Cybersecurity Risk & Technical Advisory Consultant - Remote (USA)

Echelon Risk + Cyber

$100K — $120K *
US-AnywhereRemote in United States
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 3+ years of experience in a cybersecurity environment, with hands-on exposure to technical security assessments, testing, or advisory work.
  • 1+ years of related experience in a client-facing role.
  • Technical experience evaluating cloud environments (AWS, Azure, GCP), Microsoft 365, network infrastructure, endpoints, or SOC operations.
  • Working knowledge of MITRE ATT&CK tactics, techniques, and procedures (TTPs).
  • Familiarity with business continuity and disaster recovery (BCDR) planning and business impact analysis (BIA).
  • Scripting or automation experience with Python and/or PowerShell.
  • Excellent verbal and written communication skills.

Responsibilities

  • Assist in executing, developing, and reporting on Technology Risk, Compliance, and Cybersecurity engagements.
  • Conduct technical security assessments across cloud environments, network infrastructure, and endpoints to identify control gaps.
  • Perform threat modeling and threat hunting to proactively address adversary behavior and detection coverage gaps.
  • Support purple team exercises and technical tabletop exercises alongside client blue teams to strengthen processes.
  • Develop incident response playbooks and provide advisory support for clients managing security incidents.
  • Document findings, create client reports, and effectively communicate results to stakeholders.
  • Collaborate with clients and team members to identify security risks and propose actionable solutions.

Benefits

  • Access to medical, dental, and vision insurance with the majority of costs covered by the employer.
  • Employer funding for HSA accounts and FSA access.
  • Access to a 401(k) with guaranteed employer contributions.
  • Flexible vacation policy to manage schedules and promote work-life balance.
  • 11 holidays with flexibility according to personal needs.
  • Family-friendly benefits including maternity and paternity leave, short-term and long-term disability, and mental health support.
  • Support for individual development through certifications and continued learning opportunities.
Full Job Description


What You Will Do:
  • Assist in the execution, development, and reporting of Technology Risk, Compliance, and Cybersecurity engagements.
  • Conduct technical security assessments across cloud environments (AWS, Azure, and GCP), Microsoft 365, network infrastructure, endpoints, and SOC operations to identify control gaps and misconfigurations.
  • Perform threat modeling and threat hunting engagements to proactively surface adversary behavior and gaps in detection coverage.
  • Apply MITRE ATT&CK tactics, techniques, and procedures (TTPs) throughout assessments, threat modeling, and purple team engagements to map client environments against real-world adversary behavior and validate detection and response coverage.
  • Support purple team exercises and technical tabletop exercises (TTXs), working alongside client blue teams to test and strengthen detection, response, and escalation processes.
  • Provide incident response advisory support to clients actively managing security incidents, and develop incident response playbooks, plans, and post-incident remediation roadmaps.
  • Contribute to detection engineering efforts, helping clients build, tune, and validate detection logic aligned to observed and anticipated threats.
  • Support business continuity and disaster recovery (BC/DR) planning, including developing business impact analyses (BIA), to help clients prepare for and recover from disruptive events.
  • Document results, create client reports, and communicate results to client management and other stakeholders.
  • Work collaboratively with our clients and other team members to identify security risks and provide actionable recommendations and solutions.
  • Demonstrate consistency, versatility, and adaptability while managing simultaneous client engagements and priorities and delivering quality results in a timely fashion.
  • Work with the internal team to develop and plan engagement strategies, define objectives, identify and provide recommendations to address client risks.
  • Handle and evaluate data and information responsibly.
  • Create and deliver client-facing presentations, reports, and analytics.
  • Establish exceptional internal and client relationships using strong written and verbal communication skills.
  • Stay up to date with industry trends, emerging threats, and related laws and regulations within cybersecurity.
  • Collaborate with members of the team to resolve new or complex cybersecurity risks and project challenges.
  • Demonstrate thought leadership through the creation of content for the organization's website blog and involvement in the cybersecurity community.

Your knowledge, skills, and abilities:
  • 3+ years of experience in a cybersecurity environment, with hands-on exposure to technical security assessments, testing, or advisory work.
  • 1+ years of related experience in a client-facing role.
  • Technical experience evaluating cloud environments (AWS, Azure, GCP), Microsoft 365, network infrastructure, endpoints, or SOC operations.
  • Working knowledge of MITRE ATT&CK tactics, techniques, and procedures (TTPs), and the ability to apply them across assessments, threat modeling, and purple team engagements.
  • Experience with, or working knowledge of, threat modeling, threat hunting, and detection engineering.
  • Exposure to purple team exercises, technical tabletop exercises (TTXs), or other collaborative adversary-emulation formats.
  • Understanding of the incident response lifecycle, including playbook/plan development and post-incident remediation.
  • Familiarity with business continuity and disaster recovery (BCDR) planning and business impact analysis (BIA).
  • Scripting or automation experience with Python and/or PowerShell to support assessment, testing, and reporting workflows.
  • Experience with a variety of information security frameworks and best practices (e.g., NIST, CMMC, ISO, GLBA, FFIEC, SOX, SOC, HIPAA, HITRUST, MITRE ATT&CK, etc.).
  • Risk management experience, including performing assessments and audits, designing information security processes, managing enterprise control frameworks, and evaluating and prioritizing risk.
  • Excellent verbal and written communication skills, with experience crafting professional messages, client reports, and presentations for both technical and non-technical audiences.
  • Ability to manage and prioritize multiple simultaneous client engagements, adapting in a demanding and fast-changing environment.
  • Strong attention to detail and excellent analytical, technical, and problem-solving skills.
  • Actively pursues opportunities to develop professionally and demonstrates a willingness to learn.
  • Applicants must have authorization to work in the United States without current or future visa sponsorship.

Preferred Qualifications:
  • Certified in, or currently in pursuit of, one or more industry standard certifications: Security+, CySA+, GCIH, OSCP, or a cloud security certification.
  • Experience and / or familiarity with Digital Forensics and Incident Response (DFIR) techniques and solutions
  • Experience developing scripts and automation for data collection and sanitization using Python and PowerShell.


We currently offer the following benefits:
  • Access to medical, dental, and vision insurance through Cigna, with the majority of the employee cost covered by the employer
  • Employer funding to HSA accounts and FSA access
  • Access to a 401(k) through Vanguard with a guaranteed employer contribution
  • Flexible vacation policy that allows you to manage your schedule and rest and recharge when you need to
  • 11 holidays with flexibility based on what is important for you and those you love
  • Family-friendly benefits, including weeks off for Maternity leave, weeks off for non-birthing parent leave, employer-paid short-term and long-term disability, employer-paid life insurance, and access to additional life insurance, hospital coverage, accidental coverage, discounted mental health support, and more
  • Support for individual development through certifications, continued learning, conferences, and more

Similar Jobs

More Jobs at Echelon Risk + Cyber

More Information Technology Jobs

Find similar Cybersecurity Risk & Technical Advisory Consultant - Remote (USA) jobs: