Responsibilities:
- Perform an overall review of internal/external security operations, tools, policies & processes
- Conduct annual security risk assessments for all clients, establishing a standardized process and system for documentation and follow-up actions
- Create/maintain dedicated client records containing annual service risk assessment documentation
- Develop and formalize templates for Office 365, PCI, and HIPAA compliance to support ongoing client management
- Align organizational security approaches with NIST, DoD, and CISA standards; leverage available DoD reports to identify and document vulnerabilities and gaps
- Partner with internal teams and third-party vendors to remediate security vulnerabilities and maintain compliance baselines
- Evaluate existing monitoring and vulnerability management processes, recommending improvements and new tools as needed
- Standardize documentation, templates, and knowledge base content for consistent operational execution
- Oversee & advise on security configuration across Windows, Office 365, macOS, Hyper-V, VM-hosted, and remote access environments
- Assist with implementing, monitoring, and maintaining security technologies including Fortigate firewalls, VIPRE EDR/MDR, ConnectSecure, and FortiCloud dashboards
- Communicate assessment findings and remediation recommendations effectively to clients and internal stakeholders
- Serve as the MSP’s subject matter expert and resource for client-facing cybersecurity strategy
- Perform other duties as needed
Experience:
- 5–7 years of progressive cybersecurity experience, preferably within an MSP, healthcare, or compliance-driven environment
- Strong familiarity with NIST framework, PCI DSS, HIPAA, and CISA baselines
- Proven experience designing and implementing risk assessment processes and compliance documentation
- Practical knowledge of Windows Server, Office 365, macOS, networking, VPN, EDR, Hyper-V, and VM-hosted infrastructure
- Experience collaborating with third-party vendors on vulnerability remediation, tool selection etc.
- Excellent written and verbal communication skills, with strong documentation discipline
- Entrepreneurial mindset, comfortable operating independently, defining processes, and driving projects forward
- Familiarity with monitoring and management tools (e.g., ConnectWise, Automate, FortiCloud, VIPRE EDR/MDR)
- CISSP certification (or equivalent qualification) – Highly Preferred

