5+ years of experience in cybersecurity focusing on Governance, Risk, and Compliance (GRC)
Proficiency with various information security frameworks like NIST, ISO, and SOC
Experience in risk management, assessments, audits, and designing security controls
Familiarity with GRC tools for compliance management
Ability to manage multiple client engagements effectively
Strong verbal and written communication skills, adaptable to diverse audiences
Preferred certifications such as CISSP, CISA, or CISM
Responsibilities
Assist in planning and executing cybersecurity risk assessments
Develop roadmaps to enhance client maturity in cybersecurity
Maintain cybersecurity policies and procedures for clients
Review security controls against best practices and compliance requirements
Lead custom tabletop exercises for incident response preparedness
Document and communicate assessment results to clients
Collaborate with clients to identify and address information security challenges
Benefits
Comprehensive medical, dental, and vision insurance with significant employer coverage
Employer contributions towards Health Savings Accounts (HSA) and Flexible Spending Accounts (FSA)
Secure 401(k) plan with guaranteed employer contributions
Flexible vacation policy allowing for personal time management
11 holidays with customizable observations
Family-friendly leave options, disability coverage, and mental health support
Development opportunities through continued education and conferences
Full Job Description
Senior Risk Advisory Consultant - Remote (USA)
This is a remote position from anywhere in the USA
What You Will Do:
Assist in the planning, scoping, execution, and reporting of cybersecurity risk and maturity assessments against frameworks such as NIST CSF, ISO 27001, SOC 2, and CMMC
Collaborate with IT management and client leadership to develop roadmaps to enhance client maturity
Develop and maintain Cybersecurity policies and procedures while supporting clients
Review and assess security and technology controls against cybersecurity best practices and compliance frameworks
Collaborate with clients to develop Incident Response Plans, and Incident Response Playbooks tailored to each client's environment and needs
Lead end-to-end tabletop exercise engagements, developing realistic, client-specific scenarios that align with organizational people, processes, and technologies and effectively engage technical, management, and executive audiences
Document results, create client reports, and communicate results to client management and other stakeholders
Work collaboratively with our clients and other team members to identify information security risks and challenges and provide actionable recommendations and solutions
Demonstrate consistency, versatility, and adaptability while managing simultaneous client engagements and priorities and delivering quality results in a timely fashion
Work with the internal team to develop and plan engagement strategies, define objectives, identify and provide recommendations to address client risks
Create client-facing presentations, reports, and analytics
Develop long-term roadmaps to assist clients in reaching their desired maturity level
Perform business impact analyses and develop Business Continuity Plans and Disaster Recovery Plans
Assist leadership in the creation of proposals, budgets, work plans, and other business development efforts
Establish exceptional internal and client relationships using strong communication skills
Produce thought leadership for the organization's website blog on a regular basis
Actively engage in the cybersecurity community by attending or speaking at local or national conferences
Your knowledge, skills, and abilities:
5+ years of related experience in the cybersecurity industry
Focus on Governance, Risk, and Compliance planning, development, and management
Knowledge of GRC Platforms/Tools to assist with Assessments and Compliance Management
Risk management experience, including performing assessments and audits, designing information security controls and processes, and evaluating and prioritizing risk
Experience with a variety of information security frameworks and best practices (e.g., CIS, NIST, PCI, CMMC, ISO, GLBA, FFIEC, SOX, SOC, HIPAA, HITRUST, etc.)
Ability to lead engagements from scoping through delivery, including managing client expectations, timelines, and deliverables
Experience with incident response, business continuity, and disaster recovery planning is preferred
Ability to provide strategic guidance to clients on tabletop exercise design, incident preparedness, and resilience.
Project Management experience preferred
Ability to manage and prioritize multiple projects simultaneously and adapt in a demanding and changing environment
Although this is not a technical oriented role, knowledge of Cloud systems, applications, security services/tools (e.g., EDR, MDR, SIEM, Vulnerability Scanning, Email Security, Backup/DR, MDM), Firewalls, Basic Networking, Data Security, IAM/SSO, etc., will be beneficial in an advisory capacity
Ability to mentor and provide guidance to junior consultants and contribute to the development of internal methodologies and best practices
Strong attention to detail and superior analytical, technical, and problem-solving skills
Excellent verbal and written communication skills with experience crafting professional messages and adjusting communication style based on audience
Preferred experience working with financial services, healthcare, or regulated industries
Applicants must have authorization to work in the United States without current or future visa sponsorship.
Preferred Qualifications:
A Bachelor's Degree in a relevant IT or Cybersecurity major
Strong background in developing incident response plans, playbooks, and tabletop exercises
Certifications recommended: CISSP, CISA, CISM, or similar certification
Experience in client-facing roles with an ability to successfully manage multiple projects at once
We currently offer the following benefits:
Access to medical, dental, and vision insurance through Cigna, with the majority of the employee cost covered by the employer
Employer funding to HSA accounts and FSA access
Access to a 401(k) through Vanguard with a guaranteed employer contribution
Flexible vacation policy that allows you to manage your schedule and rest and recharge when you need to
11 holidays with flexibility based on what is important for you and those you love
Family-friendly benefits, including weeks off for Maternity leave, weeks off for non-birthing parent leave, employer-paid short-term and long-term disability, employer-paid life insurance, and access to additional life insurance, hospital coverage, accidental coverage, discounted mental health support, and more
Support for individual development through certifications, continued learning, conferences, and more