- Workplace
- Remote
- Experience
- 10+ years
- Education
- Bachelor
- Source
- ApplicantStack
Description
Sr. Cybersecurity Consultant
Excentium, Inc. is a Service-Disabled Veteran-Owned Small Business (SDVOSB) that provides Cybersecurity Consulting and Advisory, Assessment, and other IT services to government and commercial organizations. Excentium is an accredited FedRAMP Independent Assessor (IAS), formerly known as a Third-Party Assessment Organization (3PAO).
We have an opportunity for a Senior Cybersecurity Consultant to join our growing Cybersecurity Professional Services (CPS) practice. CPS delivers cybersecurity consulting and advisory, and assessment services to commercial companies that deliver capability to the government, helping clients build, mature, and sustain compliant, risk-informed security programs.
MINIMUM CLEARANCE LEVEL:
Public Trust
CITIZENSHIP:
US Citizenship
LOCATION:
Remote
Position Description:
The Senior Cybersecurity Consultant will serve as a trusted advisor to client leadership, providing hands-on guidance across governance, risk, and compliance (GRC); security assessment and authorization; and enterprise security program development. This role will lead client engagements spanning gap assessments, control implementation support, and compliance readiness against frameworks such as NIST SP 800-53, NIST SP 800-171, CMMC, ISO 27001/9001/20000-1, and FedRAMP, as well as support for Authority to Operate (ATO) preparation.
The consultant will develop and present assessment findings, risk register updates, remediation roadmaps, and executive-level briefings to client stakeholders, while helping shape the internal methodologies, templates, and playbooks that scale across the practice. Will serve as a principal point of contact between assigned clients and Excentium for CPS engagements, demonstrating strong written and oral communication skills and sound judgment in balancing security requirements against client operations and business risk.
Excentium is a small but growing company, and this role is expected to grow with it. As the CPS practice expands, this individual will be expected to take on increasing leadership responsibility — mentoring junior consultants, overseeing engagement quality, contributing to business development and proposal efforts, and helping define the practice's service offerings and delivery standards.
Excentium is also developing a cloud-based compliance platform designed to help organizations meet CMMC and FedRAMP 20x requirements. This individual may support the platform's development and cloud deployments — contributing security engineering, cloud architecture, and compliance-automation expertise alongside the development team, and helping validate the platform's own security posture as it matures. This is expected to be a growing part of the role over time and offers the opportunity to help shape a new product line at Excentium.
Position Requirements:
Has extensive experience providing cybersecurity consulting, advisory, or vCISO-type services to commercial or government clients, with a strong understanding of governance, risk, and compliance (GRC) frameworks and the ability to translate technical risk into business terms for executive audiences.
- Demonstrated experience with Risk Management Framework (RMF) and applicable regulations, including NIST SP 800-37, NIST SP 800-53 or 800-53A, NIST SP 800-171, or CNSSI 1253, and experience developing or reviewing SSPs, SARs, RARs, and POA&Ms.
- Experience supporting CMMC readiness or assessment activities, including practice implementation, gap analysis, and preparation for C3PAO assessment.
- Experience supporting ISO management system implementation, maintenance, or audit readiness (e.g., ISO 27001, 9001, 20000-1).
- Familiarity with cloud security and authorization processes (AWS, Azure, M365 / Entra ID) and experience supporting FedRAMP authorization activities.
- Experience conducting or overseeing vulnerability and risk assessments, and delivering actionable, prioritized remediation recommendations to clients.
- Ability to independently manage client relationships and serve as the principal liaison between the customer and supporting personnel for assigned engagements.
- Cloud security engineering experience in AWS and/or Azure, including hardening cloud infrastructure, securing CI/CD pipelines, and applying Infrastructure-as-Code (e.g., Terraform, CloudFormation) is a plus, and directly relevant to supporting the development and secure deployment of Excentium's compliance automation platform.
- Exposure to DevSecOps practices and scripting/automation (PowerShell, Python, or similar) for compliance control implementation, validation, and continuous monitoring is a plus.
- Interest or experience supporting a SaaS or cloud product build, and familiarity with FedRAMP 20x and emerging automated authorization frameworks, is a plus.
Educational Requirements/Qualifications:
- Bachelor's degree in Information Technology, Information Assurance and Security, Computer Science, Information Systems, or a related field (equivalent experience considered).
- 10+ years of experience working in cybersecurity.
- One or more of the following certifications: CISSP, CISM, or a CMMC certification (CCP or CCA).
Desired Certifications:
- CMMC Lead CCA
- Security+ CE
- CCSK or CCZT (Cloud Security Alliance)
- Certified Ethical Hacker (CEH)
- AWS Certified Security – Specialty and/or Microsoft Certified: Azure Security Engineer Associate
We take pride in building a workforce with a strong Veterans focus.
Excentium offers a competitive salary and comprehensive benefits package, including medical, dental, life, disability, 401k, and paid time off.
Excentium, Inc. is an equal opportunity employer.