CISSP Cybersecurity Consultant – NYDFS Part 500 and AI Readiness Assessment
Only freelancers located in the U.S. may apply.U.S. located freelancers only
# CISSP Cybersecurity Consultant – NYDFS Part 500 and AI Readiness Assessment ## Project Overview FortifyData is seeking an experienced **CISSP-certified cybersecurity consultant** to conduct a comprehensive **NYDFS 23 NYCRR Part 500 readiness and gap assessment** for one of our financial-services clients. The engagement will evaluate the client’s cybersecurity program, policies, technical controls, governance processes, and supporting evidence to determine its readiness for the annual NYDFS Part 500 compliance certification process. The assessment must also address cybersecurity risks associated with the client’s use of artificial intelligence, third-party AI solutions, and AI-enabled threats. This is a hands-on consulting engagement requiring direct experience conducting NYDFS Part 500 assessments—not general cybersecurity advisory experience. ## Scope of Work The selected consultant will: * Review the client’s cybersecurity program against applicable NYDFS Part 500 requirements. * Conduct stakeholder interviews and evidence-review sessions. * Review the organization’s current cybersecurity risk assessment. * Assess cybersecurity governance and senior-management oversight. * Evaluate applicable policies, procedures, standards, and technical controls. * Review asset inventory, data protection, access control, multifactor authentication, vulnerability management, penetration testing, incident response, business continuity, disaster recovery, and cybersecurity training practices. * Evaluate third-party service provider cybersecurity risk management. * Assess cybersecurity risks arising from the use of AI, including: * AI-enabled social engineering and cyberattacks. * Exposure of nonpublic or confidential information through AI tools. * Employee use of public generative AI platforms. * AI vendors and supply-chain dependencies. * Access controls, data governance, monitoring, and acceptable-use requirements for AI systems. * Identify areas of noncompliance, partial compliance, insufficient evidence, and control-design weaknesses. * Provide practical remediation recommendations prioritized by regulatory and cybersecurity risk. * Conduct a final findings presentation with the client and FortifyData team. ## Required Deliverables The consultant will be responsible for producing: 1. **NYDFS Part 500 Requirements Matrix** A section-by-section assessment identifying applicability, compliance status, evidence reviewed, gaps, and recommended corrective actions. 2. **Executive Readiness Report** A concise summary of the client’s overall readiness, material risks, significant deficiencies, and recommended next steps. 3. **Detailed Gap Assessment Report** Documentation of control gaps, policy gaps, evidence deficiencies, and areas requiring remediation. 4. **Prioritized Remediation Roadmap** Recommendations organized by criticality, regulatory impact, estimated level of effort, responsible function, and suggested completion timeline. 5. **AI Cybersecurity Risk Assessment** An evaluation of risks associated with the organization’s use of AI systems and exposure to AI-enabled cyber threats. 6. **Annual Certification Readiness Package** A consolidated collection of findings and supporting documentation to assist the client’s leadership in evaluating its readiness for the annual NYDFS Part 500 certification or acknowledgment process. 7. **Final Executive Presentation** A virtual presentation of findings, major risks, and recommended remediation priorities. ## Mandatory Qualifications Applicants must have: * An active **CISSP certification**. * Demonstrated experience conducting **NYDFS 23 NYCRR Part 500 readiness, compliance, or gap assessments**. * Strong knowledge of the current NYDFS Part 500 requirements and amendments. * Experience working with regulated financial-services organizations. * Experience reviewing cybersecurity governance, risk assessments, policies, technical controls, and compliance evidence. * Knowledge of AI cybersecurity risks, generative AI governance, and third-party AI risk. * Strong report-writing, interviewing, and executive-presentation skills. * The ability to independently lead the assessment and meet agreed deadlines. ## Preferred Qualifications Preference will be given to candidates with: * CISA, CISM, CRISC, CCSP, or similar certifications in addition to CISSP. * Experience supporting NYDFS annual certification readiness. * Experience with financial institutions, insurance companies, fintech companies, lenders, or other DFS-regulated entities. * Familiarity with NIST CSF, NIST AI RMF, ISO 27001, SOC 2, and other cybersecurity frameworks. * Experience assessing third-party service providers and cloud environments. * Experience developing executive-ready cybersecurity and regulatory reports. ## Engagement Details * **Engagement type:** Independent consulting project * **Work arrangement:** Remote * **Expected commitment:** Approximately 30–60 hours, depending on the client’s environment and documentation readiness * **Potential for additional work:** Yes, including remediation validation, policy development, recurring assessments, and other FortifyData client engagements * **Confidentiality:** The consultant will be required to sign a nondisclosure agreement before accessing client information ## How to Apply Please include the following in your proposal: * Confirmation that your CISSP certification is active. * A summary of your direct NYDFS Part 500 assessment experience. * The number and types of NYDFS Part 500 engagements you have completed. * A description of your proposed assessment methodology. * Your experience assessing AI-related cybersecurity risks. * A redacted example of a cybersecurity gap assessment, requirements matrix, or executive report, when available. * Your estimated availability and anticipated project duration. * Your proposed fixed-price fee or hourly rate. Proposals that do not clearly demonstrate direct NYDFS Part 500 experience will not be considered. ## Screening Questions 1. Is your CISSP certification currently active? 2. How many NYDFS Part 500 readiness or gap assessments have you personally completed? 3. What types of DFS-regulated organizations have you assessed? 4. Describe the primary deliverables you produced during your most recent NYDFS Part 500 engagement. 5. How would you evaluate cybersecurity risks associated with generative AI and third-party AI platforms? 6. Are you available to participate in client interviews and present findings to executive leadership? 7. Can you provide a redacted sample of a comparable assessment deliverable?
- Less than 30 hrs/weekHourly
- 3-6 monthsDuration
- ExpertExperience Level
- Remote Job
- Complex projectProject Type
Skills and Expertise
Activity on this job
- Proposals:5 to 10
- Interviewing:0
- Invites sent:1
- Unanswered invites:1
About the client
- United StatesKennesaw8:42 PM
- $406K total spent65 hires, 7 active
- 12,593 hours
- Mid-sized company (10-99 people)
Explore similar jobs on Upwork
How it works
Create your free profileHighlight your skills and experience, show your portfolio, and set your ideal pay rate.
Work the way you wantApply for jobs, create easy-to-by projects, or access exclusive opportunities that come to you.
Get paid securelyFrom contract to payment, we help you work safely and get paid securely.
About Upwork
- 4.9/5(Average rating of clients by professionals)
- G2 2021#1 freelance platform
- 49,000+Signed contract every week
- $2.3BFreelancers earned on Upwork in 2020
Find the best freelance jobs
Growing your career is as easy as creating a free profile and finding work like this that fits your skills.
Trusted by