Cybersecurity & Compliance Specialist
Company: Fisch Solutions, Inc.
Location: New Windsor, NY in-office with client visits
Type: Full-Time
Reports to: Michael Parrella, IT Operations Manager
Compensation: $24 - $26/hr depending on experience.
About Us
Fisch Solutions is one of the largest and fastest growing managed IT and cybersecurity providers in the Hudson Valley. We support SMB, municipal, healthcare, and defense-adjacent clients with managed IT, security operations, AI enablement, and compliance advisory. We are a 2026 Channel Futures MSP 501 company (Top 501 MSPs List Globally), a CRN Magazine Top 500 MSP (National ranking of Top MSPs), a three time Inc. 5000 honoree, and we hold a 99.2 percent client satisfaction rating with 80+ five star Google reviews.
The Role
We are building out a dedicated compliance function. This person owns our compliance run books, both internal and client facing, and makes sure they are documented, implemented, and actually followed. You will also own our incident response plans and run them live when an incident hits, for us and for our clients.
This is a hands-on role for someone who can work independently, write clearly, and hold both our team and our clients accountable to the standards we sell.
What You'll Own
Compliance Run Books and Documentation
- Build, maintain, and version control compliance run books for Fisch and for client engagements
- Map client environments to the applicable framework, including HIPAA, PCI DSS, CMMC, NIST 800-171, NY SHIELD, and cyber insurance attestation requirements
- Verify that documented controls are actually implemented in the environment, not just written down
- Maintain evidence libraries, policy sets, and system security plans so clients are audit ready at any time
- Track remediation items to closure with named owners and due dates
Incident Response
- Own and maintain Fisch's IR plan and client specific IR plans
- Act as incident commander during live incidents, coordinating our SOC, engineering team, client leadership, insurance carriers, and outside counsel where needed
- Drive containment, eradication, and recovery decisions alongside the technical team
- Produce post incident reports, root cause findings, and corrective action plans
- Run tabletop exercises with our team and with clients at least annually
Client Advisory
- Conduct risk assessments, gap analyses, and readiness reviews
- Translate findings into plain language for owners, boards, and non technical stakeholders
- Support clients through cyber insurance applications and renewals
- Assist with client audits, questionnaires, and vendor security reviews
- Partner with our vCIO cadence so compliance status shows up in quarterly business reviews
Internal Program
- Maintain Fisch's own security policies, awareness training program, and control documentation
- Support internal SOC 2 readiness work as the program matures
- Keep leadership informed on regulatory changes that affect our clients or our business
What We're Looking For
- 3+ years in cybersecurity, IT compliance, audit, or a closely related role
- Working knowledge of at least two of: HIPAA, PCI DSS, CMMC or NIST 800-171, SOC 2, CIS Controls, NYS Breach/Shield Act, Cybersecurity Insurance Compliance Requirements
- Real incident response experience, ideally in an MSP, MSSP, or multi client environment
- Strong technical writing skills, since documentation is a core deliverable here, not an afterthought
- Comfortable with Microsoft 365/ GSuite security, EDR and SIEM tooling, backup and recovery concepts, and network security fundamentals
- Able to hold a client accountable politely and hold your ground when the answer is no
- Clean background check, since some client work requires it
Nice to Have
- CISSP, CISA, CISM, Security+, CCP or CCA, HCISPP, or equivalent
- Prior MSP experience
- Experience with defense contractors, healthcare practices, or municipal government
- Familiarity with IR and Compliance tooling like PO&EMs.
Pay: $24.00 - $26.00 per hour
Work Location: In person