Skip to content

Open nowPosted 245 days ago

Information Security Consultant

hatchit28 open roles

Where
Remote
Work mode
Remote
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowInformation Security Consultanthatchit · Remote
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on hatchit's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.7% of postings close within 7 days. Measured by our own scanner across the market.

Share of postings closed within
  1. 1.4%1 day
  2. 3.5%3 days
  3. 7.7%7 days
  4. 13.4%14 days
  5. 34.5%30 days
This job: posted 245 days ago

The posting

hatch I.T. is partnering with Assura to find a Virtual Information Security Officer (VISO). Details below:

About the Role

The Virtual Information Security Officer (VISO) is an analyst-level GRC consulting role delivering day-to-day security program work for Assura clients under the direction of a Senior VISO or GRC Director. This is not a strategic ownership role — it's a delivery role. You'll execute assigned service and planning tasks, support assessments and documentation, maintain professional client communication, and follow through on instructions reliably, while building toward greater responsibility over time.

About the Company

Assura is a cybersecurity firm with nearly 20 years of singular focus on information security. They work primarily with state, local, and education (SLED) organizations that need real world, practical security leadership — not checkbox compliance or theoretical frameworks. Their team is made up of career cybersecurity practitioners, not career consultants. They take the work seriously, but not themselves. People stay here because they're supported, trusted, and given room to grow.

Responsibilities:

  • Perform assigned GRC service and planning tasks under the direction of a Senior VISO or GRC Director
  • Support security assessments and identify risks, issues, and basic remediation activities under supervision
  • Maintain, update, and support development of core deliverables: policies, procedures, standards, BIA documentation, incident response and disaster recovery documentation, system security plans, vulnerability management plans, and third-party risk documentation
  • Facilitate client meetings, track follow-up items, and communicate clearly and professionally with clients and Assura colleagues
  • Interact directly with clients (once trained) without requiring constant senior intervention
  • Support audit and compliance activities — preparing compliant documentation, participating in audit defense as directed, and helping develop remediation plans under leadership direction
  • Customize and deliver client security awareness training within established parameters (e.g., KnowBe4)
  • Manage deadlines and quality expectations, including adherence to review steps such as Second Set of Eyes
  • Conduct independent research and analysis to close gaps or answer questions before escalating

Qualifications:

  • Approximately 3–5 years of relevant experience in cybersecurity, GRC, risk, compliance, audit, or information security
  • Meaningful hands-on experience with at least one regulatory framework (e.g., NIST 800-53, HIPAA, PCI DSS), with working familiarity in others
  • Strong working knowledge of NIST 800-53, with specific familiarity across the AC, IA, CM, SI, SC, AU, SA, and AT control families
  • Demonstrated experience updating or helping develop GRC deliverables (policies, procedures, standards, BIA, IR/DR docs, SSPs, VM plans, TPRM documentation)
  • Ability to take direction from senior staff and reliably carry instructions through to completion
  • Strong writing, documentation, and client communication skills
  • Intellectual curiosity and the ability to research and problem-solve independently when gaps arise

Preferred Skills:

  • Familiarity with SEC530 and Virginia public-sector compliance expectations
  • Foundational understanding of how functions like IT, HR, and Finance intersect with security planning and documentation
  • Prior audit support experience beyond evidence collection (planning, remediation, documentation ownership)
  • Comfort with client-facing meetings and stakeholder communication

Equal Opportunity Statement

Assura is committed to diversity and inclusivity in the workplace.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against hatchit's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on hatchit's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    hatchit's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.