At Ferrilli, we drive positive changes in higher education through technology. Our mission is to enhance student success by optimizing campus IT infrastructure and implementing innovative solutions. With a holistic approach, we provide expert IT services and consulting, to help clients achieve their goals.
This role is based in the Philippines and will follow a hybrid work setup. Working hours for this role are aligned with U.S. business hours to ensure seamless collaboration with our clients and teams.
POSITION SUMMARY
We are seeking a highly skilled and client-focused Cybersecurity Consultant to deliver cybersecurity assessments, advisory services, and remediation planning to our higher education clients. The ideal candidate will have a strong technical background combined with a consultative mindset, capable of translating complex security needs into actionable solutions for IT leaders, compliance teams, and institutional stakeholders.
RESPONSIBILITIES
- Conduct cybersecurity risk assessments, gap analyses, and maturity evaluations aligned with frameworks such as NIST 800-171, GLBA, and ISO 27001.
- Support clients in the development of security roadmaps, policies, procedures, and incident response plans tailored for academic environments.
- Evaluate existing controls and recommend improvements across areas including identity and access management (IAM), endpoint protection, network security, and cloud security (e.g., Microsoft 365, AWS, Google Workspace).
- Assist institutions with preparation for audits and regulatory compliance (e.g., GLBA Safeguards Rule, PCI DSS, FERPA, HIPAA).
- Conduct internal and external penetration tests and perform vulnerability scans to identify, assess, and report on security weaknesses across network, application, and endpoint systems.
- Provide advisory services on the implementation of security technologies and secure architecture design.
- Deliver executive-level briefings and technical documentation to IT and administrative leadership.
- Stay current on emerging threats, vulnerabilities, and compliance requirements affecting the higher education sector.
- Contribute to internal knowledge sharing and continuous improvement of service offerings.
QUALIFICATIONS
Required:
- Bachelor's degree in Cybersecurity, Information Technology, or related field (or equivalent experience).
- 3+ years of experience in cybersecurity consulting, risk assessments, or information security roles.
- Strong knowledge of NIST Cybersecurity Framework, NIST 800-171, CIS Controls, and/or ISO 27001.
- Familiarity with higher education IT environments, systems, and organizational structures.
- Excellent communication, documentation, and stakeholder engagement skills.
- Experience with Microsoft Entra ID (Azure AD), M365 security tools, or other enterprise solutions.
Preferred:
- Industry certifications (e.g., CISSP, CISA, CISM, GIAC, CCSP, or similar).
- Experience working in or consulting for colleges and universities.
- Knowledge of GLBA, FERPA, and HIPAA regulatory frameworks.
- Experience supporting security incident response or security operations.