SKILLBRIDGE.MIL DATALAST SYNC 2026-09-25
SkillBridgeConnectby Civic HackingPrograms
Programs / Waterleaf International LLC dba Cyberleaf
In official directorySynced 2026-09-25

Professional Services - Internship

USAFUSAUSCGUSMCUSNUSSF
Program summary

Waterleaf International, an engineering, cybersecurity and science-based defense and networking contractor, is seeking an experienced, client-focused Cybersecurity GRC & Advisory Consultant to deliver professional services across the following delivery areas: Governance, Risk, and Compliance, Assessments, and Advisory/Consulting services.Waterleaf offers a forward leaning culture – that means our focus and direction is on people, intellect, process and deliverables. Our people include employees, contractors, and customers, all of whom have inherent value and contributions to not only our mission in defending our country but to the community we each live in. We support professional and individual growth and provide dynamic, fascinating, and supportive work environments. Talk to us about the ability to have great financial and personal gains in a thriving and vital environment.A seasoned candidate operates like a trusted senior IT consultant: equally comfortable running a NIST CSF assessment, authoring a policy stack, briefing a board on risk posture, and validating that documented controls hold up.This role is strategic and advisory in nature. It is not a hands-on offensive or operational security position (see What This Role Is Not, below).

Roles & job description

Governance, Risk & Compliance (GRC)Evaluate client governance structures, policies, procedures, and controls against the frameworks most relevant to their industry - NIST CSF, NIST 800-171, CMMC, SOC 2, HIPAA, PCI DSS, and ISO 27001.Conduct GRC assessments that identify gaps, quantify risk, and map findings across multiple standards simultaneously.Produce risk-ranked findings, executive summaries written for leadership and board audiences, and prioritized remediation roadmaps.Support clients in maintaining compliance over time, including post-certification continuity of controls.Advisory & ConsultingServe in an advisory capacity, providing strategic security leadership without the cost of a full-time executive hire.Help clients answer the questions their boards and auditors are asking: What is our risk exposure? Are we compliant? Where should we invest next?Develop multi-year cybersecurity roadmaps that benchmark current maturity, define a target future state, and sequence initiatives to balance near-term risk reduction with long-term resilience.Facilitate stakeholder workshops to calibrate strategy to each client’s risk tolerance and business goals.Present findings, roadmaps, and progress through clear executive-level reporting and regular reviews.Building Security Programs Through Policy DevelopmentStand up information security programs from the ground up for clients with little or no existing structure.Author and mature policies, procedures, charters, RACI matrices, and escalation paths that are internally consistent and built to survive audits and personnel changes.Translate overlapping regulatory obligations into a single, coherent policy and control stack rather than a patchwork of one-off documents.Define decision rights, control ownership, and the operating model that keeps a program running after the engagement ends.NIST CSF AssessmentsLead NIST Cybersecurity Framework assessments across all six core functions: Govern, Identify, Protect, Detect, Respond, and Recover.Establish a current-state profile, identify gaps, and build a target-state roadmap with clear milestones and assigned ownership.Apply structured, repeatable assessment methodology so results are actionable rather than academic.Technical Validation (Controls Assurance)Conduct technical validation engagements that confirm documented controls work as described - moving beyond policy and documentation review to verify real-world control effectiveness.Conduct a comprehensive assessment of the Client’s Cloud environment to identify vulnerabilities, enhance overall security posture, and ensure compliance.Map validated control coverage back to the relevant framework subcategories for traceable, audit-ready results.

Eligibility notes

3+ years in cybersecurity, IT risk, audit, or compliance consulting, with demonstrated client-facing delivery.Hands-on experience conducting framework-based assessments (NIST CSF and/or SOC 2 strongly preferred).Demonstrated ability to author security policies, procedures, and program documentation from scratch.Working fluency across multiple compliance frameworks (e.g., SOC 2, HIPAA, PCI DSS, ISO 27001, CMMC).Strong written communication: the ability to produce executive summaries, findings reports, and remediation roadmaps that leadership can act on.Comfort presenting to and advising senior stakeholders, including boards and auditors.

Additional notes

Remote OpportunityActive Opportunity

Candidate reviews

No reviews yet. Reviews unlock for candidates 30 days after adding this program to their tracker — integrity over volume.

Interview prep for this program▸
Ask them
  • ▸ "How many of your past SkillBridge interns received full-time offers?" — a serious program knows the number.
  • ▸ "Who will my day-to-day mentor be, and what does week one look like?"
  • ▸ "The listing says 31 - 60 days — can that flex to my approved window if my command shortens it?"
  • ▸ "How do virtual interns stay visible to hiring managers — what worked for past cohorts?"
  • ▸ Confirm the eligibility notes above — ask exactly what they need from you and when.
Bring to the conversation
  • ✓ Your projected start window and separation date (from your profile)
  • ✓ Your command's approval status — even "packet drafted" signals you're serious
  • ✓ Your civilian-translated resume bullets (generate them here)
  • ✓ A written training-plan ask — you'll need it for your packet anyway
More from Waterleaf International LLC dba Cyberleaf