What You'll Do Lead projects, teams, and client relationships across compliance and assessment engagements (SOC reporting, PCI, HIPAA, ISO 27001, NIST 800-53/171, HITRUST, vendor privacy assurance, GDPR, and other risk-based work) Plan, execute, and close cybersecurity assessment and compliance projects tailored to each engagement's scope Own a book of business with multiple concurrent projects, including scheduling and administration Draft and review audit reports describing procedures performed, testing results, control weaknesses, and risk exposure Document and test client information systems; recommend improvements to technology and infrastructure Verify that applications, infrastructure, and controls operate as intended Perform risk-based integrated reviews of financial, operational, systems, and management controls Build and maintain strong client and team relationships; support retention on both sides Coach, train, and develop junior staff; foster a collaborative team environment Perform detailed reviews of workpapers, reports, and proposals to ensure quality deliverables Execute hands-on technical work in complex areas when needed Travel to client sites as needed Required Qualifications Bachelor's in MIS, Cybersecurity, Accounting, Finance, or related field At least one of: CPA, CISA, or CISSP 4+ years in cybersecurity compliance, security assessment, or architecture design/review 2+ years of professional services experience at the senior level 1–3 years of supervisory/management experience Executive presence, strong writing and technical skills, and proven ability to mentor others Track record of delivering engagements on time and on budget Preferred Qualifications MBA or MS Willingness to pursue additional certifications (CISM, ISO 27001 LA, PCI QSA, HITRUST CCSFP, etc.) Working knowledge of multiple security frameworks, application controls, and the SDLC Entrepreneurial, client-centric mindset; works well independently and on teams Extensive completed engagement history (25+ professional services projects preferred) Determining compensation for this role (and others) at Vaco/Highspring depends upon a wide array of factors including but not limited to the individual’s skill sets, experience and training, licensure and certifications, office location and other geographic considerations, as well as other business and organizational needs. Determining compensation for this role (and others) at Vaco by Highspring depends upon a wide array of factors including but not limited to: the individual’s skill sets, experience and training; licensure and certification requirements; office location and other geographic considerations; other business and organizational needs.