CIS Controls Implementation Specialist

Sora Schools
Summary
Join Sora Schools as a Cybersecurity Consultant to implement the CIS Controls Implementation Group 1 (IG1) framework. This is a fully remote, contract role (40 or 20 hours/week) lasting 8-12 weeks, focusing on strengthening the security of Sora's online learning environment. You will lead the full implementation of the CIS IG1 framework, assessing current tools and policies, identifying gaps, and creating a prioritized implementation plan. Responsibilities include recommending and configuring tools, creating documentation, collaborating with cross-functional teams, and delivering a fully implemented and operational framework. The ideal candidate possesses hands-on experience with CIS Controls and IG1 implementation, particularly in cloud-based or education settings. Compensation is $30/hour, and flexible scheduling is available.
Requirements
- Hands-on implementation of CIS Controls, especially IG1
- Strong understanding of cybersecurity in cloud-based environments
- Ability to work independently and manage a project end-to-end
- Strong communication and collaboration skills
Responsibilities
- Conduct a comprehensive assessment of our current tools, policies, and systems against the CIS IG1 controls
- Identify security gaps and create a prioritized implementation plan tailored to a cloud-native, education-first organization
- Recommend, configure, and deploy tools and workflows to meet IG1 control requirements
- Create or revise documentation, including policies, procedures, and staff guidance
- Collaborate with team members across functions to align on security needs and ensure smooth implementation
- Track progress, report on milestones, and adjust the plan as needed to stay on schedule
- Deliver a fully implemented, operational, and documented CIS IG1 framework by the end of the project
Benefits
- Compensation for this role is $30/hr for this role
- We are open to either 40hr/week or 20hr/week
- This is a fully remote role expected to last about 8β12 weeks, with flexible scheduling as long as project milestones are met