Key Responsibilities
- NYDFS Compliance Assessments
- Perform NYDFS cybersecurity regulation assessments and Security Control Assessments
- Evaluate compliance with 23 NYCRR Part 500 requirements.
- Conduct regulatory readiness and examination support reviews.
- Assess control design and operating effectiveness.
- Develop compliance scorecards and maturity assessments.
- Operational NYDFS evidence tracking across in-scope applications (with clear status and aging visibility.
- Validated and organized evidence artifacts maintained in the agreed repository structure and naming convention.
- A prioritized list of out-of-compliance risk assessments and a remediation action plan (where applicable).
- Weekly status update package (progress, blockers, top risks, at-risk items, next steps).
- A documented process improvement plan for the annual NYDFS attestation cycle (templates, cadence, QA checks, escalation path, and metrics).
- Work closely with external application vendor contacts to ensure application compliance and customer's applications / data remain secure.
IT Audit Activities
- Execute risk based IT audits.
- Develop audit plans, audit programs, and test procedures.
- Conduct walkthroughs and control validation.
- Review evidence and perform sample testing.
- Document audit observations and recommendations.
- Prepare audit workpapers and audit report
Client Advisory
- Facilitate stakeholder workshops.
- Present assessment findings to executive leadership.
- Advise CISOs, CIOs, and compliance teams on NYDFS requirements.
- Assist customers in developing target operating models.
- Support cybersecurity program modernization initiatives
Required Sills (Must have)
- Bachelor's degree in Cybersecurity, Information Security, Computer Science, Information Systems, or related field.
- Strong English communication skills (written and verbal); ability to drive follow-ups with business stakeholders and vendor contacts.
- Experience coordinating evidence/artifact collection for audits, attestations, or regulatory requirements.
- Strong organization skills: tracking, repository hygiene, and maintaining audit-ready traceability.
- Ability to validate evidence for completeness and applicability; escalate gaps and drive closure.
- Project management fundamentals (status reporting, issue/risk escalation, etc).
- 5+ years of cybersecurity, risk, or compliance consulting experience.
- Strong understanding of NYDFS Cybersecurity Regulation (23 NYCRR Part 500).
- Experience conducting cybersecurity assessments and regulatory compliance reviews.
- Knowledge of cybersecurity governance and risk management practices.
- Excellent communication and client-facing skills.
Preferred Certifications : CISSP, CISA, CISM, CRISC
Notes:- All qualified applicants will receive consideration for employment without regard to race, color, religion, religious creed, sex, national origin, ancestry, age, physical or mental disability, medical condition, genetic information, military and veteran status, marital status, pregnancy, gender, gender expression, gender identity, sexual orientation, or any other characteristic protected by local law, regulation, or ordinance.
Benefits: Danta offers a compensation package to all W2 employees that are competitive in the industry. It consists of competitive pay, the option to elect healthcare insurance (Dental, Medical, Vision), Major holidays and Paid sick leave as per state law.
The rate/ Salary range is dependent on numerous factors including Qualification, Experience and Location.