Cyber Risk Consultant

The Nippon Telegraph and Telephone Corporation (NTT)

$143K *
Finance & Insurance
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 7+ years in Cybersecurity Risk Management or related fields.
  • 7+ years in Financial Services or highly regulated industries.
  • 5+ years identifying technology risks and proposing mitigation strategies.
  • 5+ years conducting cybersecurity risk assessments and technology reviews.
  • 5+ years across cybersecurity domains including IAM and Cloud Security.
  • 5+ years with cybersecurity control frameworks like NIST or ISO 27001.
  • 3+ years assessing cybersecurity risks related to AI technologies.

Responsibilities

  • Conduct cyber risk assessments and technology reviews for new initiatives.
  • Perform toll gate reviews for cyber-related technology intake requests.
  • Partner with cross-functional teams to evaluate technology solutions and assess risks.
  • Support the AI Center of Excellence with cybersecurity evaluations.
  • Collaborate to ensure AI initiatives meet cybersecurity standards and governance.
  • Represent the BISO team in supporting AI CoE processes and managing backlogs.
  • Evaluate cybersecurity risks across various security domains.

Benefits

  • Medical, dental, and vision insurance.
  • Flexible spending or health savings account.
  • Accidental death and dismemberment (AD&D) insurance.
  • Employee assistance program.
  • 401k program participation.
Full Job Description
Basic Qualifications
  • Minimum 7 years of hands-on experience in Cybersecurity Risk Management, Technology Risk, Information Security, or Cybersecurity Governance.
  • Minimum 7 years of experience working within the Financial Services, Banking, Insurance, Brokerage, or other highly regulated industry.
  • Minimum 5 years of experience identifying technology risks, defining cybersecurity control requirements, identifying control gaps, and proposing risk mitigation strategies.
  • Minimum 5 years of experience conducting cybersecurity risk assessments, technology reviews, and control assessments.
  • Minimum 5 years of experience across cybersecurity domains including IAM, Vulnerability Management, Cloud Security, Cybersecurity Architecture, Network Security, Metrics, and Compliance.
  • Minimum 5 years of experience with cybersecurity control frameworks such as NIST, ISO 27001, or equivalent industry frameworks.
  • Minimum 3 years of experience assessing cybersecurity risks associated with AI, Machine Learning, Generative AI, or other emerging technologies.
  • Minimum 3 years of experience evaluating AI and Machine Learning architectures, associated cybersecurity risk vectors, data protection risks, and evaluation methodologies.
  • Minimum 3 years of experience with third-party or vendor cybersecurity risk assessments and due diligence.
  • Minimum 3 years of experience supporting BISO, Cyber Risk, Technology Risk, Information Security Governance, or Enterprise Risk Management functions.
  • Minimum 3 years of experience managing technology evaluation requests, cyber risk intake processes, BISO intake requests, or similar cybersecurity governance workflows.
  • Strong understanding of cybersecurity risk identification, control assessment, risk remediation, risk acceptance, issue management, and risk reporting.
  • Strong communication and stakeholder management skills with the ability to communicate complex cybersecurity and technology risk concepts to both technical and non-technical audiences.
  • Strong experience facilitating working sessions and collaborating with Cyber SMEs, technology teams, business stakeholders, and senior leadership.
  • Minimum 5 years of experience working independently, managing multiple priorities, and delivering tasks within project timelines.

Day to Day Job Duties
  • Conduct cyber risk assessments and technology reviews for new and existing technology initiatives within a regulated financial services environment.
  • Perform toll gate reviews for cyber-related technology intake requests to ensure cybersecurity and risk requirements are identified, documented, and addressed before initiatives advance.
  • Partner with technology teams, business stakeholders, Cyber SMEs, and cross-functional teams to evaluate technology solutions, assess control adequacy, identify gaps, and provide actionable risk guidance throughout the project lifecycle.
  • Support the AI Center of Excellence (CoE) by performing cybersecurity risk evaluations of Artificial Intelligence, Machine Learning, Generative AI, and other emerging technology solutions.
  • Collaborate with Cyber SMEs, business stakeholders, and technology partners to ensure AI initiatives align with established cybersecurity standards, governance frameworks, and risk management requirements.
  • Represent the BISO team in supporting AI CoE processes, including conducting reviews, managing and clearing Technology Evaluation and other BISO intake request backlogs, sustaining operational processes, and building reporting capabilities.
  • Evaluate cybersecurity risks across IAM, Vulnerability Management, Cloud Security, Cybersecurity Architecture, Network Security, Metrics, Compliance, and other security domains.
  • Assess cybersecurity controls against established frameworks such as NIST, ISO 27001, or equivalent cybersecurity control frameworks.
  • Evaluate third-party and vendor cybersecurity risks and identify appropriate security and risk management requirements.
  • Review AI and Machine Learning architectures, technology solutions, data flows, and associated cybersecurity risk vectors to support risk evaluations and governance decisions.
  • Develop and maintain reporting capabilities, metrics, dashboards, and management reporting for cyber risk assessments, technology evaluations, AI governance, and BISO activities.
  • Facilitate working sessions and communicate complex cybersecurity and technology risk concepts clearly to technical and non-technical stakeholders.
  • Build trusted relationships and collaborate effectively with Cyber SMEs, technology partners, business stakeholders, and business leaders.

Preferred Certifications
At least one of the following certifications is preferred: CISSP, CISM, CRISC, CISA

Nice to Have
  • Experience working within or supporting a BISO function at a financial institution.
  • Experience supporting an AI Center of Excellence (CoE) or enterprise AI governance program.
  • Experience with AI governance frameworks, AI risk management, model risk management, or responsible AI practices.
  • Experience with enterprise risk management programs within a regulated financial services environment.
  • Experience developing cybersecurity risk dashboards, metrics, and executive reporting.
  • Experience working with Agile, Scrum, or enterprise governance processes.


Degree
Bachelor's degree in computer science, Information Systems, Cybersecurity, Engineering, Risk Management, or equivalent work experience.

We are currently seeking a professional to join our team in Halifax, Nova Scotia (CA-NS), Canada (CA).

NTT DATA provides a reasonable range of compensation for U.S.-based positions. The starting pay range for this remote role is [$69/hr. on W2]. This range reflects the minimum and maximum target compensation for the position across all US locations. Actual compensation will depend on a number of factors, including the candidate's actual work location, relevant experience, technical skills, and other qualifications. This position is eligible for company benefits including participation in medical, dental, and vision insurance, flexible spending or health savings account, and AD&D insurance, employee assistance, participation in a 401k program, and additional voluntary or legally-required benefits

Similar Jobs

More Jobs at The Nippon Telegraph and Telephone Corporation (NTT)

More Finance & Insurance Jobs

Find similar Cyber Risk Consultant jobs: