TECHNOLOGY & IT
Overview
Our client, a large IT and system integrator, is seeking an experienced Senior Cybersecurity Consultant for its New York operation. This position will serve as a senior advisor to enterprise clients, helping organizations develop cybersecurity strategies, strengthen governance and compliance programs, design modern security architectures, and manage long-term security initiatives. The ideal candidate will have extensive cybersecurity consulting or advisory experience, strong executive-level communication skills, and business-level Japanese proficiency.
Description
Strategic Security Advisory: Lead multi-quarter advisory engagements for strategic client accounts. Develop cybersecurity strategies, governance frameworks, and three-year security program roadmaps aligned with each client's business priorities and risk appetite.
Regulatory and Compliance Readiness: Conduct readiness assessments and gap analyses against major cybersecurity and regulatory frameworks, including NIST CSF 2.0, CRI Profile v2.1, NYDFS Part 500, HIPAA, CMMC, ISO 27001, SOC 2, and related standards. Translate regulatory requirements into practical remediation plans.
Virtual CISO (vCISO) Engagements: Serve as a fractional CISO for organizations without a dedicated security executive. Participate in executive and board-level discussions, advise leadership on risk decisions, and lead annual cybersecurity program reviews.
Security Architecture and Program Design: Define target-state security architectures across identity, network, endpoint, cloud, and data security. Align security architecture with client IT modernization initiatives and managed security solutions.
Incident Response Advisory: Provide strategic guidance following cybersecurity incidents, including root-cause analysis facilitation, executive communications, regulatory notification considerations, and recommendations for security program improvement. Partner with technical incident response teams without directly owning operational response.
Client Relationship Leadership: Build trusted, long-term relationships with senior client stakeholders. Serve as a senior point of contact for strategic accounts and coordinate with sales, pre-sales, delivery, and customer success teams.
Thought Leadership and Practice Development: Contribute to cybersecurity advisory methodologies, service offerings, best practices, and internal intellectual property. Mentor junior consultants and technical professionals.
Global Collaboration: Work closely with U.S. and Japan-based teams to support enterprise clients and strategic cybersecurity initiatives.
Requirements
Required Qualifications
Minimum 10 years of professional experience in cybersecurity, information security, information risk management, or related advisory roles.
At least 5 years of experience in a senior consulting, advisory, or vCISO capacity, preferably within a Big Four firm, cybersecurity consultancy, managed services organization, or enterprise security leadership environment.
Demonstrated experience leading multi-quarter cybersecurity advisory engagements involving executive-level stakeholders, including CIOs, CISOs, boards, and audit committees.
Working knowledge of major cybersecurity and compliance frameworks, including NIST CSF, ISO 27001/27002, CRI Profile, NYDFS Part 500, HIPAA Security Rule, CMMC, and CIS Controls.
Strong technical understanding of modern cybersecurity architecture, including identity and access management (IAM, SSO, MFA), network security (SASE, ZTNA, firewalls), endpoint security (EDR, MDM), cloud security (AWS, Azure, Microsoft 365), and data security (DLP, DSPM, SSPM).
Business-level Japanese proficiency in reading, writing, and speaking is required.
Excellent written and verbal communication skills, including the ability to translate complex technical findings into clear business recommendations for executive audiences.
Bachelor's degree in Computer Science, Information Systems, Engineering, Business, or a related field. Master's degree or MBA preferred.
At least one senior-level cybersecurity certification such as CISSP, CISM, CISA, CRISC, or equivalent.
Compensation
$90,000 - $140,000 annually, depending on experience and qualifications.
Benefits
Medical, dental, and vision coverage
Basic life insurance and AD&D
Short-term and long-term disability insurance
Flexible Spending Account (FSA)
401(k) with company match
Paid Time Off, including vacation, sick leave, and floating holidays
13 paid company holidays
Tuition reimbursement program
Employee Assistance Program (EAP)
Employee wellbeing programs
Company
Large IT and system integrator.
Candidates interested in this opportunity are encouraged to contact MAX Consulting Group, Inc. The full job description provided by the client can be shared with qualified candidates upon request.
Certain company-identifying information has been intentionally omitted from this posting to maintain client confidentiality. Additional details will be shared with qualified candidates during the recruitment process.
シニア・サイバーセキュリティ・コンサルタント
勤務地:New York, NY
雇用形態:正社員
分野:Cybersecurity
経験レベル:Experienced
ポジション概要
大手IT・システムインテグレーターが、ニューヨーク拠点にて経験豊富なシニア・サイバーセキュリティ・コンサルタントを募集しています。
本ポジションでは、企業クライアントに対するシニアアドバイザーとして、サイバーセキュリティ戦略の策定、ガバナンスおよびコンプライアンス体制の強化、最新のセキュリティアーキテクチャ設計、中長期的なセキュリティプログラムの推進を担当します。
サイバーセキュリティ分野での豊富なコンサルティングまたはアドバイザリー経験に加え、経営層との高いコミュニケーション能力、ビジネスレベルの日本語力をお持ちの方を求めています。
主な業務内容
戦略的セキュリティアドバイザリー:
主要クライアントに対する中長期のアドバイザリープロジェクトをリードし、クライアントの事業戦略やリスク方針に沿ったサイバーセキュリティ戦略、ガバナンス体制、3年間のプログラムロードマップを策定します。
規制・コンプライアンス対応:
NIST CSF 2.0、CRI Profile v2.1、NYDFS Part 500、HIPAA、CMMC、ISO 27001、SOC 2などの主要なフレームワークや規制に基づき、現状評価およびギャップ分析を実施します。規制上の要件を具体的な改善計画へ落とし込みます。
Virtual CISO(vCISO)業務:
専任のセキュリティ責任者を持たないクライアントに対し、外部CISOとして経営層や取締役会との協議に参加し、リスク判断の支援や年次セキュリティプログラムレビューを行います。
セキュリティアーキテクチャ・プログラム設計:
ID管理、ネットワーク、エンドポイント、クラウド、データセキュリティ領域における将来のセキュリティアーキテクチャを設計し、クライアントのITモダナイゼーション戦略やマネージドセキュリティサービスと整合させます。
インシデント対応アドバイザリー:
サイバーセキュリティインシデント発生後の原因分析支援、経営層向けコミュニケーション、規制当局への通知に関する助言、今後のセキュリティ改善提案を行います。実際の技術対応は専門チームと連携して進めます。
クライアントリレーションシップ:
主要クライアントの経営層との長期的な信頼関係を構築し、戦略的アカウントにおけるシニア窓口として、営業、プリセールス、デリバリー、カスタマーサクセスチームとの連携を行います。
サービス・プラクティス開発:
サイバーセキュリティコンサルティングの手法、サービス、ベストプラクティス、社内ナレッジの開発に貢献します。また、ジュニアコンサルタントや技術担当者の育成も担当します。
グローバル連携:
米国および日本のチームと連携し、企業クライアントのサイバーセキュリティプロジェクトや戦略的取り組みを支援します。
応募資格
サイバーセキュリティ、情報セキュリティ、情報リスク管理、または関連するアドバイザリー業務における10年以上の実務経験
シニアコンサルタント、アドバイザー、またはvCISOとして5年以上の経験
Big 4、サイバーセキュリティコンサルティング会社、マネージドサービス企業、または事業会社におけるセキュリティリーダー経験が望ましい
CIO、CISO、取締役会、監査委員会などの経営層を対象とした、中長期のサイバーセキュリティアドバイザリープロジェクトをリードした経験
NIST CSF、ISO 27001/27002、CRI Profile、NYDFS Part 500、HIPAA Security Rule、CMMC、CIS Controlsなど主要なサイバーセキュリティフレームワークに関する知識
以下を含む最新のセキュリティアーキテクチャに関する高い理解
Identity & Access Management(IAM、SSO、MFA)
Network Security(SASE、ZTNA、Firewall)
Endpoint Security(EDR、MDM)
Cloud Security(AWS、Azure、Microsoft 365)
Data Security(DLP、DSPM、SSPM)
日本語の読み書き・会話におけるビジネスレベルの能力必須
技術的な内容を経営層向けに分かりやすいビジネス上の提案へ変換できる、高い文章力およびコミュニケーション能力
Computer Science、Information Systems、Engineering、Business、または関連分野のBachelor's Degree
Master's DegreeまたはMBA保持者歓迎
CISSP、CISM、CISA、CRISC、または同等の上位レベルのサイバーセキュリティ資格を1つ以上保有していること
給与
年収 $90,000 - $140,000
経験・能力により決定
福利厚生
Medical、Dental、Vision Insurance
Basic Life Insurance、AD&D
Short-Term / Long-Term Disability Insurance
Flexible Spending Account(FSA)
会社マッチング付き401(k)
Vacation、Sick Leave、Floating Holidaysを含むPaid Time Off
年間13日のPaid Holidays
Tuition Reimbursement Program
Employee Assistance Program(EAP)
Employee Wellbeing Program
会社について
大手IT・システムインテグレーター
本ポジションにご関心のある方は、MAX Consulting Group, Inc.までお問い合わせください。クライアントから提供されている正式なJob Descriptionを、ご希望の方にはお送りいたします。
本求人ではクライアント企業の機密性を保つため、企業を特定できる一部の情報を意図的に省略しています。詳細については、選考対象となる方にご案内いたします。