Associate Managing Director, Principal Cybersecurity Consultant
Job Description
The Associate Managing Director, Principal Cybersecurity Consultant at Nardello & Co. is a player-coach role focused on strengthening the firm’s proactive security practice. This position combines senior advisory responsibilities with hands-on leadership to ensure consistent delivery quality, measurable strategic impact, and business-aligned outcomes across multiple client engagements. Based in New York, NY, the role works in a hybrid setup with some travel required.
In addition to serving as a senior client advisor and vCISO, the role evolves service offerings by standardizing delivery methodologies and enforcing quality controls across teams. The consultant also guides technical work that spans assessments, incident response program development, tabletop exercises, and security architecture reviews for enterprise clients.
Key Responsibilities
- Own delivery quality, consistency, and strategic impact across a portfolio of concurrent client engagements.
- Serve as a senior client advisor/vCISO on complex, multi-stakeholder engagements requiring executive-level presence and technical depth.
- Standardize delivery methodologies and enforce quality controls across all team engagements.
- Lead or guide technical assessments, incident response program development, tabletop exercises, and security architecture reviews for enterprise clients.
- Drive repeatable engagement frameworks that align cybersecurity programs with each client’s business objectives, regulatory environment, and risk tolerance.
- Ensure engagements consistently deliver business-aligned cyber outcomes.
- Contribute to thought leadership, methodology documentation, and practice intellectual property to strengthen the Company’s market position.
- Represent the practice in cross-functional planning and discussions with peer leadership across business units.
- Assist with recruiting, retention, and development of teammates.
Requirements
- Bachelor’s degree in information technology, cybersecurity, or a related discipline (or equivalent professional experience); advanced degree preferred.
- Minimum 15 years of experience in information security, IT operations, or security consulting.
- Demonstrated success managing a portfolio of concurrent complex confidential client engagements with accountability for delivery quality, utilization, and margin.
- Track record building and scaling consulting teams, including hiring, performance management, and career development of directors and senior individual contributors.
- Proven ability to act as a trusted advisor to CISOs, CIOs, and other senior client executives across diverse industries.
- Strong project and program management discipline, including ability to standardize delivery methodologies and enforce quality across a team.
- Deep understanding of technical and threat trends and their security implications, including cloud migration, identity, OT/IoT, and emerging adversary tradecraft.
- Experience defining security requirements based on business strategy and regulatory environment, including NIST, ISO 27001, PCI, applicable state laws, and industry best practices.
- Experience leading development of incident response programs, tabletop exercises, and security architecture reviews for enterprise clients.
- Experience contributing to pre-sales activity, scoping, proposal development, and executive presentations.
- Excellent written and verbal communication skills to explain complex issues to clients and key internal stakeholders.
- Collaborative, entrepreneurial mindset with credibility, discretion, risk management awareness, sound judgment, integrity, and ethical conduct.
Technologies
- NIST
- ISO 27001
- PCI
Preferred Qualifications
- Relevant security certifications such as CISSP, CISM, CCISO, GSLC, GCIH, or equivalent.
- Prior experience in a cybersecurity consultancy and/or an enterprise security leadership role.
- Familiarity with managed security services, delivery models, and how proactive services integrate with detection and response, plus supply chain risk offerings.
- Demonstrated knowledge of adversary tactics, techniques, and procedures and how they inform proactive controls.
- Experience presenting at industry conferences, contributing to thought leadership, or publishing security research.
Work Conditions
- Professional office environment.
- Hybrid working arrangement.
- Some travel required.
Salary: USD 225,000 - 260,000 per year.
Location: New York, NY (hybrid).