- Workplace
- Remote
- Type
- Full-time
- Department
- Legal
- Seniority
- Manager
- Closing date
- Today
- Source
- ApplyToJob
Description
WHO WE ARE
Prowess Consulting is a consulting firm that specializes in helping the largest enterprises in the technology industry define, manage, benchmark, and market their solutions and services. We take great pride in investing the time and effort to gain a deep understanding of our clients’ technologies, their customers, and the stories and strategies they need to tell to be successful in the market. Our team of technology and marketing experts is immersed in the technology trends that affect our clients’ businesses, so we can add value at every stage of engagement to help them succeed.
WHO YOU ARE
Prowess Consulting is looking for a Security Compliance Project Manager who has experience doing security assessments for engineering groups.
To be considered for this role, you must reside in one of the following states: Alabama, California, Colorado, Georgia, Iowa, Maryland, Michigan, Minnesota, Mississippi, Missouri, New Jersey, New York, North Carolina, Oregon, Pennsylvania, South Carolina, Texas, Utah, Virginia, or Washington.
This is a full-time role that can be worked remotely, however, collaboration with teammates centered in the Pacific time zone will be essential. No third-party agencies, please.
THE ROLE
QUALIFICATIONS
Prowess Consulting is a consulting firm that specializes in helping the largest enterprises in the technology industry define, manage, benchmark, and market their solutions and services. We take great pride in investing the time and effort to gain a deep understanding of our clients’ technologies, their customers, and the stories and strategies they need to tell to be successful in the market. Our team of technology and marketing experts is immersed in the technology trends that affect our clients’ businesses, so we can add value at every stage of engagement to help them succeed.
WHO YOU ARE
Prowess Consulting is looking for a Security Compliance Project Manager who has experience doing security assessments for engineering groups.
To be considered for this role, you must reside in one of the following states: Alabama, California, Colorado, Georgia, Iowa, Maryland, Michigan, Minnesota, Mississippi, Missouri, New Jersey, New York, North Carolina, Oregon, Pennsylvania, South Carolina, Texas, Utah, Virginia, or Washington.
This is a full-time role that can be worked remotely, however, collaboration with teammates centered in the Pacific time zone will be essential. No third-party agencies, please.
THE ROLE
- Drive end to end execution of security assessments that include:
- Creating assessment questionnaires
- Conduct kickoffs, review assessment responses, and identify risks/control gaps from a risk management perspective
- Perform risk scoring exercise and maintain risks in the risk register
- Track implementation (and adherence) of security requirements across engineering groups/teams
- Collaborate with partner teams to build continuous monitoring capabilities/reports for security requirements
- Validate compliance to security requirements and drive compliance sign off process for upcoming releases
- Coordinate with partner teams on security scope and finalize implementation requirements
- Support strategy and roadmap development for existing and emerging cybersecurity certification and/or regulatory requirements for internal/external audit needs
- Support risk management process enhancements
- Support the development and ongoing maintenance of Standard Operating Procedures (SOPs)
- Work with assigned groups to ensure security compliance
- Create and maintain risk dashboards using Power BI or similar tools and report to leadership
- Socialize risks/control gaps with service owners
- Support certification and audit preparation efforts for internal and external regulatory requirements.
- Drive execution of Security Compliance frameworks (NIST, SDLC, etc.)
- Partner with Windows engineering teams to review feature designs and system changes (e.g., identity, credential storage, telemetry/logging, update mechanisms) for regulatory impact and required compliance controls
- Translate Cyber EO / CRA requirements into implementable control requirements, test procedures, and release gates; define clear evidence expectations (e.g., design artifacts, configurations, build/release attestations, vulnerability handling records)
- Validate compliance using technical evidence and telemetry (e.g., policy/config exports, audit logs, vulnerability scan results, update/patch metrics) and drive remediation plans with engineering owners
QUALIFICATIONS
- 5+ years of Program Management experience necessary
- Strong interpersonal and written communication skills
- Demonstrated ability to own and drive programs and initiatives by working through ambiguity
- Familiarity with cybersecurity, risk management and audit best practices desirable
- Strong understanding of security and supply chain concepts, standards, and control frameworks
- Strong understanding of regulatory frameworks and the ability to interpret requirements into actionable workstreams
- Good track record of working collaboratively and effectively with senior leaders and teams across organizational boundaries
- Experience influencing others without authority
- Experience building PowerBI dashboards or producing dashboard specifications
- Experience using tools to manage compliance and evidence (e.g., control tracking, audit readiness, risk registers), plus engineering workflow tools (ADO) and security/compliance signals (e.g., vulnerability scanning findings, SBOM outputs) are desired
- Must have stellar organizational skills and be able to work well with multiple technical groups and stakeholders in multiple areas
- Strong understanding of enterprise/on-prem Windows security fundamentals, such as Active Directory, authentication/authorization concepts, Group Policy, credential hygiene, hardening baselines, and security logging/auditing
- Experience operating vulnerability management and coordinated disclosure processes, including intake/triage, severity scoring (e.g., CVSS), remediation SLAs, exception handling, and reporting/notification obligations
- Software supply chain & secure development knowledge (aligned to NIST SSDF concepts), including build integrity, dependency management, SBOMs (SPDX/CycloneDX), code signing, and release/change control
- Ability to work with compliance tooling and evidence workflows (GRC/control libraries, automated evidence collection, audit trails) and integrate with engineering systems (ADO/Jira, CI/CD, ticketing)
- Data/analytics skills to build continuous monitoring and compliance reporting (Power BI or similar; ability to work with log/metric sources and perform basic querying to validate control health)
- The offered pay range for this position is $95,000 105,000 per year depending on experience.
Skills
CI/CDJiraPower BICybersecurityRisk ManagementComplianceProgram Management