Security Practitioner

image

About the Opportunity

At TechCompass, we help organizations build security programs that fit the way they actually operate. Our work spans cybersecurity assessments, security program development, cloud and product security, compliance readiness, security architecture, incident preparedness, technical implementation, and ongoing security leadership.

That means we look for practitioners who can do more than identify gaps. You should be comfortable understanding the business behind the technology, determining what matters most, and helping clients move from recommendation to execution.

We maintain relationships with strong security professionals as our team and client needs grow. The scope and structure of individual opportunities may vary based on experience, specialization, and project requirements.

What You May Work On

Depending on your background and area of expertise, you may:

  • Conduct cybersecurity risk, maturity, and technical security assessments.
  • Evaluate security controls across identity, endpoint, cloud, infrastructure, applications, data, and third-party environments.
  • Help clients prioritize security risks based on business impact and practical remediation requirements.
  • Develop and execute security roadmaps, policies, standards, and control improvements.
  • Support security programs aligned with frameworks and requirements such as NIST CSF, CIS Controls, SOC 2, ISO 27001, HIPAA, PCI DSS, and related standards.
  • Review AWS, Azure, GCP, SaaS, identity, and other modern technology environments.
  • Help clients select, configure, implement, or optimize security technologies and processes.
  • Support incident readiness, business continuity, cyber insurance readiness, vendor risk, and other security initiatives.
  • Translate technical findings into clear recommendations for executives, IT teams, developers, and other stakeholders.
  • Collaborate with other TechCompass specialists when an engagement requires deeper expertise in areas such as penetration testing, cloud security, compliance, or security architecture.

What We're Looking For

We’re interested in practitioners who bring a combination of technical knowledge, sound judgment, curiosity, and strong client-facing communication.

Strong candidates will typically have:

  • Professional experience in cybersecurity, information security, IT security, security consulting, or a closely related field.
  • Hands-on experience in one or more cybersecurity disciplines.
  • The ability to evaluate an environment, identify meaningful risks, and recommend practical solutions rather than relying solely on checklists.
  • Strong written communication and documentation skills.
  • Confidence explaining security issues to both technical and non-technical audiences.
  • The ability to work independently while collaborating effectively with clients and other practitioners.
  • A practical mindset and an understanding that the "right" security solution depends on the organization's risk, resources, business objectives, and stage of growth.
  • Current knowledge of cybersecurity threats, technologies, frameworks, and industry practices.
  • U.S.-based work authorization and residence.

Areas of Expertise We Value

You do not need experience in every area below. We are interested in practitioners with meaningful depth in one or more areas, including:

  • Cybersecurity assessments and risk management
  • Security architecture and engineering
  • Cloud security
  • Identity and access management
  • Application and product security
  • Security program development
  • Governance, risk, and compliance
  • SOC 2, ISO 27001, NIST, CIS, HIPAA, PCI, or CMMC
  • Incident preparedness and resilience
  • Security tooling and implementation
  • Vulnerability management
  • Third-party and vendor risk
  • AI security and governance
  • Security leadership or advisory

Relevant industry certifications are valued, but we care more about your ability to apply security knowledge effectively in real-world environments than about collecting credentials.

Why TechCompass

TechCompass is a boutique cybersecurity firm built around experienced practitioners and practical security.

Our clients range from startups and growing businesses to established organizations navigating complex security, compliance, and technology challenges.

Rather than applying the same playbook everywhere, we work alongside clients to understand their environment, identify what matters, and build security programs that support the business. You’ll have the opportunity to work across different industries, technologies, and security challenges while collaborating with people who value clear thinking, deep expertise, and meaningful outcomes.

Interested in Working With Us?

Even if there isn't an immediate opportunity that matches your background, we want to meet talented security professionals before we need them.

Tell us about your experience, the areas of security where you do your best work, and the types of challenges you want to solve.

Interested in working with TechCompass? We’d like to hear from you.

The talented team
behind our service

team
team
team
See All Team
image