Overview
The Senior Client Compliance Consultant plays a vital role in managing all client-facing compliance activities for the firm. This includes organizing due diligence responses, tracking compliance timelines, preparing policy documentation, and communicating key regulatory developments. The successful candidate will possess strong writing and presentation skills, an understanding of security and regulatory frameworks, and a proactive, organized, and client-oriented mindset. This role is based in New York City.
Key Responsibilities
- Client Due Diligence & Requests : Coordinate incoming and outgoing due diligence questionnaires, vendor assessments, and security documentation from clients and partners.
- Maintain a repository of compliance materials and coordinate subject matter expert (SME) involvement to complete responses.
- Ensure timely and complete delivery of all compliance documentation.
- Compliance Calendar & Operational Coordination : Work with clients to create and maintain IT Compliance Calendars that cover their IT related compliance considerations including :
Annual security reviews
Annual disaster recovery and business continuity plan testingAnnual policy and control reviewsAnnual cyber security testingAnnual vendor reviewsAnnual penetration testingCoordination and planning of tabletop exercisesRegulatory deadlines and attestationsISO 27001 Program including key activities, internal and external audit, and InfoSec meetingsSchedule and track progress of key compliance activities, engaging relevant stakeholders.
Regulatory Monitoring & Trend Response : Monitor changes in client-relevant regulatory environments (e.g., SEC, NY SHIELD Act, ISO 27001). Identify trends and communicate legislative developments to clients and internal teams. Assist in developing strategies and action plans to ensure client readiness.
Policy Documentation & Best Practice Alignment : Lead the onboarding process for client compliance documentation, including drafting baseline policies and procedures. Work with the technical teams to support critical client IT processes (on / off boarding, change management, etc.). Review client policies and ensure alignment with regulatory standards and best practices. Identify documentation gaps and propose remediation.
For The ISO 27001 Program :
Draft, maintain, and manage internal information security policies and procedures in alignment with ISO 27001 controls and Annex A requirements.Oversee version control, policy review cycles, and internal approvals.Ensure policies remain current with changes in business operations, risk posture, and industry standards.Coordinate and document policy acceptance and training efforts across the firm.Stakeholder Communication & Presentation : Deliver briefings and presentations to internal teams and external clients on compliance posture, regulatory changes, and project milestones. Translate complex compliance issues into clear, actionable language suitable for business and technical audiences.
Travel / Job Expectations : Occasional travel to office in NY and client sites, as required.
Adherence To The ISMS Framework :
The ISMS consists of processes and controls to manage the firm s data security with a goal of protecting the confidentiality, integrity, and availability of information assets for clients and of companyPersonnel are expected to contribute continuously to the ISMS framework by :Reporting incidents, events, and potential threats
Identifying weakness within the ISMS and reporting itProviding recommendations for improvement for both the security infrastructure and related operating proceduresRequired Qualificiations
Bachelor s degree in Business, Law, Information Security, or a related discipline.Minimum 5 years of experience in compliance, information security, risk, or regulatory affairs.Demonstrated ability to manage projects and meet deadlines across multiple stakeholders.Excellent grammar, writing, and verbal communication skills; strong attention to detail.Familiarity with relevant regulatory and security frameworks (e.g., ISO 27001, SOC 2, HIPAA, NY SHIELD Act, SEC / Client).Ability to interpret and summarize legal and regulatory changes for a professional audience.Desired Qualifications
Experience in IT consulting, SaaS, or professional services environments.Prior supervisory experience.Professional certifications such as CISA, CIPM, or CIPP.Seniority level
Mid-Senior levelEmployment type
Full-timeJob function
Information TechnologyIndustries
IT Services and IT ConsultingJ-18808-Ljbffr