Opportunity sourced from the Official SkillBridge website. Not endorsed by the Department of Defense.
Is this your organization? Claim it for free to manage listings and see applicants.
Waterleaf International, an engineering, cybersecurity and science-based defense and networking contractor, is seeking an experienced, client-focused Cybersecurity GRC & Advisory Consultant to deliver professional services across the following delivery areas: Governance, Risk, and Compliance, Assessments, and Advisory/Consulting services.Waterleaf offers a forward leaning culture – that means our focus and direction is on people, intellect, process and deliverables. Our people include employees, contractors, and customers, all of whom have inherent value and contributions to not only our mission in defending our country but to the community we each live in. We support professional and individual growth and provide dynamic, fascinating, and supportive work environments. Talk to us about the ability to have great financial and personal gains in a thriving and vital environment.A seasoned candidate operates like a trusted senior IT consultant: equally comfortable running a NIST CSF assessment, authoring a policy stack, briefing a board on risk posture, and validating that documented controls hold up.This role is strategic and advisory in nature. It is not a hands-on offensive or operational security position (see What This Role Is Not, below).
Governance, Risk & Compliance (GRC)Evaluate client governance structures, policies, procedures, and controls against the frameworks most relevant to their industry - NIST CSF, NIST 800-171, CMMC, SOC 2, HIPAA, PCI DSS, and ISO 27001.Conduct GRC assessments that identify gaps, quantify risk, and map findings across multiple standards simultaneously.Produce risk-ranked findings, executive summaries written for leadership and board audiences, and prioritized remediation roadmaps.Support clients in maintaining compliance over time, including post-certification continuity of controls.Advisory & ConsultingServe in an advisory capacity, providing strategic security leadership without the cost of a full-time executive hire.Help clients answer the questions their boards and auditors are asking: What is our risk exposure? Are we compliant? Where should we invest next?Develop multi-year cybersecurity roadmaps that benchmark current maturity, define a target future state, and sequence initiatives to balance near-term risk reduction with long-term resilience.Facilitate stakeholder workshops to calibrate strategy to each client’s risk tolerance and business goals.Present findings, roadmaps, and progress through clear executive-level reporting and regular reviews.Building Security Programs Through Policy DevelopmentStand up information security programs from the ground up for clients with little or no existing structure.Author and mature policies, procedures, charters, RACI matrices, and escalation paths that are internally consistent and built to survive audits and personnel changes.Translate overlapping regulatory obligations into a single, coherent policy and control stack rather than a patchwork of one-off documents.Define decision rights, control ownership, and the operating model that keeps a program running after the engagement ends.NIST CSF AssessmentsLead NIST Cybersecurity Framework assessments across all six core functions: Govern, Identify, Protect, Detect, Respond, and Recover.Establish a current-state profile, identify gaps, and build a target-state roadmap with clear milestones and assigned ownership.Apply structured, repeatable assessment methodology so results are actionable rather than academic.Technical Validation (Controls Assurance)Conduct technical validation engagements that confirm documented controls work as described - moving beyond policy and documentation review to verify real-world control effectiveness.Conduct a comprehensive assessment of the Client’s Cloud environment to identify vulnerabilities, enhance overall security posture, and ensure compliance.Map validated control coverage back to the relevant framework subcategories for traceable, audit-ready results.
3+ years in cybersecurity, IT risk, audit, or compliance consulting, with demonstrated client-facing delivery.Hands-on experience conducting framework-based assessments (NIST CSF and/or SOC 2 strongly preferred).Demonstrated ability to author security policies, procedures, and program documentation from scratch.Working fluency across multiple compliance frameworks (e.g., SOC 2, HIPAA, PCI DSS, ISO 27001, CMMC).Strong written communication: the ability to produce executive summaries, findings reports, and remediation roadmaps that leadership can act on.Comfort presenting to and advising senior stakeholders, including boards and auditors.
US Air Force, US Army, US Coast Guard, US Marine Corps, US Navy, US Space Force
Remote OpportunityActive Opportunity
Send a professional application in seconds, created by prior SkillBridge POCs.