CISSP Cybersecurity Consultant – NYDFS Part 500 and AI Readiness Assessment

Posted last week

Only freelancers located in the U.S. may apply.U.S. located freelancers only

Summary

# CISSP Cybersecurity Consultant – NYDFS Part 500 and AI Readiness Assessment ## Project Overview FortifyData is seeking an experienced **CISSP-certified cybersecurity consultant** to conduct a comprehensive **NYDFS 23 NYCRR Part 500 readiness and gap assessment** for one of our financial-services clients. The engagement will evaluate the client’s cybersecurity program, policies, technical controls, governance processes, and supporting evidence to determine its readiness for the annual NYDFS Part 500 compliance certification process. The assessment must also address cybersecurity risks associated with the client’s use of artificial intelligence, third-party AI solutions, and AI-enabled threats. This is a hands-on consulting engagement requiring direct experience conducting NYDFS Part 500 assessments—not general cybersecurity advisory experience. ## Scope of Work The selected consultant will: * Review the client’s cybersecurity program against applicable NYDFS Part 500 requirements. * Conduct stakeholder interviews and evidence-review sessions. * Review the organization’s current cybersecurity risk assessment. * Assess cybersecurity governance and senior-management oversight. * Evaluate applicable policies, procedures, standards, and technical controls. * Review asset inventory, data protection, access control, multifactor authentication, vulnerability management, penetration testing, incident response, business continuity, disaster recovery, and cybersecurity training practices. * Evaluate third-party service provider cybersecurity risk management. * Assess cybersecurity risks arising from the use of AI, including: * AI-enabled social engineering and cyberattacks. * Exposure of nonpublic or confidential information through AI tools. * Employee use of public generative AI platforms. * AI vendors and supply-chain dependencies. * Access controls, data governance, monitoring, and acceptable-use requirements for AI systems. * Identify areas of noncompliance, partial compliance, insufficient evidence, and control-design weaknesses. * Provide practical remediation recommendations prioritized by regulatory and cybersecurity risk. * Conduct a final findings presentation with the client and FortifyData team. ## Required Deliverables The consultant will be responsible for producing: 1. **NYDFS Part 500 Requirements Matrix** A section-by-section assessment identifying applicability, compliance status, evidence reviewed, gaps, and recommended corrective actions. 2. **Executive Readiness Report** A concise summary of the client’s overall readiness, material risks, significant deficiencies, and recommended next steps. 3. **Detailed Gap Assessment Report** Documentation of control gaps, policy gaps, evidence deficiencies, and areas requiring remediation. 4. **Prioritized Remediation Roadmap** Recommendations organized by criticality, regulatory impact, estimated level of effort, responsible function, and suggested completion timeline. 5. **AI Cybersecurity Risk Assessment** An evaluation of risks associated with the organization’s use of AI systems and exposure to AI-enabled cyber threats. 6. **Annual Certification Readiness Package** A consolidated collection of findings and supporting documentation to assist the client’s leadership in evaluating its readiness for the annual NYDFS Part 500 certification or acknowledgment process. 7. **Final Executive Presentation** A virtual presentation of findings, major risks, and recommended remediation priorities. ## Mandatory Qualifications Applicants must have: * An active **CISSP certification**. * Demonstrated experience conducting **NYDFS 23 NYCRR Part 500 readiness, compliance, or gap assessments**. * Strong knowledge of the current NYDFS Part 500 requirements and amendments. * Experience working with regulated financial-services organizations. * Experience reviewing cybersecurity governance, risk assessments, policies, technical controls, and compliance evidence. * Knowledge of AI cybersecurity risks, generative AI governance, and third-party AI risk. * Strong report-writing, interviewing, and executive-presentation skills. * The ability to independently lead the assessment and meet agreed deadlines. ## Preferred Qualifications Preference will be given to candidates with: * CISA, CISM, CRISC, CCSP, or similar certifications in addition to CISSP. * Experience supporting NYDFS annual certification readiness. * Experience with financial institutions, insurance companies, fintech companies, lenders, or other DFS-regulated entities. * Familiarity with NIST CSF, NIST AI RMF, ISO 27001, SOC 2, and other cybersecurity frameworks. * Experience assessing third-party service providers and cloud environments. * Experience developing executive-ready cybersecurity and regulatory reports. ## Engagement Details * **Engagement type:** Independent consulting project * **Work arrangement:** Remote * **Expected commitment:** Approximately 30–60 hours, depending on the client’s environment and documentation readiness * **Potential for additional work:** Yes, including remediation validation, policy development, recurring assessments, and other FortifyData client engagements * **Confidentiality:** The consultant will be required to sign a nondisclosure agreement before accessing client information ## How to Apply Please include the following in your proposal: * Confirmation that your CISSP certification is active. * A summary of your direct NYDFS Part 500 assessment experience. * The number and types of NYDFS Part 500 engagements you have completed. * A description of your proposed assessment methodology. * Your experience assessing AI-related cybersecurity risks. * A redacted example of a cybersecurity gap assessment, requirements matrix, or executive report, when available. * Your estimated availability and anticipated project duration. * Your proposed fixed-price fee or hourly rate. Proposals that do not clearly demonstrate direct NYDFS Part 500 experience will not be considered. ## Screening Questions 1. Is your CISSP certification currently active? 2. How many NYDFS Part 500 readiness or gap assessments have you personally completed? 3. What types of DFS-regulated organizations have you assessed? 4. Describe the primary deliverables you produced during your most recent NYDFS Part 500 engagement. 5. How would you evaluate cybersecurity risks associated with generative AI and third-party AI platforms? 6. Are you available to participate in client interviews and present findings to executive leadership? 7. Can you provide a redacted sample of a comparable assessment deliverable?

  • Less than 30 hrs/week
    Hourly
  • 3-6 months
    Duration
  • Expert
    Experience Level
  • Remote Job
  • Complex project
    Project Type
Skills and Expertise
Mandatory skills
Information Security
Certified Information Systems Security Professional
Activity on this job
  • Proposals:5 to 10
  • Interviewing:
    0
  • Invites sent:
    1
  • Unanswered invites:
    1
About the client
Member since Jan 7, 2017
  • United States
    Kennesaw8:42 PM
  • $406K total spent
    65 hires, 7 active
  • 12,593 hours
  • Mid-sized company (10-99 people)

Explore similar jobs on Upwork

Ethical hackingHourly‐ Posted 2 weeks ago
Information Security
Penetration Testing
Vulnerability Assessment
Cybersecurity Management
Cybersecurity Tool
Cybersecurity Monitoring
Ethical Hacking
Malware Removal
WordPress Bug Fix
WordPress Malware Removal
Malware Website
Malware Detection
Backup & Migration
Information Gathering
Bug Bounty
Skincare Toxicological Risk AssessmentFixed-price‐ Posted 3 weeks ago
Academic Writing
Chemistry
Economics
Essay Writing

How it works

  • Post a job icon
    Create your free profile
    Highlight your skills and experience, show your portfolio, and set your ideal pay rate.
  • Talent comes to you icon
    Work the way you want
    Apply for jobs, create easy-to-by projects, or access exclusive opportunities that come to you.
  • Payment simplified icon
    Get paid securely
    From contract to payment, we help you work safely and get paid securely.
Want to get started? Create a profile

About Upwork

  • Rating is 4.9 out of 5.
    4.9/5
    (Average rating of clients by professionals)
  • G2 2021
    #1 freelance platform
  • 49,000+
    Signed contract every week
  • $2.3B
    Freelancers earned on Upwork in 2020

Find the best freelance jobs

Growing your career is as easy as creating a free profile and finding work like this that fits your skills.

Trusted by

  • Microsoft Logo
  • Airbnb Logo
  • Bissell Logo
  • GoDaddy Logo