Senior Consultant- CyberSecurity
Job Description
Sia’s Cybersecurity & AI Trust team within the Global Business Line is hiring a Senior Consultant to support end-to-end cybersecurity consulting engagements. This role spans strategy and risk through compliance, operations, data protection, offensive security, resilience, and training, while also contributing to internal initiatives and the firm’s visibility in the cybersecurity community.
Based in New York, NY with a hybrid work model, you will manage complex engagements, build trusted client relationships, and help develop both deliverables and consulting teams across projects.
What you will do
- Manage end-to-end cybersecurity projects, or be responsible for sub-projects within complex and/or international engagements, including proactive and regular reporting to the Manager and Client to ensure commitments are met.
- Support business development by contributing to commercial proposal design and development, and by identifying new opportunities and clients.
- Own client relationship management across your engagements and build strong connections with client-side contacts who view you as an expert in your assigned tasks.
- Manage consultants in project or internal project settings, serving as a liaison for the Manager/Senior Manager on project follow-ups, deliverable validation, achievement evaluation, and the development of consultants’ soft and technical skills.
- Contribute to internal cybersecurity initiatives, including Learning and Development, Squads, Lunch and Learns, Cyber Events, and related programs.
- Strengthen the firm’s eminence through contributions to a publication plan (articles, white papers, studies, webinars, etc.) and by representing the firm at professional clubs, trade shows, and events.
Engagement focus
- Work on one or more of the following offers: Strategy, Risk, Compliance, Operations, Data Protection, Offensive Security, Resilience, and Training.
Requirements
- Graduation with a Cybersecurity degree or related field from an accredited college or university, plus at least 3 years of experience with a consulting firm or a cybersecurity solutions/service provider/integrator.
- Strong command of cybersecurity standards, norms, and/or market reference systems, including ISO 270xx, NIST, NYDFS, and FFIEC.
- Active participation in successful projects/missions, building solid knowledge across at least two of the 8 offerings listed in the job description.
- Strong communication, critical thinking, writing, and presentation skills.
- General knowledge of IP networks, operating systems (Unix/Linux, Windows, and/or MacOs), Cloud (AWS, Azure, and/or GCP), applications (Web Server, DB, Middleware, etc.), and cryptography. Knowledge in Blockchain is a plus.
- Familiarity with major market solutions and technologies including: Endpoint Security, VPN, VSX, Proxy/Reverse Proxy, EDR, IAM, MDM, DLP, CASB, and Office 365 Security.
- Holds or is willing to obtain industry or cybersecurity certifications.
Technologies (examples)
- ISO 270xx, NIST, NYDFS, FFIEC; Unix/Linux, Windows, MacOs; AWS, Azure, GCP; Web Server, DB, Middleware; cryptography; Blockchain.
- Endpoint Security, VPN, VSX, Proxy/Reverse Proxy, EDR, IAM, MDM, DLP, CASB, Office 365 Security.
- Certifications listed include CISSP, Security+, OSCE, OSEE, OSCP, OSWE, CCSP, SSCP, CSSLP, HCISPP, CISM, C-CISO, CISA, SANS SECXXX, CEH, LTP, GCIH, GCFA, GPEN, GXPN, GWAPT, GCFE, GCIA.
- Additional references include ISO 27001 LI/LA, ISO 27005 RM, ISO 22301 LI/LA, AWS Certified Security, and M-AZ 500 Preferred.
Compensation & benefits
- Base salary: USD 130,600 - 135,700 per year.
- Actual compensation within this range is determined based on experience, qualifications, geographic location, and other job-related factors permitted by applicable law.
- Medical, dental, and vision coverage.
- Company-paid life and AD&D insurance; voluntary supplemental insurance and EAP at no cost.
- 401(k) with company match and immediate vesting; HSA and FSA.
- College savings and student loan repayment programs.
- Paid parental leave.
- Generous PTO, nine company holidays, and one floating holiday.
- Monthly cell phone stipend.
- Well-being and professional development programs.
- Annual Performance Bonus (appraisal).
Workplace and authorization
- Sia uses a flexible workplace model balancing autonomy with in-person connection.
- Management is expected to be in the office at least three days per week to mentor teams, strengthen client relationships, and lead by example.
- Applicants must be legally authorized to work in the United States at the time of application and throughout employment.
- This position is not eligible for employment visa sponsorship now or in the future.
Equal opportunity and certification exception
- Sia is an equal opportunity employer, and employment decisions are based solely on performance, competence, conduct, or business needs.
- An exception will be made for high potential profiles who do not have the listed certifications.
- Those profiles will join the internal Cyber Training program within the Sia Cyber Institute to prepare for cybersecurity certifications.