Role Description
The Senior Security Consultant, US Privacy & Assurance is responsible for helping clients identify, manage, and reduce cybersecurity, privacy, and regulatory risk through advisory, assessment, and assurance services. The role provides expert guidance on US privacy regulations, healthcare and financial services requirements, security frameworks, and risk management practices, enabling organizations to protect sensitive information, strengthen governance, and demonstrate compliance with evolving legal and regulatory obligations.
The Senior Security Consultant is expected to have deep experience conducting privacy-focused assessments that help organizations understand and manage privacy risk in increasingly complex regulatory environments. This includes:
-
Leading Privacy Impact Assessments (PIAs) and privacy risk assessments.
-
Developing and validating data flow maps to identify how personal information is collected, used, shared, stored, and retained.
-
Evaluating compliance with evolving US privacy requirements.
The role requires a strong understanding of privacy-intensive state regulations, including CCPA/CPRA and other emerging state privacy laws, and the ability to translate regulatory obligations into practical business and technical controls.
Additionally, the Senior Security Consultant delivers privacy assessments, security and compliance reviews, risk assessments, and assurance engagements across frameworks and regulations such as:
-
CCPA
-
CMS
-
HIPAA
-
HITRUST
-
NIST
-
NYDFS
This position plays a key role in supporting NCC Group's mission to create a more secure digital future.
Key Responsibilities
-
Lead and deliver client engagements across privacy, cybersecurity, risk, and assurance domains.
-
Provide subject matter expertise on US privacy regulations and data protection requirements.
-
Deliver assurance and compliance engagements against industry standards and regulatory frameworks.
-
Support business development activities by assisting with scoping, planning, and estimation.
-
Contribute to proposals, statements of work (SOWs), client presentations, and solution development.
-
Support the development and enhancement of NCC Group's US privacy consulting offerings.
-
Advise clients on the design, implementation, and improvement of privacy and security programs.
-
Develop and maintain trusted client relationships.
-
Mentor and support junior consultants and team members.
-
Produce high-quality client deliverables.
-
Collaborate with multidisciplinary teams to deliver integrated solutions.
-
Maintain current knowledge of evolving privacy, cybersecurity, and regulatory requirements.
-
Travel occasionally to client locations for assessments and other engagement-related activities.
Qualifications
-
Practical experience delivering privacy, cybersecurity, risk, and assurance consulting engagements.
-
Experience assessing, implementing, or advising on privacy and security programs.
-
Knowledge of US privacy laws and regulations, including CCPA/CPRA.
-
Experience conducting privacy, cybersecurity, and compliance assessments against recognized frameworks.
-
Experience performing risk assessments and developing risk treatment plans.
-
Experience producing clear reports, presentations, and recommendations.
-
Experience coordinating with legal, compliance, privacy, security, and technology teams.
Skills & Behaviours
-
Ability to analyze complex regulatory, privacy, and cybersecurity requirements.
-
Strong problem-solving and critical-thinking skills.
-
Ability to manage multiple engagements and priorities.
-
Ability to present complex information clearly to various audiences.
-
Strong stakeholder management and relationship-building skills.
-
Ability to mentor and support the development of consultants.
-
Adaptability and willingness to learn emerging requirements.
-
Strong project planning and organizational skills.
Certifications
-
Certified Information Privacy Professional (CIPP/US) (Preferred)
-
Certified Information Privacy Manager (CIPM)
-
Certified Information Systems Security Professional (CISSP)
Benefits
-
Generous annual leave starting at 15 days, increasing to 20 days with service, plus 3 floating days.
-
401(k) with up to 5% company match.
-
Life assurance at 1x your annual salary.
-
Comprehensive health cover including medical, dental, and vision plans.
-
Income protection through short and long term disability cover.
-
Opportunity to invest through SAYE and Employee Stock Purchase Plan.