NCC Group Logo

NCC Group

Senior Security Consultant - Privacy and Assurance

Posted Yesterday
Be an Early Applicant
Remote or Hybrid
Hiring Remotely in Eastern, KY
Senior level
Remote or Hybrid
Hiring Remotely in Eastern, KY
Senior level
Leads client consulting engagements covering privacy, cybersecurity, risk, compliance, and assurance. Conducts Privacy Impact Assessments, data flow reviews, regulatory assessments, and framework-based reviews involving CCPA/CPRA, HIPAA, HITRUST, NIST, NYDFS, CIS Controls, and ISO 27001. Advises clients on privacy and security program improvements, develops reports and remediation roadmaps, supports business development, mentors junior consultants, maintains client relationships, and contributes to privacy consulting methodologies. Occasional travel to client locations is required.
The summary above was generated by AI
The Senior Security Consultant, US Privacy & Assurance is responsible for helping clients identify, manage, and reduce cybersecurity, privacy, and regulatory risk through advisory, assessment, and assurance services. The role provides expert guidance on US privacy regulations, healthcare and financial services requirements, security frameworks, and risk management practices, enabling organizations to protect sensitive information, strengthen governance, and demonstrate compliance with evolving legal and regulatory obligations.

The Senior Security Consultant, US Privacy & Assurance is expected to have deep experience conducting privacy-focused assessments that help organizations understand and manage privacy risk in increasingly complex regulatory environments. This includes leading Privacy Impact Assessments (PIAs) and privacy risk assessments, developing and validating data flow maps to identify how personal information is collected, used, shared, stored, and retained, and evaluating compliance with evolving US privacy requirements. The role requires a strong understanding of privacy-intensive state regulations, including CCPA/CPRA and other emerging state privacy laws, and the ability to translate regulatory obligations into practical business and technical controls. Through these assessments, the consultant helps clients strengthen privacy governance, improve transparency, reduce regulatory risk, and build sustainable privacy programs aligned with business objectives and legal requirements.

Additionally, working collaboratively with clients, technical teams, and business stakeholders, the Senior Security Consultant delivers privacy assessments, security and compliance reviews, risk assessments, and assurance engagements across frameworks and regulations such as CCPA, CMS, HIPAA, HITRUST, NIST, NYDFS, and other applicable US privacy and cybersecurity requirements. The role helps organizations build resilient security and privacy programs by translating complex regulatory and technical requirements into practical, business-focused solutions.
This position plays a key role in supporting NCC Group's mission to create a more secure digital future. 

Through trusted client relationships, high-quality project delivery, and thought leadership, the Senior Security Consultant helps clients improve security maturity, manage regulatory risk, and build trust with customers, partners, and regulators. The role contributes directly to client satisfaction, revenue growth, successful engagement delivery, regulatory readiness, and the continued reputation of NCC Group as a trusted cybersecurity and risk management advisor.

Key Responsibilities
Lead and deliver client engagements across privacy, cybersecurity, risk, and assurance domains, ensuring projects are completed on time, within scope, on budget, and to a high standard of quality. This includes privacy assessments, compliance reviews, cybersecurity assessments, risk assessments, and audit support activities aligned to client requirements and regulatory obligations.
Provide subject matter expertise on US privacy regulations and data protection requirements, including CCPA/CPRA and emerging federal and state privacy laws. Monitor regulatory developments, assess their impact on clients, and deliver practical recommendations to help organizations maintain compliance and manage risk.
Deliver assurance and compliance engagements against industry standards and regulatory frameworks, including HITRUST, HIPAA, NYDFS Cybersecurity Regulation, NIST Cybersecurity Framework (CSF), NIST Risk Management Framework (RMF), and related governance, risk, and compliance requirements.
Support business development activities by assisting with the scoping, planning, and estimation of privacy, risk, and assurance engagements. Contribute to proposals, statements of work (SOWs), client presentations, and solution development to ensure client needs are accurately understood and appropriately addressed.
Support the development and enhancement of NCC Group's US privacy consulting offerings, methodologies, templates, accelerators, and intellectual property. Contribute to the growth of privacy services including CCPA/CPRA readiness assessments, privacy program development, data governance, and regulatory compliance offerings.
Advise clients on the design, implementation, and improvement of privacy and security programs, helping organizations establish effective governance, risk management, compliance, and data protection practices.
Develop and maintain trusted client relationships, serving as a strategic advisor throughout engagements. Identify opportunities to expand services, support account growth, and strengthen NCC Group's position as a trusted cybersecurity and privacy partner.
Mentor and support junior consultants and team members by providing coaching, technical guidance, quality reviews, and knowledge sharing to promote professional development and delivery excellence.

Produce high-quality client deliverables
, including assessment reports, risk analyses, audit documentation, executive presentations, remediation roadmaps, and compliance recommendations tailored to both technical and non-technical stakeholders.

Collaborate with multidisciplinary teams
across cybersecurity, privacy, assurance, healthcare, financial services, and risk management practices to deliver integrated solutions that address client and regulatory requirements.
Maintain current knowledge of evolving privacy, cybersecurity, and regulatory requirements, industry trends, emerging threats, and best practices, and apply this knowledge to client engagements, service development, and thought leadership activities.
Travel occasionally to client locations to perform assessments, audits, workshops, stakeholder interviews, and other engagement-related activities as required.

Skills, Knowledge and Expertise
Professional Knowledge & Experience
  • Practical experience delivering privacy, cybersecurity, risk, and assurance consulting engagements for clients across regulated industries.
  • Experience assessing, implementing, or advising on privacy and security programs, including governance, risk management, compliance, and data protection initiatives.
  • Knowledge of US privacy laws and regulations, including CCPA/CPRA and other state privacy requirements, and the ability to interpret regulatory changes and translate them into practical business recommendations.
  • Experience conducting privacy, cybersecurity, and compliance assessments against recognized frameworks and regulations, including: 
    • HITRUST CSF
    • HIPAA
    • NIST Cybersecurity Framework (CSF)
    • NIST SP 800-53
    • NYDFS Cybersecurity Regulation
    • CIS Controls
    • ISO 27001
  • Experience performing risk assessments, developing risk treatment plans, and supporting remediation activities.
  • Experience producing clear reports, presentations, and recommendations for both technical and non-technical stakeholders.
  • Experience coordinating with legal, compliance, privacy, security, and technology teams to achieve client objectives.
Skills & Behaviours
  • Ability to analyze complex regulatory, privacy, and cybersecurity requirements and translate them into actionable business guidance.
  • Strong problem-solving and critical-thinking skills with the ability to assess risk and identify practical solutions.
  • Ability to manage multiple engagements and priorities while maintaining high-quality deliverables.
  • Ability to present complex information clearly to executive, operational, and technical audiences.
  • Strong stakeholder management and relationship-building skills.
  • Ability to mentor and support the development of consultants and other team members.
  • Adaptability and willingness to learn emerging privacy, cybersecurity, and regulatory requirements.
  • Strong project planning and organizational skills.

Certifications
Candidates should hold one or more relevant certifications, such as:
  • Certified Information Privacy Professional (CIPP/US) (Preferred)
  • Certified Information Privacy Manager (CIPM)
  • Certified Information Systems Security Professional (CISSP)

Benefits
We believe great work deserves great support. That’s why we offer a benefits package designed to look after you, your family, and your future.
We Offer
Generous annual leave
  •  Starting at 15 days, increasing to 20 days with service, plus 3 floating days from day one to use at your leisure
Plan for your future
  •  401(k) with up to 5% company match
Life protection for peace of mind
  • Life assurance at 1x your annual salary
Comprehensive health cover
  •  Medical, dental, and vision plans available for you and your family, with flexible options to suit your needs
Financial protection when it matters most
  •  Income protection through short and long term disability cover, plus accidental death and disability insurance
Share in our success
  •  Opportunity to invest through our SAYE and Employee Stock Purchase Plan


About
We assess, develop and manage cyber threats across our increasingly connected society. We advise global technology, manufacturers, financial institutions, critical national infrastructure providers, retailers and governments on the best way to keep businesses, software and personal data safe.With our knowledge, experience and global footprint, we are best placed to help businesses identify, assess, mitigate & respond to the risks they face.We are passionate about making the Internet safer and revolutionising the way in which organisations think about cyber security.Headquartered in Manchester, UK, with over 35 offices across the world, NCC Group employs more than 2,000 people and is a trusted advisor to 15,000 clients worldwide.

NCC Group Boston, Massachusetts, USA Office

76 Summer Street, 4th Floor Boston MA , Boston, United States, 02110

Similar Jobs

An Hour Ago
Remote or Hybrid
USA
145K-220K Annually
Expert/Leader
145K-220K Annually
Expert/Leader
Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
Lead technical marketing for Falcon Secure Access by creating demos, labs, workshops, and technical content that translate secure access, browser security, Zero Trust, and AI security capabilities into market-facing messaging, sales enablement, and go-to-market strategy. Collaborate cross-functionally to drive adoption and competitive differentiation.
Top Skills: AIBrowser ExtensionsBrowser SecurityCasbCrowdstrike FalconFalcon Secure AccessGenaiIdentity-Aware AccessPolicy-Based Access ControlSafe BrowsingSaseSseSwgVdiVpnZero TrustZtna
3 Hours Ago
Remote or Hybrid
United States
85K-143K Annually
Senior level
85K-143K Annually
Senior level
Fintech • Information Technology • Insurance • Financial Services • Big Data Analytics
Manages brand alignment and serves as the liaison between business stakeholders and creative teams. Oversees creative strategy, project scope, planning, execution, budgets, timelines, and delivery across marketing channels. Reviews campaign analytics to identify optimization opportunities, facilitates collaboration, presents work to internal clients, and supports performance marketing initiatives. Requires substantial creative agency experience, project management expertise, and the ability to use AI to improve operational efficiency.
Top Skills: AIFigmaMS OfficeMicrosoft TeamsSharepointWorkfront
3 Hours Ago
Remote or Hybrid
USA
160K-250K Annually
Senior level
160K-250K Annually
Senior level
Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
Design, build, deploy, and scale production AI agents and platforms for legal workflows. Develop and evaluate agent solutions, optimize performance and cost, redesign business processes, and promote responsible AI adoption. Collaborate with Legal, Enterprise AI, Data, Security, Privacy, and Engineering teams to deliver secure, reliable, scalable solutions. Contribute frameworks, training, governance guidance, and innovative applications using modern LLM and AI techniques.
Top Skills: Advanced RetrievalAgent FrameworksAi AgentsAi GatewaysAi/MlAWSFine-TuningGCPKnowledge GraphsLarge Language ModelsModel Context ProtocolModel CustomizationMulti-Agent SystemsMultimodal Document ProcessingPythonSecure Tool IntegrationsSynthetic Data

What you need to know about the Boston Tech Scene

Boston is a powerhouse for technology innovation thanks to world-class research universities like MIT and Harvard and a robust pipeline of venture capital investment. Host to the first telephone call and one of the first general-purpose computers ever put into use, Boston is now a hub for biotechnology, robotics and artificial intelligence — though it’s also home to several B2B software giants. So it’s no surprise that the city consistently ranks among the greatest startup ecosystems in the world.

Key Facts About Boston Tech

  • Number of Tech Workers: 269,000; 9.4% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Thermo Fisher Scientific, Toast, Klaviyo, HubSpot, DraftKings
  • Key Industries: Artificial intelligence, biotechnology, robotics, software, aerospace
  • Funding Landscape: $15.7 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Summit Partners, Volition Capital, Bain Capital Ventures, MassVentures, Highland Capital Partners
  • Research Centers and Universities: MIT, Harvard University, Boston College, Tufts University, Boston University, Northeastern University, Smithsonian Astrophysical Observatory, National Bureau of Economic Research, Broad Institute, Lowell Center for Space Science & Technology, National Emerging Infectious Diseases Laboratories

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account