Senior Consultant - Cybersecurity Consultant
Listed on 2025-12-18
-
IT/Tech
Cybersecurity, IT Consultant
Senior Consultant - Cybersecurity Consultant
Job Category:
Professional
Requisition Number: SENIO
001171
Posted:
December 4, 2025
Full-Time
On-site
LocationsShowing 1 location
Albany office, 540 Broadway, 3rd Floor, Albany, NY 12207, USA
- Pay or shift range: $84,497 USD to $109,846 USD
This is the target base salary range for this position. When determining compensation, we analyze and carefully consider several factors, including skill set, experience, location, and job-related qualifications.
DescriptionAbout Us:
NYSTEC is a nonprofit technology consulting company, advising agencies, organizations, institutions, and businesses since 1996. We’re independent and vendor-neutral, so we have our clients’ best interests NYSTEC, we know that we succeed when individuals and teams flourish personally and professionally, so our benefits and perks support that mindset.
About the Role:As a senior consultant on the Cybersecurity and Data Privacy team, you will collaborate with team members to support our clients as you expand your knowledge related to assessing and securing cloud-based solutions, application protocol interfaces (APIs) and artificial intelligence (AI) technologies.
NYSTEC is considered a trusted advisor, providing cybersecurity subject matter expertise and program operations support for our clients. Your day-to-day role as a NYSTEC consultant will involve providing support for our client’s security program.
Our client’s security program oversees vendor- and data-consuming-entity security compliance, including security control analysis. Cybersecurity team members also support security program elements, such as incident response, vulnerability management, and anti-phishing efforts.
This position is expected to be performed on-site in Albany, NY.
Key Responsibilities:- Integrating identity and access management, such as NY.Gov , into client system initiatives.
- Preparing and delivering summaries, reports, and presentations to communicate complex technical security and privacy information, and make actionable recommendations to both technical and nontechnical stakeholders.
- Assisting with developing and maturing API and AI security standards.
- Coordinating with the web and application security testing team.
- Ensuring regulatory compliance with the Health Insurance Portability and Accountability Act (HIPAA), Centers for Medicare & Medicaid Services (CMS) Acceptable Risk Safeguards (ARS), New York State standards and policies, and National Institute of Standards and Technology (NIST) Special Publication 800-53.
- Conducting security compliance assessments.
- Preparing security documentation and policies.
- Supporting audits and CMS reviews.
Required Qualifications
- Excellent work ethic, critical thinking, analytic, and problem-solving skills.
- Clear and concise written and verbal communication skills.
- Diplomacy and stakeholder relationship development and management skills.
- Sound operational technical background.
- Knowledge of, and experience with, implementing NIST 800-53 controls and an understanding of the IT security processes behind those controls.
- Ability to assess IT risk in a client’s environment and a desire to learn NIST 800-30 style risk assessments.
- Security certification from an accredited organization, such as ISC
2.
- Skills across multiple security domains.
- Experience with privacy programs, requirements, and controls.
- Knowledge of the New York State Medicaid program, its systems, data, and uses.
- Expertise in public health, health information, or security and privacy policies and standards, such as NIST 800-53 and CMS ARS.
- Expertise with identity and access systems and modern protocols, such as Security Assertion Markup Language (SAML), Open Authorization (OAuth), OpenID Connect, multi-factor authentication (MFA), etc.
- Experience with vulnerability assessments of cloud services and infrastructure.
- Familiarity with the secure software development life cycle (SSDLC) and technologies and the causes of vulnerabilities
- Ability to articulate risk and mitigation strategies to clients in written and verbal communications.
- A background in software development or system administration.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).