5+ years of experience in cybersecurity, focusing on governance, risk, and compliance (GRC) planning and management.
Proven track record in client-facing roles, including leading workshops and managing project deliverables.
Experience in mentoring or coaching junior staff and providing constructive feedback.
Strong risk management skills, including assessments and mitigation strategies.
Familiarity with multiple information security frameworks (e.g., NIST, PCI, ISO) and GRC tools.
Excellent communication skills, adaptable to various audiences from technical teams to executives.
Knowledge of cloud systems and security tools is beneficial.
Responsibilities
Lead and manage client engagements, ensuring timely delivery of key deliverables.
Conduct client onboarding and discovery, including interviews and assessments.
Plan and coordinate cybersecurity and compliance programs, building security roadmaps.
Facilitate workshops and communicate complex security topics to senior stakeholders.
Review and assure quality of team deliverables, ensuring adherence to standards.
Identify growth opportunities within client accounts and contribute to business development.
Coach and develop junior team members, fostering a culture of technical excellence.
Benefits
Comprehensive medical, dental, and vision insurance with significant employer coverage.
Employer contributions to HSA accounts and access to FSA.
401(k) plan with guaranteed employer contributions.
Flexible vacation policy for work-life balance.
11 holidays with flexibility to accommodate personal needs.
Family-friendly benefits including maternity and parental leave, disability coverage, and mental health support.
Support for professional development through certifications and conferences.
Full Job Description
GRC Senior Consuntant (vCISO) - Remote (USA)
As a Senior Consultant, you are a trusted, reliable resource for clients and a technical and delivery leader inside Echelon. You will own significant portions of client initiatives and key deliverables, lead workshops, quality-review team output before it reaches the client, and coach junior consultants. You will address broader strategic challenges for clients, proactively identify and address project risks, and represent Echelon with confidence in senior-level discussions.
This is a remote position from anywhere in the USA
What You Will Do:
Lead client engagements and initiatives
Own and manage defined portions of client initiatives, including scope, timeline, dependencies, status reporting, and delivery of key deliverables.
Conduct client discoveries and onboarding of services, including client interviews, discovery and assessment plans, evidence requests, and review of documentation and supporting evidence.
Plan, coordinate, and manage cybersecurity and compliance programs using strong project management and communication techniques (e.g., build security roadmaps, prioritize and track initiatives).
Proactively identify and address project risks, scope changes, and client dependencies before they affect delivery.
Facilitate workshops and advise senior stakeholders
Plan and lead client workshops, such as risk assessments, framework assessments and policy walkthroughs.
Communicate complex security and compliance topics clearly to senior client stakeholders, adjusting message and depth to the audience.
Work with clients to identify information security risks and challenges and provide actionable, right-sized recommendations.
Represent Echelon in high-level client discussions.
Assess, document, and assure quality
Review and assess security and technology controls against cybersecurity best practices and compliance frameworks.
Develop and maintain cybersecurity policies and procedures.
Perform quality assurance review of team deliverables, including reports, assessments, policies, roadmaps, and presentations, for accuracy, completeness, consistency, and adherence to Echelon standards before client delivery.
Document results, create client reports, and communicate findings to client management and other stakeholders.
Create client-facing presentations and executive-level reporting.
Grow accounts and the practice
Take ownership of proposals, statements of work, budgets, and work plans, and contribute strategic insights to business development efforts.
Identify new growth opportunities within client accounts and partner with leadership to act on them.
Work with the internal team to develop engagement strategies, define objectives, and recommend approaches to address client risks.
Help build and improve Echelon's internal processes, templates, and methodologies.
Coach and develop the team
Provide guidance, coaching, and feedback to junior team members, and contribute to team capability through training.
Model Echelon values, including "Turning Pro" and "Client Centricity," by mentoring others on technical excellence, ownership, and follow-through.
Manage multiple simultaneous client engagements and priorities while delivering quality results on time.
Contribute to the community
Create and execute a formal plan for personal growth marketing, including regularly publishing thought leadership for Echelon's website blog.
Engage in the cybersecurity community by attending or speaking at local or national conferences.
Your Knowledge, Skills, and Abilities:
5+ years of related experience in the cybersecurity industry, with a focus on governance, risk, and compliance planning, development, and management. Consulting or advisory experience preferred.
Demonstrated experience leading client-facing work, such as facilitating workshops, owning deliverables, or managing portions of projects.
Experience reviewing the work of others and providing constructive feedback; prior mentoring or coaching of junior staff is a plus.
Risk management experience, including performing assessments, recommending risk mitigation strategies, as well as evaluating and prioritizing risks.
Depth of expertise across multiple information security frameworks and best practices (e.g., CIS, NIST, PCI, CMMC, ISO, GLBA, FFIEC, SOX, SOC, HIPAA, HITRUST).
Knowledge of GRC platforms and tools that support assessments and compliance management.
Excellent verbal and written communication skills, with the ability to craft professional messages and adjust style to the audience, from technical teams to executives and boards.
Ability to manage and prioritize multiple projects simultaneously and adapt in a demanding, changing environment.
Strong attention to detail and superior analytical, technical, and problem-solving skills.
Although this is not a deeply technical role, working knowledge of cloud systems, applications, and security tools and services (e.g., EDR, MDR, SIEM, vulnerability scanning, email security, backup/DR, MDM), firewalls, basic networking, data security, and IAM/SSO is valuable in an advisory capacity.
Preferred experience working with financial services, healthcare, or other regulated industries.
Degree in Information Systems, Computer Science, Information Security, or a related discipline preferred. Project management experience preferred.
Preferred certifications: CISSP, CISA, CISM, or similar.
Intellectual curiosity, with a willingness to learn and develop.
Applicants must have authorization to work in the United States without current or future visa sponsorship.
We currently offer the following benefits:
Access to medical, dental, and vision insurance through Cigna, with the majority of the employee cost covered by the employer
Employer funding to HSA accounts and FSA access
Access to a 401(k) through Vanguard with a guaranteed employer contribution
Flexible vacation policy that allows you to manage your schedule and rest and recharge when you need to
11 holidays with flexibility based on what is important for you and those you love
Family-friendly benefits, including weeks off for Maternity leave, weeks off for non-birthing parent leave, employer-paid short-term and long-term disability, employer-paid life insurance, and access to additional life insurance, hospital coverage, accidental coverage, discounted mental health support, and more
Support for individual development through certifications, continued learning, conferences, and more