Department: Cyber Services and Capabilities
Employment Type: Full Time
Location: USA Remote - Eastern Time
The Senior Security Consultant, US Privacy & Assurance is responsible for helping clients identify, manage, and reduce cybersecurity, privacy, and regulatory risk through advisory, assessment, and assurance services. The role provides expert guidance on US privacy regulations, healthcare and financial services requirements, security frameworks, and risk management practices, enabling organizations to protect sensitive information, strengthen governance, and demonstrate compliance with evolving legal and regulatory obligations.
The Senior Security Consultant, US Privacy & Assurance is expected to have deep experience conducting privacy-focused assessments that help organizations understand and manage privacy risk in increasingly complex regulatory environments. This includes leading Privacy Impact Assessments (PIAs) and privacy risk assessments, developing and validating data flow maps to identify how personal information is collected, used, shared, stored, and retained, and evaluating compliance with evolving US privacy requirements. The role requires a strong understanding of privacy-intensive state regulations, including CCPA/CPRA and other emerging state privacy laws, and the ability to translate regulatory obligations into practical business and technical controls. Through these assessments, the consultant helps clients strengthen privacy governance, improve transparency, reduce regulatory risk, and build sustainable privacy programs aligned with business objectives and legal requirements.
Additionally, working collaboratively with clients, technical teams, and business stakeholders, the Senior Security Consultant delivers privacy assessments, security and compliance reviews, risk assessments, and assurance engagements across frameworks and regulations such as CCPA, CMS, HIPAA, HITRUST, NIST, NYDFS, and other applicable US privacy and cybersecurity requirements. The role helps organizations build resilient security and privacy programs by translating complex regulatory and technical requirements into practical, business-focused solutions.
This position plays a key role in supporting NCC Group's mission to create a more secure digital future.
Through trusted client relationships, high-quality project delivery, and thought leadership, the Senior Security Consultant helps clients improve security maturity, manage regulatory risk, and build trust with customers, partners, and regulators. The role contributes directly to client satisfaction, revenue growth, successful engagement delivery, regulatory readiness, and the continued reputation of NCC Group as a trusted cybersecurity and risk management advisor.
Lead and deliver client engagements across privacy, cybersecurity, risk, and assurance domains, ensuring projects are completed on time, within scope, on budget, and to a high standard of quality. This includes privacy assessments, compliance reviews, cybersecurity assessments, risk assessments, and audit support activities aligned to client requirements and regulatory obligations.
Provide subject matter expertise on US privacy regulations and data protection requirements, including CCPA/CPRA and emerging federal and state privacy laws. Monitor regulatory developments, assess their impact on clients, and deliver practical recommendations to help organizations maintain compliance and manage risk.
Deliver assurance and compliance engagements against industry standards and regulatory frameworks, including HITRUST, HIPAA, NYDFS Cybersecurity Regulation, NIST Cybersecurity Framework (CSF), NIST Risk Management Framework (RMF), and related governance, risk, and compliance requirements.
Support business development activities by assisting with the scoping, planning, and estimation of privacy, risk, and assurance engagements. Contribute to proposals, statements of work (SOWs), client presentations, and solution development to ensure client needs are accurately understood and appropriately addressed.
Support the development and enhancement of NCC Group's US privacy consulting offerings, methodologies, templates, accelerators, and intellectual property. Contribute to the growth of privacy services including CCPA/CPRA readiness assessments, privacy program development, data governance, and regulatory compliance offerings.
Advise clients on the design, implementation, and improvement of privacy and security programs, helping organizations establish effective governance, risk management, compliance, and data protection practices.
Develop and maintain trusted client relationships, serving as a strategic advisor throughout engagements. Identify opportunities to expand services, support account growth, and strengthen NCC Group's position as a trusted cybersecurity and privacy partner.
Mentor and support junior consultants and team members by providing coaching, technical guidance, quality reviews, and knowledge sharing to promote professional development and delivery excellence.
Produce high-quality client deliverables, including assessment reports, risk analyses, audit documentation, executive presentations, remediation roadmaps, and compliance recommendations tailored to both technical and non-technical stakeholders.
Collaborate with multidisciplinary teams across cybersecurity, privacy, assurance, healthcare, financial services, and risk management practices to deliver integrated solutions that address client and regulatory requirements.
Maintain current knowledge of evolving privacy, cybersecurity, and regulatory requirements, industry trends, emerging threats, and best practices, and apply this knowledge to client engagements, service development, and thought leadership activities.
Travel occasionally to client locations to perform assessments, audits, workshops, stakeholder interviews, and other engagement-related activities as required.
Candidates should hold one or more relevant certifications, such as:
We believe great work deserves great support. That’s why we offer a benefits package designed to look after you, your family, and your future.

We are NCC Group. A people powered, tech-enabled global cyber security and resilience company with 2,000 colleagues around the world.
For over 25 years we’ve been trusted by the world’s leading companies and Governments to manage and deliver cyber resilience, working together to create a more secure digital future.