remote

Salary
$117,500–$166,250
Posted
Jul 22, 2026
Location
Last confirmed open
Jul 23, 2026

What this job asks for AI summary

A client-facing advisory role within a cybersecurity consulting practice, responsible for leading day-to-day delivery across engagements covering security strategy, risk assessment, GRC, and program development. The position serves as the primary client contact, facilitates workshops, produces deliverables such as assessment reports and roadmaps, and mentors junior staff. Suits an experienced security consultant comfortable working across both technical and executive audiences.

Senior level · 5+ years · Bachelor's required · Full-time

Must have (5)
NIST CSFISO 27001HIPAASOC 2PCI-DSS
Nice to have (6)
Cloud SecurityIAMCISSP, Cism or CisaDevSecOpsVulnerability ManagementEndpoint Security

“or” means any one of them counts — you don't need all of them.

We read this from the posting text with AI. Skim the description below before ruling yourself out.

How this req sits in the market our data

What the occupation pays Median $132,021 (middle half $99,961–$167,095).

Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.

Why we read it this way (7)

The role title 'Cybersecurity Strategy Lead' carries no explicit seniority level word, so advertised seniority is Unspecified; however, the 5+ years requirement, client-facing leadership scope, and responsibility for mentoring junior staff support a Senior classification.

NIST CSF, ISO 27001, HIPAA, SOC 2, and PCI-DSS are listed under the 'What You Have' (requirements) section as 'familiarity with common cybersecurity frameworks including…' — the section placement makes these hard gates even though 'familiarity' softens the depth expected.

Cloud Security, IAM, Security Operations, and data protection are explicitly called 'a plus' in the requirements section, so they are marked preferred.

CISSP, CISM, and CISA are listed as 'preferred' certifications; CISSP is used as the primary skill name with CISM and CISA as alternatives since the posting treats them as interchangeable.

The 'Bonus experience' block covering DevSecOps, Vulnerability Management, Endpoint Security, and Log Management is explicitly framed as bonus/optional and is marked preferred.

The alt SOC (15-1299) reflects that this is a consulting/advisory delivery role rather than a pure in-house security analyst position; 15-1212 is the best available fit given the security risk, GRC, and program advisory focus.

Ignored 2 non-technology phrase(s) as skills (responsibilities/concepts, not named tools): Security Operations, Log Management.

Read the full posting

The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.

Apply

Apply on employer site ↗