
  • Strong problem-solving and critical-thinking skills with the ability to assess risk and identify practical solutions.
  • Ability to manage multiple engagements and priorities while maintaining high-quality deliverables.
  • Ability to present complex information clearly to executive, operational, and technical audiences.
  • Strong stakeholder management and relationship-building skills.
  • Ability to mentor and support the development of consultants and other team members.
  • Adaptability and willingness to learn emerging privacy, cybersecurity, and regulatory requirements.
  • Strong project planning and organizational skills.

Certifications
Candidates should hold one or more relevant certifications, such as:
  • Certified Information Privacy Professional (CIPP/US) (Preferred)
  • Certified Information Privacy Manager (CIPM)
  • Certified Information Systems Security Professional (CISSP)

Benefits

We believe great work deserves great support. That’s why we offer a benefits package designed to look after you, your family, and your future.

We Offer
Generous annual leave
  • Starting at 15 days, increasing to 20 days with service, plus 3 floating days from day one to use at your leisure
Plan for your future
  • 401(k) with up to 5% company match
Life protection for peace of mind
  • Life assurance at 1x your annual salary
Comprehensive health cover
  • Medical, dental, and vision plans available for you and your family, with flexible options to suit your needs
Financial protection when it matters most
  • Income protection through short and long term disability cover, plus accidental death and disability insurance
Share in our success
  • Opportunity to invest through our SAYE and Employee Stock Purchase Plan


Similar jobs

Apply for this job