Infosec Consultant

Cyber SecurityInfosec
Contract Remote in United States or Canada Posted 7 hours ago

InfoSec Security Review Consultant

Short-Term Contract Engagement

Estimated Effort: ~40 hours total

Start Date: Targeting next week — timing is a priority Contract Term: Through end of September 2026

Engagement Type: Independent review & advisory, short-term contract

Work Mode: Remote

Background

K2 Partnering Solutions is delivering a ServiceNow and Workato integration for a financial services client, enabling an AI platform to read from and write to ServiceNow (Incidents, Requests, Change records, and related objects) through a Workato-orchestrated, ServiceNow-side compliance layer. Before we commit further build effort, we need an independent InfoSec resource to review the client's security standards and confirm our proposed approach holds up against them.

Why We Need This Role

Our team can review the client's InfoSec policies and make a good-faith effort to align to them, but we don't have a dedicated security specialist validating that read. Based on prior integration/automation engagements, misreading a client's security requirements upfront is one of the most common sources of costly rework later — this role is aimed squarely at catching that early, not at finding a hypothetical showstopper.

Scope of Work

• Review the client's InfoSec policies, security standards, and any relevant ServiceNow platform-security/compliance requirements (API access, service/identity accounts, data handling, audit logging, etc.).

• Assess our proposed integration architecture — AI-triggered actions orchestrated via Workato, enforced through a ServiceNow-side Scripted REST API compliance layer, using a scoped “digital worker” identity — against those policies.

• Identify gaps, risks, or likely points of friction (e.g., indirect/multiplexed access licensing questions, service-account/API-identity requirements, audit and access-control expectations).

• Propose specific amendments or mitigations anywhere our approach doesn't cleanly meet the client's standards.

• Advise on what is and isn't likely to be acceptable to the client's InfoSec team, so we can reduce the risk of rework after build is underway.

• Deliver a concise written assessment (findings + recommendations) and be available for one or two working sessions with the delivery team.

Ideal Background

• InfoSec / security consulting experience, ideally with enterprise SaaS platforms.

• Familiarity with API security and identity/access management for machine or service (non-human) identities.

• Experience reviewing vendor or partner integration patterns against a client's security policies, ideally in financial services or another regulated industry.

• Comfortable working independently and producing a clear, actionable written assessment on a short timeline.

Your Cart (0)

Your cart is empty

Looks like you haven't added any items to your cart yet.