Cybersecurity Consultant
Job Description
Join Claris Consulting Inc. as a Cybersecurity Consultant supporting technical security assessments, offensive testing, remediation validation, and CISO/vCISO advisory work.
Responsibilities
- Support technical security assessments, control reviews, vulnerability management, and remediation efforts
- Review and validate security findings, vulnerabilities, system configurations, and supporting technical evidence
- Research vulnerabilities, attack techniques, security controls, and practical remediation options
- Track remediation progress and help validate whether identified issues are effectively resolved
- Conduct internal, external, network, web application, and other penetration testing activities within approved rules of engagement
- Perform reconnaissance, vulnerability validation, exploitation, privilege escalation, lateral movement, and post-exploitation testing as appropriate
- Conduct onsite testing, technical validation, and evidence collection at client facilities when required
- Identify realistic attack paths and explain how individual weaknesses can impact business operations
- Plan and facilitate cybersecurity tabletop, red-team, purple-team, and adversary simulation exercises
- Contribute technical expertise to scenarios covering attacker behavior, detection, response, containment, recovery, and business disruption
- Support cybersecurity framework and control reviews, including NIST CSF, CIS Controls, and similar standards
- Assist with vendor security reviews, technical documentation reviews, and third-party risk activities
- Develop clear findings with supporting evidence, affected assets, risk, technical context, and practical remediation guidance
- Prepare technical reports, project summaries, and executive-level updates for different audiences
- Present findings and recommendations to technical teams, security leadership, and other stakeholders when needed
- Coordinate with system owners, administrators, vendors, and client contacts to clarify findings and support remediation planning
- Maintain organized project notes, evidence, timelines, and engagement documentation
- Support CISO/vCISO advisory and cybersecurity program activities as client needs evolve
- Follow established testing boundaries, data-handling requirements, and escalation procedures
Requirements
- Approximately 3 to 5 years of professional experience in cybersecurity consulting, security assessments, vulnerability management, penetration testing, security operations, governance, risk, compliance, or a closely related area
- Strong technical foundation across networking, operating systems, identity and access management, common enterprise services, and security controls
- Hands-on experience across multiple areas such as security assessments, vulnerability management, remediation, penetration testing, control validation, incident response, or security program support
- Practical experience conducting or supporting authorized penetration tests or offensive security assessments
- Ability to review and interpret vulnerabilities, scanner results, logs, system configurations, network diagrams, policies, and other technical evidence
- Experience evaluating security findings, determining practical risk, and developing clear remediation recommendations
- Familiarity with common security tools and platforms including vulnerability scanners, SIEM solutions, endpoint security tools, firewalls, network analysis tools, and penetration testing tools
- Working knowledge of Windows, Linux, and Active Directory in enterprise IT environments
- Ability to independently complete substantial portions of assigned projects once objectives, scope, and expectations are established
- Ability to research unfamiliar technologies, security issues, frameworks, and client environments
- Strong written and verbal communication skills for documenting findings and explaining technical issues clearly
- Ability to manage multiple projects, competing priorities, and changing client needs in a consulting environment
- Strong judgment around sensitive information, testing boundaries, operational risk, and escalation
- Self-motivated and adaptable, contributing across technical and non-technical cybersecurity projects
- Must currently reside in Hawaii, be authorized to work in the United States, and be able to travel to client locations within Hawaii for onsite project activities
Technologies
- NIST CSF, CIS Controls, NIST SP 800-53
- ISO 27001
- MITRE ATT&CK, PTES, OWASP
- Windows, Linux, Active Directory
- SIEM solutions, endpoint security tools, firewalls, network analysis tools, penetration testing tools
- Python, PowerShell, Bash
- CrowdStrike, Microsoft Defender, vulnerability management platforms
Benefits
- 401(k)
- Dental insurance
- Health insurance
- Paid time off
- Vision insurance
- Flexible schedule
- Life insurance
Location and Employment
- Location: Hybrid remote in Honolulu, HI, with onsite work at client locations as required
- Address: Honolulu, HI 96816 (Required)
- Job type: Full-time
- Salary: USD 80,000 - 100,000 per year (depending on experience and technical capabilities)