5+ years of experience in cybersecurity, focused on Governance, Risk, and Compliance (GRC)
Familiarity with GRC tools for assessments and compliance management
Proficiency in various information security frameworks (e.g., NIST, ISO, SOC)
Strong project management skills, including managing client expectations and deliverables
Experience with incident response and disaster recovery planning preferred
Excellent communication skills, capable of adjusting style based on audience
Ability to mentor junior consultants and contribute to internal methodologies
Responsibilities
Plan and execute cybersecurity assessments using established frameworks like NIST CSF and ISO 27001
Collaborate with clients to create roadmaps for enhancing cybersecurity maturity
Develop and maintain tailored cybersecurity policies and procedures
Assess security controls for compliance with best practices and frameworks
Lead tabletop exercises to test client incident response capabilities
Document findings and communicate effectively with client management
Identify and provide strategic recommendations for information security risks
Benefits
Comprehensive medical, dental, and vision insurance with employer covering most costs
Employer funding for HSA and access to FSA
401(k) with guaranteed employer contribution
Flexible vacation policy allowing personalized time off
11 holidays with adaptable observance for personal importance
Family-friendly benefits including maternity and non-birthing parent leave, disability coverage, and mental health support
Support for professional development through certifications and continued learning opportunities
Full Job Description
Senior Risk Advisory Consultant - Remote (USA)
This is a remote position from anywhere in the USA
What You Will Do:
Assist in the planning, scoping, execution, and reporting of cybersecurity risk and maturity assessments against frameworks such as NIST CSF, ISO 27001, SOC 2, and CMMC
Collaborate with IT management and client leadership to develop roadmaps to enhance client maturity
Develop and maintain Cybersecurity policies and procedures while supporting clients
Review and assess security and technology controls against cybersecurity best practices and compliance frameworks
Collaborate with clients to develop Incident Response Plans, and Incident Response Playbooks tailored to each client's environment and needs
Lead end-to-end tabletop exercise engagements, developing realistic, client-specific scenarios that align with organizational people, processes, and technologies and effectively engage technical, management, and executive audiences
Document results, create client reports, and communicate results to client management and other stakeholders
Work collaboratively with our clients and other team members to identify information security risks and challenges and provide actionable recommendations and solutions
Demonstrate consistency, versatility, and adaptability while managing simultaneous client engagements and priorities and delivering quality results in a timely fashion
Work with the internal team to develop and plan engagement strategies, define objectives, identify and provide recommendations to address client risks
Create client-facing presentations, reports, and analytics
Develop long-term roadmaps to assist clients in reaching their desired maturity level
Perform business impact analyses and develop Business Continuity Plans and Disaster Recovery Plans
Assist leadership in the creation of proposals, budgets, work plans, and other business development efforts
Establish exceptional internal and client relationships using strong communication skills
Produce thought leadership for the organization's website blog on a regular basis
Actively engage in the cybersecurity community by attending or speaking at local or national conferences
Your knowledge, skills, and abilities:
5+ years of related experience in the cybersecurity industry
Focus on Governance, Risk, and Compliance planning, development, and management
Knowledge of GRC Platforms/Tools to assist with Assessments and Compliance Management
Risk management experience, including performing assessments and audits, designing information security controls and processes, and evaluating and prioritizing risk
Experience with a variety of information security frameworks and best practices (e.g., CIS, NIST, PCI, CMMC, ISO, GLBA, FFIEC, SOX, SOC, HIPAA, HITRUST, etc.)
Ability to lead engagements from scoping through delivery, including managing client expectations, timelines, and deliverables
Experience with incident response, business continuity, and disaster recovery planning is preferred
Ability to provide strategic guidance to clients on tabletop exercise design, incident preparedness, and resilience.
Project Management experience preferred
Ability to manage and prioritize multiple projects simultaneously and adapt in a demanding and changing environment
Although this is not a technical oriented role, knowledge of Cloud systems, applications, security services/tools (e.g., EDR, MDR, SIEM, Vulnerability Scanning, Email Security, Backup/DR, MDM), Firewalls, Basic Networking, Data Security, IAM/SSO, etc., will be beneficial in an advisory capacity
Ability to mentor and provide guidance to junior consultants and contribute to the development of internal methodologies and best practices
Strong attention to detail and superior analytical, technical, and problem-solving skills
Excellent verbal and written communication skills with experience crafting professional messages and adjusting communication style based on audience
Preferred experience working with financial services, healthcare, or regulated industries
Applicants must have authorization to work in the United States without current or future visa sponsorship.
Preferred Qualifications:
A Bachelor's Degree in a relevant IT or Cybersecurity major
Strong background in developing incident response plans, playbooks, and tabletop exercises
Certifications recommended: CISSP, CISA, CISM, or similar certification
Experience in client-facing roles with an ability to successfully manage multiple projects at once
We currently offer the following benefits:
Access to medical, dental, and vision insurance through Cigna, with the majority of the employee cost covered by the employer
Employer funding to HSA accounts and FSA access
Access to a 401(k) through Vanguard with a guaranteed employer contribution
Flexible vacation policy that allows you to manage your schedule and rest and recharge when you need to
11 holidays with flexibility based on what is important for you and those you love
Family-friendly benefits, including weeks off for Maternity leave, weeks off for non-birthing parent leave, employer-paid short-term and long-term disability, employer-paid life insurance, and access to additional life insurance, hospital coverage, accidental coverage, discounted mental health support, and more
Support for individual development through certifications, continued learning, conferences, and more