Professional Services - Internship
Waterleaf International, an engineering, cybersecurity and science-based defense and networking contractor, is seeking an experienced, client-focused Cybersecurity GRC & Advisory Consultant to deliver professional services across the following delivery areas: Governance, Risk, and Compliance, Assessments, and Advisory/Consulting services.Waterleaf offers a forward leaning culture – that means our focus and direction is on people, intellect, process and deliverables. Our people include employees, contractors, and customers, all of whom have inherent value and contributions to not only our mission in defending our country but to the community we each live in. We support professional and individual growth and provide dynamic, fascinating, and supportive work environments. Talk to us about the ability to have great financial and personal gains in a thriving and vital environment.A seasoned candidate operates like a trusted senior IT consultant: equally comfortable running a NIST CSF assessment, authoring a policy stack, briefing a board on risk posture, and validating that documented controls hold up.This role is strategic and advisory in nature. It is not a hands-on offensive or operational security position (see What This Role Is Not, below).
Governance, Risk & Compliance (GRC)Evaluate client governance structures, policies, procedures, and controls against the frameworks most relevant to their industry - NIST CSF, NIST 800-171, CMMC, SOC 2, HIPAA, PCI DSS, and ISO 27001.Conduct GRC assessments that identify gaps, quantify risk, and map findings across multiple standards simultaneously.Produce risk-ranked findings, executive summaries written for leadership and board audiences, and prioritized remediation roadmaps.Support clients in maintaining compliance over time, including post-certification continuity of controls.Advisory & ConsultingServe in an advisory capacity, providing strategic security leadership without the cost of a full-time executive hire.Help clients answer the questions their boards and auditors are asking: What is our risk exposure? Are we compliant? Where should we invest next?Develop multi-year cybersecurity roadmaps that benchmark current maturity, define a target future state, and sequence initiatives to balance near-term risk reduction with long-term resilience.Facilitate stakeholder workshops to calibrate strategy to each client’s risk tolerance and business goals.Present findings, roadmaps, and progress through clear executive-level reporting and regular reviews.Building Security Programs Through Policy DevelopmentStand up information security programs from the ground up for clients with little or no existing structure.Author and mature policies, procedures, charters, RACI matrices, and escalation paths that are internally consistent and built to survive audits and personnel changes.Translate overlapping regulatory obligations into a single, coherent policy and control stack rather than a patchwork of one-off documents.Define decision rights, control ownership, and the operating model that keeps a program running after the engagement ends.NIST CSF AssessmentsLead NIST Cybersecurity Framework assessments across all six core functions: Govern, Identify, Protect, Detect, Respond, and Recover.Establish a current-state profile, identify gaps, and build a target-state roadmap with clear milestones and assigned ownership.Apply structured, repeatable assessment methodology so results are actionable rather than academic.Technical Validation (Controls Assurance)Conduct technical validation engagements that confirm documented controls work as described - moving beyond policy and documentation review to verify real-world control effectiveness.Conduct a comprehensive assessment of the Client’s Cloud environment to identify vulnerabilities, enhance overall security posture, and ensure compliance.Map validated control coverage back to the relevant framework subcategories for traceable, audit-ready results.
3+ years in cybersecurity, IT risk, audit, or compliance consulting, with demonstrated client-facing delivery.Hands-on experience conducting framework-based assessments (NIST CSF and/or SOC 2 strongly preferred).Demonstrated ability to author security policies, procedures, and program documentation from scratch.Working fluency across multiple compliance frameworks (e.g., SOC 2, HIPAA, PCI DSS, ISO 27001, CMMC).Strong written communication: the ability to produce executive summaries, findings reports, and remediation roadmaps that leadership can act on.Comfort presenting to and advising senior stakeholders, including boards and auditors.
Remote OpportunityActive Opportunity
No reviews yet. Reviews unlock for candidates 30 days after adding this program to their tracker — integrity over volume.
Interview prep for this program▸
- ▸ "How many of your past SkillBridge interns received full-time offers?" — a serious program knows the number.
- ▸ "Who will my day-to-day mentor be, and what does week one look like?"
- ▸ "The listing says 31 - 60 days — can that flex to my approved window if my command shortens it?"
- ▸ "How do virtual interns stay visible to hiring managers — what worked for past cohorts?"
- ▸ Confirm the eligibility notes above — ask exactly what they need from you and when.
- ✓ Your projected start window and separation date (from your profile)
- ✓ Your command's approval status — even "packet drafted" signals you're serious
- ✓ Your civilian-translated resume bullets (generate them here)
- ✓ A written training-plan ask — you'll need it for your packet anyway
Cyberleaf Professional Services
Cyberleaf is a Managed Security Services Provider (MSSP) and CMMC advisory firm supporting clients across the Defense Industrial Base (DIB). Through this SkillBridge internship, transitioning service members gain…
SOC Analyst - Internship
Waterleaf International, an engineering, cybersecurity and science-based defense and networking contractor, is seeking a full-time SOC Analyst. Waterleaf hires, trains and promotes the best and brightest for upward…