- Hourly
- Expert
- Est. time: Less than 1 month, Less than 30 hrs/week
We are conducting research into how organizations manage cybersecurity, including vulnerability discovery, prioritization, remediation, incident response, and emerging AI-assisted security tools. We are seeking current or recently active cybersecurity professionals with direct responsibility for protecting organizational software, infrastructure, systems, or data. Relevant roles include: - CISO, VP, Director, or Head of Security - Security Engineering or Security Operations leadership - Application, Product, Cloud, or Infrastructure Security - Vulnerability Management - Incident Response and Threat Detection We are especially interested in professionals with experience in financial services, manufacturing, supply chain, healthcare, SaaS, cloud infrastructure, retail, telecommunications, energy, or critical infrastructure. The engagement consists of a paid 30-minute interview covering: - How cybersecurity responsibilities are organized - How threats and vulnerabilities are discovered and prioritized - Common obstacles to remediation - How security products are evaluated and purchased - False positives and alert volume - Current and expected uses of AI in cybersecurity - We will not request confidential information, credentials, vulnerability details, customer data, or restricted internal information.
- Fixed price
- Expert
- Est. budget: $150.00
We're looking for information security professionals to chat with us about how you assess and respond to file sharing risks in Google Drive (or similar cloud storage). We'll cover topics like: • Your current approach to managing sensitive content in Google Drive • How you decide if a shared file is overshared • How you respond once you've flagged a file This will be a 60-min video call where we'll discuss your approach to file security. Everything will be recorded, but recordings will not be shared publicly, ever. You ideally have: • Experience as a Google Workspace admin, ideally at a company (or with clients) actively using it • 7 years minimum in information security, in a senior or manager-level role • Hands-on experience identifying and remediating overshared files, and/or designing policies to handle this automatically • Experience in information security for organizations with 100 - 5000 employees We have a short survey below for applicants. Please do not write a cover letter. Brevity is appreciated; please avoid overly-long AI-generated responses.
- Hourly: $75.00 - $150.00
- Expert
- Est. time: More than 6 months, 30+ hrs/week
Seeking a cybersecurity and IT audit expert for a government internal audit contract. Must have CISA or CISSP certification and 5+ years public sector experience. Remote, US-based. Hourly, task-order basis.
- Hourly
- Expert
- Est. time: 3 to 6 months, Less than 30 hrs/week
# CISSP Cybersecurity Consultant – NYDFS Part 500 and AI Readiness Assessment ## Project Overview FortifyData is seeking an experienced **CISSP-certified cybersecurity consultant** to conduct a comprehensive **NYDFS 23 NYCRR Part 500 readiness and gap assessment** for one of our financial-services clients. The engagement will evaluate the client’s cybersecurity program, policies, technical controls, governance processes, and supporting evidence to determine its readiness for the annual NYDFS Part 500 compliance certification process. The assessment must also address cybersecurity risks associated with the client’s use of artificial intelligence, third-party AI solutions, and AI-enabled threats. This is a hands-on consulting engagement requiring direct experience conducting NYDFS Part 500 assessments—not general cybersecurity advisory experience. ## Scope of Work The selected consultant will: * Review the client’s cybersecurity program against applicable NYDFS Part 500 requirements. * Conduct stakeholder interviews and evidence-review sessions. * Review the organization’s current cybersecurity risk assessment. * Assess cybersecurity governance and senior-management oversight. * Evaluate applicable policies, procedures, standards, and technical controls. * Review asset inventory, data protection, access control, multifactor authentication, vulnerability management, penetration testing, incident response, business continuity, disaster recovery, and cybersecurity training practices. * Evaluate third-party service provider cybersecurity risk management. * Assess cybersecurity risks arising from the use of AI, including: * AI-enabled social engineering and cyberattacks. * Exposure of nonpublic or confidential information through AI tools. * Employee use of public generative AI platforms. * AI vendors and supply-chain dependencies. * Access controls, data governance, monitoring, and acceptable-use requirements for AI systems. * Identify areas of noncompliance, partial compliance, insufficient evidence, and control-design weaknesses. * Provide practical remediation recommendations prioritized by regulatory and cybersecurity risk. * Conduct a final findings presentation with the client and FortifyData team. ## Required Deliverables The consultant will be responsible for producing: 1. **NYDFS Part 500 Requirements Matrix** A section-by-section assessment identifying applicability, compliance status, evidence reviewed, gaps, and recommended corrective actions. 2. **Executive Readiness Report** A concise summary of the client’s overall readiness, material risks, significant deficiencies, and recommended next steps. 3. **Detailed Gap Assessment Report** Documentation of control gaps, policy gaps, evidence deficiencies, and areas requiring remediation. 4. **Prioritized Remediation Roadmap** Recommendations organized by criticality, regulatory impact, estimated level of effort, responsible function, and suggested completion timeline. 5. **AI Cybersecurity Risk Assessment** An evaluation of risks associated with the organization’s use of AI systems and exposure to AI-enabled cyber threats. 6. **Annual Certification Readiness Package** A consolidated collection of findings and supporting documentation to assist the client’s leadership in evaluating its readiness for the annual NYDFS Part 500 certification or acknowledgment process. 7. **Final Executive Presentation** A virtual presentation of findings, major risks, and recommended remediation priorities. ## Mandatory Qualifications Applicants must have: * An active **CISSP certification**. * Demonstrated experience conducting **NYDFS 23 NYCRR Part 500 readiness, compliance, or gap assessments**. * Strong knowledge of the current NYDFS Part 500 requirements and amendments. * Experience working with regulated financial-services organizations. * Experience reviewing cybersecurity governance, risk assessments, policies, technical controls, and compliance evidence. * Knowledge of AI cybersecurity risks, generative AI governance, and third-party AI risk. * Strong report-writing, interviewing, and executive-presentation skills. * The ability to independently lead the assessment and meet agreed deadlines. ## Preferred Qualifications Preference will be given to candidates with: * CISA, CISM, CRISC, CCSP, or similar certifications in addition to CISSP. * Experience supporting NYDFS annual certification readiness. * Experience with financial institutions, insurance companies, fintech companies, lenders, or other DFS-regulated entities. * Familiarity with NIST CSF, NIST AI RMF, ISO 27001, SOC 2, and other cybersecurity frameworks. * Experience assessing third-party service providers and cloud environments. * Experience developing executive-ready cybersecurity and regulatory reports. ## Engagement Details * **Engagement type:** Independent consulting project * **Work arrangement:** Remote * **Expected commitment:** Approximately 30–60 hours, depending on the client’s environment and documentation readiness * **Potential for additional work:** Yes, including remediation validation, policy development, recurring assessments, and other FortifyData client engagements * **Confidentiality:** The consultant will be required to sign a nondisclosure agreement before accessing client information ## How to Apply Please include the following in your proposal: * Confirmation that your CISSP certification is active. * A summary of your direct NYDFS Part 500 assessment experience. * The number and types of NYDFS Part 500 engagements you have completed. * A description of your proposed assessment methodology. * Your experience assessing AI-related cybersecurity risks. * A redacted example of a cybersecurity gap assessment, requirements matrix, or executive report, when available. * Your estimated availability and anticipated project duration. * Your proposed fixed-price fee or hourly rate. Proposals that do not clearly demonstrate direct NYDFS Part 500 experience will not be considered. ## Screening Questions 1. Is your CISSP certification currently active? 2. How many NYDFS Part 500 readiness or gap assessments have you personally completed? 3. What types of DFS-regulated organizations have you assessed? 4. Describe the primary deliverables you produced during your most recent NYDFS Part 500 engagement. 5. How would you evaluate cybersecurity risks associated with generative AI and third-party AI platforms? 6. Are you available to participate in client interviews and present findings to executive leadership? 7. Can you provide a redacted sample of a comparable assessment deliverable?
- Fixed price
- Expert
- Est. budget: $50.00
We are seeking an experienced Open-Source Intelligence (OSINT) specialist or Cybersecurity Professional for a live/recorded video consultation for an upcoming YouTube educational video. The goal of this session is to educate our audience on digital footprint analysis, network infrastructure, and OSINT investigation methodologies. You will join our host on a recorded video call to analyze a case study involving anonymous online accounts, explaining how technical indicators (such as IP lookups, domain WHOIS records, server logs, and digital breadcrumbs) work in real-world investigations. Note: This contract is strictly for educational, media-consultation, and technical explanation purposes. It does not involve skip-tracing, illegal access, or the targeted collection of private individual data. Key Responsibilities: On-Camera Technical Commentary: Participate in a 30 minute recorded video interview breakdown detailing OSINT methodologies, IP geographic node lookups vs. legal ISP discovery, and digital footprint analysis. Methodological Breakdown: Explain to a lay audience how investigators cross-reference public network logs, ISP data, and social media breadcrumbs to map out coordinated online networks. Prep / Pre-Interview Briefing: Conduct a quick 15-minute sync prior to recording to review the discussion structure and verify on-camera assets/screen-shares. Requirements: Proven professional background in OSINT, Cybersecurity, Digital Forensics, or Threat Intelligence. Strong, clear communication skills with the ability to break down technical network concepts for a mainstream audience. Comfortable being recorded on camera for broadcast on YouTube. High-quality video, clean audio, and proper lighting setup for screen recording. Willingness to execute a standard Work for Hire / Media Appearance release agreement. To Apply: Please submit: A brief overview of your background in OSINT, threat intelligence, or digital forensics. Confirmation that you are comfortable appearing on camera for a YouTube video. Links to any previous interviews, podcasts, technical presentations, or media appearances (if available).
- Hourly: $80.00 - $100.00
- Expert
- Est. time: 3 to 6 months, Hours to be determined
The Cybersecurity Auditor is responsible for planning and executing information security audits, assessing the effectiveness of cybersecurity controls, evaluating compliance with regulatory and industry standards, and identifying opportunities to strengthen the organization's security posture. The ideal candidate will possess strong auditing, risk management, and cybersecurity expertise with a proven ability to communicate findings to technical and executive stakeholders. Refer to attachment for more info.
- Hourly
- Expert
- Est. time: Less than 1 month, Less than 30 hrs/week
I am seeking an experienced cybersecurity consultant with a strong background in cyber investigations, digital forensics, email authentication, and online threat attribution. The ideal candidate should have demonstrated experience investigating cyberbullying, harassment, impersonation, defamatory online activity, or anonymous communications and should be capable of tracing digital evidence through email headers, IP logs, domain records, social-media activity, and related technical sources. Experience with Microsoft 365, Office 365, Microsoft Exchange, user authentication, account security, penetration testing, ethical hacking, and infrastructure assessments is strongly preferred.
- Hourly: $20.00 - $80.00
- Intermediate
- Est. time: 1 to 3 months, Less than 30 hrs/week
We are seeking a senior network administrator, Sr. Archictecture Design engineer with expertise in Linux, complex infrustructre. The role involves hands on network infrastructure arch redesign and rebuild, ensuring security protocols are in place, and troubleshooting network issues. The ideal candidate will have experience with Linux, Node, Java, Docker, Apache2, Tailscale, SSH, Phyton cybersecurity, router Ubiq and switch, Dginx, reverse proxies, cloudflare, API and extensive network security, and be able to work independently to resolve complex problems.
- Hourly
- Intermediate
- Est. time: More than 6 months, 30+ hrs/week
Join our team as a Sales Representative to sale our Cybersecurity Awareness Training programs. We are looking for a motivated Cybersecurity Sales Representative to help us grow our customer base by identifying businesses that need cybersecurity awareness training and presenting our services to potential clients. This is a commission only sales position with the opportunity to earn recurring commissions from every client you bring in. Your primary responsibility will be selling our Cybersecurity Awareness Training services to businesses. You will be responsible for: Finding and prospecting potential business clients Contacting business owners, executives, IT managers, HR departments, and other decision-makers Explaining the value of cybersecurity awareness training Identifying businesses that need employee cybersecurity training Conducting sales calls and presentations Following up with potential clients Negotiating and closing sales Maintaining communication with clients through the sales process You will receive 20% of the client's monthly service price for the first four (5) months.
- Fixed price
- Expert
- Est. budget: $450.00
We're SecureW2, the leader in passwordless, continuous trust cybersecurity solutions that empower network professionals with RADIUS servers, PKI certificates, and AI security. We need expert cybersecurity writers and thought leaders who can have expertise in our core topics, can write authoritatively about AI security, and are confident writing SEO-optimized articles, blogs, and longform content. Here's what we're looking for: • Human content • 7+ years of experience in cybersecurity with a technical background • Expert knowledge of core passwordless and zero-trust concepts like 802.1X, RADIUS, PKI, SCEP, EAP-TLS, WPA2 • Strong understanding of the emerging AI security field, from non-human identities to prompt injection and SPIFFE/SPIRE. • Knowledge of fundamental SEO principles and blog writing in 2026 Here's what we're NOT looking for: • AI content - your content will go through a multi-step review with editors trained to detect AI usage • Cybersecurity expertise, but in adjacent fields • SEO writers without deep technical knowledge in the field • Technical writers unable/unwilling to integrate SEO briefs into their work and write in modern blog style Please send a portfolio of recent published work if interested. Thank you!