5+ years of experience in cybersecurity focusing on Governance, Risk, and Compliance (GRC)
Proficiency with GRC tools for assessments and compliance management
Strong background in risk management, including assessments and designing security controls
Familiarity with various cybersecurity frameworks and best practices (NIST, ISO, SOC, etc.)
Ability to lead projects from initiation through delivery, managing expectations and timelines
Knowledge of incident response and business continuity planning is preferred
Excellent communication skills tailored for diverse audiences
Responsibilities
Assist in planning and executing cybersecurity risk assessments against industry frameworks
Collaborate with client leadership to enhance cybersecurity maturity roadmaps
Develop cybersecurity policies and procedures
Review security controls against best practices and compliance frameworks
Create and tailor Incident Response Plans and Playbooks for clients
Lead tabletop exercise engagements with realistic scenarios
Document results and communicate effectively with clients and stakeholders
Benefits
Comprehensive medical, dental, and vision insurance with major costs covered
Employer contributions to HSA and access to FSA
401(k) with guaranteed employer contributions
Flexible vacation policy for personal management of time off
11 customizable holidays based on personal significance
Family-friendly benefits including generous parental leave, disability insurance, and mental health support
Support for professional development through certifications and learning opportunities
Full Job Description
Senior Risk Advisory Consultant - Remote (USA)
This is a remote position from anywhere in the USA
What You Will Do:
Assist in the planning, scoping, execution, and reporting of cybersecurity risk and maturity assessments against frameworks such as NIST CSF, ISO 27001, SOC 2, and CMMC
Collaborate with IT management and client leadership to develop roadmaps to enhance client maturity
Develop and maintain Cybersecurity policies and procedures while supporting clients
Review and assess security and technology controls against cybersecurity best practices and compliance frameworks
Collaborate with clients to develop Incident Response Plans, and Incident Response Playbooks tailored to each client's environment and needs
Lead end-to-end tabletop exercise engagements, developing realistic, client-specific scenarios that align with organizational people, processes, and technologies and effectively engage technical, management, and executive audiences
Document results, create client reports, and communicate results to client management and other stakeholders
Work collaboratively with our clients and other team members to identify information security risks and challenges and provide actionable recommendations and solutions
Demonstrate consistency, versatility, and adaptability while managing simultaneous client engagements and priorities and delivering quality results in a timely fashion
Work with the internal team to develop and plan engagement strategies, define objectives, identify and provide recommendations to address client risks
Create client-facing presentations, reports, and analytics
Develop long-term roadmaps to assist clients in reaching their desired maturity level
Perform business impact analyses and develop Business Continuity Plans and Disaster Recovery Plans
Assist leadership in the creation of proposals, budgets, work plans, and other business development efforts
Establish exceptional internal and client relationships using strong communication skills
Produce thought leadership for the organization's website blog on a regular basis
Actively engage in the cybersecurity community by attending or speaking at local or national conferences
Your knowledge, skills, and abilities:
5+ years of related experience in the cybersecurity industry
Focus on Governance, Risk, and Compliance planning, development, and management
Knowledge of GRC Platforms/Tools to assist with Assessments and Compliance Management
Risk management experience, including performing assessments and audits, designing information security controls and processes, and evaluating and prioritizing risk
Experience with a variety of information security frameworks and best practices (e.g., CIS, NIST, PCI, CMMC, ISO, GLBA, FFIEC, SOX, SOC, HIPAA, HITRUST, etc.)
Ability to lead engagements from scoping through delivery, including managing client expectations, timelines, and deliverables
Experience with incident response, business continuity, and disaster recovery planning is preferred
Ability to provide strategic guidance to clients on tabletop exercise design, incident preparedness, and resilience.
Project Management experience preferred
Ability to manage and prioritize multiple projects simultaneously and adapt in a demanding and changing environment
Although this is not a technical oriented role, knowledge of Cloud systems, applications, security services/tools (e.g., EDR, MDR, SIEM, Vulnerability Scanning, Email Security, Backup/DR, MDM), Firewalls, Basic Networking, Data Security, IAM/SSO, etc., will be beneficial in an advisory capacity
Ability to mentor and provide guidance to junior consultants and contribute to the development of internal methodologies and best practices
Strong attention to detail and superior analytical, technical, and problem-solving skills
Excellent verbal and written communication skills with experience crafting professional messages and adjusting communication style based on audience
Preferred experience working with financial services, healthcare, or regulated industries
Applicants must have authorization to work in the United States without current or future visa sponsorship.
Preferred Qualifications:
A Bachelor's Degree in a relevant IT or Cybersecurity major
Strong background in developing incident response plans, playbooks, and tabletop exercises
Certifications recommended: CISSP, CISA, CISM, or similar certification
Experience in client-facing roles with an ability to successfully manage multiple projects at once
We currently offer the following benefits:
Access to medical, dental, and vision insurance through Cigna, with the majority of the employee cost covered by the employer
Employer funding to HSA accounts and FSA access
Access to a 401(k) through Vanguard with a guaranteed employer contribution
Flexible vacation policy that allows you to manage your schedule and rest and recharge when you need to
11 holidays with flexibility based on what is important for you and those you love
Family-friendly benefits, including weeks off for Maternity leave, weeks off for non-birthing parent leave, employer-paid short-term and long-term disability, employer-paid life insurance, and access to additional life insurance, hospital coverage, accidental coverage, discounted mental health support, and more
Support for individual development through certifications, continued learning, conferences, and more