Get more replies from employers
Send a job-specific resume in minutes.
Avance Consulting is seeking an experienced cybersecurity consultant to lead a NIST CSF 2.0 maturity assessment for a global program. You will plan engagements, engage stakeholders, review controls and evidence, and deliver maturity scoring plus remediation roadmaps.
You will conduct interviews with senior security, risk, and business stakeholders and develop executive-ready reports and dashboards. The role emphasizes governance, client-facing deliverables, and structured methodologies.
Lead the delivery of a NIST CSF 2.0 cybersecurity gap and maturity assessment for a global enterprise program, covering assessment planning, stakeholder engagement, evidence review, maturity scoring, risk based gap prioritization, executive reporting, and development of a practical improvement roadmap.
Own end to end engagement governance, project planning, milestones, risks, dependencies, status reporting, and stakeholder communications.
Conduct NIST CSF 2.0 maturity assessment across functions, categories, subcategories, implementation tiers, and profiles.
Review policies, standards, procedures, controls, risk registers, asset inventories, KPIs/KRIs, and supporting evidence.
Facilitate interviews and workshops with cybersecurity, risk, compliance, technology, and business stakeholders.
Define defensible maturity scoring, identify control gaps, assess business risk, and prioritize remediation actions.
Develop executive ready assessment reports, maturity dashboards, prioritized recommendations, and near/mid/long term roadmap.
10 to 15 years in cybersecurity, GRC, risk management, audit, security consulting, or cybersecurity program assessment.
Strong hands on experience with NIST CSF, preferably NIST CSF 2.0 maturity assessments.
Experience mapping controls across NIST CSF, ISO 27001, NIST 800 53, CIS Controls, SOC 2, or similar frameworks.
Proven experience conducting enterprise wide cybersecurity maturity, gap, risk, or control assessments.
Ability to conduct interviews/workshops with senior security, risk, compliance, technology, and business stakeholders.
Strong experience creating leadership ready cybersecurity reports, maturity dashboards, and roadmap presentations.
Experience working in consulting/advisory environments with structured methodology, governance, and client facing deliverables.
Ability to convert control gaps into risk ranked remediation recommendations and practical roadmaps.
GRC and evidence management platforms such as Archer, ServiceNow GRC, OneTrust, MetricStream, SharePoint, Teams, Excel, PowerPoint, Visio, Power BI, and cybersecurity KPI/KRI dashboarding tools.