Logo for hatch I.T.

Information Security Consultant

Role overview

Qualifications

  • Approximately 3–5 years of relevant experience in cybersecurity, GRC, risk, compliance, audit, or information security
  • Meaningful hands-on experience with at least one regulatory framework (e.g., NIST 800-53, HIPAA, PCI DSS), with working familiarity in others
  • Strong working knowledge of NIST 800-53, with specific familiarity across the AC, IA, CM, SI, SC, AU, SA, and AT control families
  • Demonstrated experience updating or helping develop GRC deliverables (policies, procedures, standards, BIA, IR/DR docs, SSPs, VM plans, TPRM documentation)

Responsibilities

  • Perform assigned GRC service and planning tasks under the direction of a Senior VISO or GRC Director
  • Support security assessments and identify risks, issues, and basic remediation activities under supervision
  • Maintain, update, and support development of core deliverables: policies, procedures, standards, BIA documentation, incident response and disaster recovery documentation, system security plans, vulnerability management plans, and third-party risk documentation
  • Facilitate client meetings, track follow-up items, and communicate clearly and professionally with clients and Assura colleagues

Key facts

  • Remote from: United States
  • Freelance
  • Information Security Analyst
  • English

Hard skills

Other skills

  • Communication
  • Problem Solving

About the company

hatch I.T. logo

hatch I.T.

Staffing & Recruiting

We are a specialty recruiting partner that scales engineering, product, and data teams for innovative and mission-driven technology startups and small businesses. Our flagship program, Scale is a customized Recruitment Process Outsourcing (RPO) hiring solution made for startup tech teams. We also offer Contract-To-Hire and Contingency Hiring, to support the needs of startups at every stage of growth. If you’re a startup or small business looking to grow your technical team, connect with hatch I.T. today: https://www.hatchit.io/hire/

Company details

Company typeTPE
IndustryStaffing & Recruiting
Company size11 - 50

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

hatch I.T. is partnering with Assura to find a Virtual Information Security Officer (VISO). Details below:   About the Role The Virtual Information Security Officer (VISO) is an analyst-level GRC consulting role delivering day-to-day security program work for Assura clients under the direction of a Senior VISO or GRC Director. This is not a strategic ownership role — it's a delivery role. You'll execute assigned service and planning tasks, support assessments and documentation, maintain professional client communication, and follow through on instructions reliably, while building toward greater responsibility over time.   About the Company Assura is a cybersecurity firm with nearly 20 years of singular focus on information security. They work primarily with state, local, and education (SLED) organizations that need real world, practical security leadership — not checkbox compliance or theoretical frameworks. Their team is made up of career cybersecurity practitioners, not career consultants. They take the work seriously, but not themselves. People stay here because they're supported, trusted, and given room to grow.
Responsibilities:
  • Perform assigned GRC service and planning tasks under the direction of a Senior VISO or GRC Director
  • Support security assessments and identify risks, issues, and basic remediation activities under supervision
  • Maintain, update, and support development of core deliverables: policies, procedures, standards, BIA documentation, incident response and disaster recovery documentation, system security plans, vulnerability management plans, and third-party risk documentation
  • Facilitate client meetings, track follow-up items, and communicate clearly and professionally with clients and Assura colleagues
  • Interact directly with clients (once trained) without requiring constant senior intervention
  • Support audit and compliance activities — preparing compliant documentation, participating in audit defense as directed, and helping develop remediation plans under leadership direction
  • Customize and deliver client security awareness training within established parameters (e.g., KnowBe4)
  • Manage deadlines and quality expectations, including adherence to review steps such as Second Set of Eyes
  • Conduct independent research and analysis to close gaps or answer questions before escalating

  • Qualifications:
  • Approximately 3–5 years of relevant experience in cybersecurity, GRC, risk, compliance, audit, or information security
  • Meaningful hands-on experience with at least one regulatory framework (e.g., NIST 800-53, HIPAA, PCI DSS), with working familiarity in others
  • Strong working knowledge of NIST 800-53, with specific familiarity across the AC, IA, CM, SI, SC, AU, SA, and AT control families
  • Demonstrated experience updating or helping develop GRC deliverables (policies, procedures, standards, BIA, IR/DR docs, SSPs, VM plans, TPRM documentation)
  • Ability to take direction from senior staff and reliably carry instructions through to completion
  • Strong writing, documentation, and client communication skills
  • Intellectual curiosity and the ability to research and problem-solve independently when gaps arise

  • Preferred Skills:
  • Familiarity with SEC530 and Virginia public-sector compliance expectations
  • Foundational understanding of how functions like IT, HR, and Finance intersect with security planning and documentation
  • Prior audit support experience beyond evidence collection (planning, remediation, documentation ownership)
  • Comfort with client-facing meetings and stakeholder communication
  • Equal Opportunity Statement Assura is committed to diversity and inclusivity in the workplace.

    Apply once. Then go straight to the hiring manager.

    After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

    MR

    Marcus Rivera

    Chief Revenue Officer

    m.rivera@company.com
    linkedin.com/in/marcusrivera
    Unlocked after you apply
    ·

    Information Security Analyst Related jobs

    Other jobs at hatch I.T.

    Premium

    Reach out to the hiring manager directly.

    Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

    • Full match report with fit score and gaps
    • Career diagnostics on how recruiters read you
    • Curated company matches and warm intros
    • 48h early access to new roles

    Cancel anytime.