Rivell

Cyber Security & Compliance Manager

Sewell, New JerseyFull-time
$85,000 - $95,000 annually
About the Job
LOCAL APPLICANTS ONLY PLEASE!

Company Overview:
Rivell, a leading Managed Services Provider (MSP) based in Sewell, New Jersey, has been recognized as one of Inc. 5000’s “Fastest Growing Companies in America.” We specialize in delivering comprehensive IT and cybersecurity solutions to businesses, local government, school districts, healthcare facilities, and other organizations across a variety of industries.
At Rivell, we foster a collaborative and innovative work environment while providing competitive compensation, professional development opportunities, and a clear path for career advancement.

Position Overview:
We are seeking a Cybersecurity & Compliance Manager to oversee, maintain, and strengthen cybersecurity and regulatory compliance initiatives across our client environments.

This role will serve as a key point of contact for clients regarding cybersecurity requirements, regulatory compliance, security assessments, cyber insurance requirements, and third-party cybersecurity questionnaires. The Cybersecurity & Compliance Manager will work closely with clients and Rivell’s technical teams to identify security and compliance gaps, develop remediation plans, maintain required documentation, and ensure clients are meeting the requirements of their applicable regulatory and compliance frameworks.

The ideal candidate is highly organized, detail-oriented, comfortable communicating with both technical and non-technical stakeholders, and capable of translating cybersecurity and regulatory requirements into clear, actionable steps.

Key Responsibilities:
  • Manage cybersecurity and compliance initiatives across multiple client environments.
  • Complete and coordinate cybersecurity questionnaires, security surveys, vendor security assessments, cyber insurance questionnaires, and third-party risk assessments on behalf of clients.
  • Identify the regulatory, contractual, and industry-specific cybersecurity requirements applicable to each client.
  • Help ensure clients maintain compliance with applicable frameworks and regulatory bodies, including standards such as HIPAA, PCI DSS, CJIS, NIST, CIS Controls, FTC Safeguards Rule, CMMC, ISO 27001, and other applicable requirements.
  • Conduct cybersecurity and compliance assessments to identify gaps between a client's current environment and required security standards.
  • Develop and maintain remediation plans, risk registers, compliance checklists, policies, procedures, and supporting documentation.
  • Work with Rivell's technical teams to implement security controls required to address identified risks or compliance deficiencies.
  • Track remediation items and follow up with clients and internal teams to ensure required corrective actions are completed.
  • Prepare clients for security audits, compliance assessments, cyber insurance reviews, and vendor security reviews.
  • Collect, organize, and maintain documentation and evidence required for audits and compliance verification.
  • Review client environments for adherence to cybersecurity best practices, including areas such as:
    • Multi-factor authentication.
    • Endpoint detection and response.
    • Email security.
    • Vulnerability management.
    • Patch management.
    • Backup and disaster recovery.
    • Access control and least privilege.
    • Firewall and network security.
    • Security awareness training.
    • Logging and monitoring.
    • Data protection and encryption.
  • Assist with the development, review, and maintenance of client cybersecurity policies, including acceptable use, incident response, password policies, access control, business continuity, and other required documentation.
  • Coordinate vulnerability assessments, security reviews, and other cybersecurity testing as required.
  • Review security findings and work with technical staff and clients to prioritize remediation based on risk and regulatory requirements.
  • Assist clients with cybersecurity incident response planning and documentation.
  • Provide cybersecurity and compliance guidance to clients, management, and internal technical teams.
  • Present security and compliance findings to clients in clear, understandable language, including recommendations and next steps.
  • Maintain detailed documentation of assessments, risks, remediation efforts, compliance requirements, and client security posture.
  • Stay current with changes to cybersecurity regulations, compliance frameworks, cyber insurance requirements, emerging threats, and industry best practices.

Work Schedule:
  • Standard hours: 8:00 AM – 4:00 PM, Monday - Friday.
  • Occasional after-hours availability may be required for critical cybersecurity incidents, compliance deadlines, or scheduled security work.

Travel Requirements:
  • Occasional local travel may be required for onsite cybersecurity assessments, audits, client meetings, or security-related projects.

On-Call Responsibilities:
  • Limited on-call responsibilities for urgent cybersecurity incidents or situations requiring compliance-related escalation.

Qualifications & Skills:
  • Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, Information Security, Risk Management, or a related field, or equivalent professional experience.
  • Experience working in cybersecurity, governance, risk and compliance (GRC), IT auditing, information security, or managed IT services.
  • Strong understanding of cybersecurity frameworks and regulatory requirements such as NIST Cybersecurity Framework, CIS Controls, HIPAA, PCI DSS, CJIS, FTC Safeguards Rule, CMMC, and ISO 27001.
  • Experience completing cybersecurity questionnaires, cyber insurance applications, vendor risk assessments, compliance assessments, or security audits is strongly preferred.
  • Ability to review regulatory or contractual cybersecurity requirements and determine the technical and administrative controls necessary to satisfy them.
  • Strong understanding of common cybersecurity technologies and controls, including:
    • Firewalls.
    • Endpoint Detection and Response (EDR).
    • SIEM and security monitoring.
    • Multi-factor authentication.
    • Email security.
    • Vulnerability management.
    • Backup and disaster recovery.
    • Identity and access management.
    • Encryption.
    • Network security.
  • Experience developing or maintaining cybersecurity policies, risk assessments, compliance documentation, and remediation plans.
  • Strong organizational and project management skills with the ability to manage compliance requirements across multiple clients simultaneously.
  • Excellent written and verbal communication skills.
  • Ability to explain cybersecurity risks and regulatory requirements to executives, business owners, and other non-technical stakeholders.
  • Strong analytical, documentation, and problem-solving skills.
  • Ability to work independently while coordinating effectively with technical teams, clients, vendors, and management.
  • Experience working within an MSP or MSSP environment is preferred.
  • Industry certifications such as Security+, CySA+, CISSP, CISM, CRISC, CISA, or similar certifications are preferred.

Benefits & Perks:
  • Competitive salary.
  • 401(k) retirement plan.
  • Paid time off.
  • Comprehensive benefits package.
  • Professional development opportunities.
  • Certification reimbursement.
  • Opportunities for continued advancement as Rivell's cybersecurity and compliance services grow.

Reporting To:
  • Technical Account Manager

Success Criteria:
Success in this role will be measured by the ability to maintain visibility into the cybersecurity and compliance posture of Rivell's clients, identify and document security deficiencies, ensure required remediation efforts are completed, and help clients meet the requirements of their applicable regulatory and compliance frameworks.

The successful candidate will also be responsible for ensuring cybersecurity questionnaires, assessments, audits, and compliance requests are completed accurately and on time while serving as a trusted cybersecurity and compliance resource for both clients and Rivell's internal teams.

If you are a detail-oriented cybersecurity professional who enjoys combining technical security, compliance, documentation, and client communication, we encourage you to apply!