Key Responsibilities
- Must excel in communication, and demonstrate the ability to explain technical security concepts to a non-technical audience.
- Captures client-specific details to ensure alignment and quality in service delivery.
- Understands and applies technical engineering processes and links to sales concepts and processes to satisfy client and prospect needs.
- Demonstrates, where appropriate, the processes and outcomes involved with solutions and services to show the client/prospect clear value.
- Prepares appropriate proposal and project documentation necessary to accurately scope solutions and services.
Skills Knowledge and Expertise
- 5+ years of relevant cybersecurity experience and solution engineering experience.
- Fluency in security frameworks such as NIST 800-171, 800-53, CSF, ISO 27000, CIS Critical Security Controls.
- Experience implementing security programs aligned with regulations and standards such as GLBA Safeguards Rule, HIPAA Security Rule, ISO27K, PCI DSS, SOC2, FISMA, etc.
- Experience scoping cybersecurity assessments such as risk assessment, vulnerability assessment, and penetration tests.
- Highly skilled in presenting complex customer solutions.
- Expertise in leading RFP responses and preparing/delivering complex client proposals
- 5+ years supporting, delivering, or designing enterprise IT systems, security focused systems OR as a technical lead for an internal Information Security program desired
- Technical experience in Networking, Security, Identity Management, Cloud Services, and Windows/Linux/Mac, TCP/IP, LAN/WAN
- Knowledge of security ecosystem - such as EDR, SIEM., SOAR, Firewalls, VPNs, DNS, vulnerability management, asset management, threat hunting solutions and applications (Where they fit in, what they do, what logs they create, how organizations use them, etc.)
Certifications (a plus): CISSP, CGRC, GRCP, CRISC, CISA,CISM, CGEIT, OSCP or other relevant certifications preferred.
Certified Information Systems Security Professional (CISSP)
Certified in Governance, Risk, and Compliance (CGRC)
GRC Professional Certification (GRCP)
Certified in Risk and Information Systems Control (CRISC)
Certified Information Systems Auditor (CISA)
Certified Information Security Manager (CISM)
Certified in the Governance of Enterprise IT (CGEIT)
OffSec Certified Professional (OSCP)
Why DeepSeas?
- We are client obsessed.
- We stand in solidarity with our teammates.
- We prioritize personal health and well-being.
- We believe in the power of diversity.
- We solve hard problems at the speed of cyber.
Information security is everyone’s responsibility:
- Understanding and following DeepSeas’s information security policies and procedures.
- Remaining vigilant and reporting any suspicious activity or possible weaknesses in DeepSeas’s information security.
- Actively participating in DeepSeas’s efforts to maintain and improve information security.
- DeepSeas considers this position is as Moderate Risk with a potential to view/access/download restricted/private client/internal data. This information must be treated with sensitivity and in the most secure manner.
- HR reserves the right to perform random background/drug screens to ensure the safety of client/DeepSeas data
