1 open position available
Assist in planning, executing, and reporting cybersecurity risk and maturity assessments, develop security policies, and collaborate on incident response planning. | 5+ years in cybersecurity, experience with industry frameworks and compliance standards, risk management skills, and client-facing consulting experience. | About us: At Echelon Risk + Cyber, we believe in defending the basic human right to security and privacy. We are looking for an exceptional Senior Risk Advisory Consultant to support the execution of Risk Advisory client engagements. This includes leading and executing relevant tasks, as well as assisting in developing service deliverables and internal processes that will drive value for the team and clients. Our next team member will be authentic, articulate, and passionate about Cybersecurity, and will be unafraid to roll up their sleeves and dive deep into the unknowns, using their security expertise to identify opportunities to increase Echelon Risk + Cyber's overall capabilities internally and for our clients. At Echelon, you will have the opportunity to engage with systems at the cutting edge of technology. We allow our employees to build from the ground up and make an impact across the organization. We look for driven, proactive people eager to contribute to a distinct and thriving Cybersecurity services organization that can adapt to a rapidly changing environment. This is a remote position from anywhere in the USA. What You Will Do: • Assist in the planning, scoping, execution, and reporting of cybersecurity risk and maturity assessments against frameworks such as NIST CSF, ISO 27001, HIPAA, and CMMC • Collaborating with IT management and client leadership to develop roadmaps to enhance client maturity • Develop and maintain Cybersecurity policies and procedures while supporting clients • Review and assess security and technology controls against cybersecurity best practices and compliance frameworks • Collaborate with clients to develop Incident Response Plans, Incident Response Playbooks, and Tabletop Exercises tailored to each client's environment and needs • Document results, create client reports, and communicate results to client management and other stakeholders • Work collaboratively with our clients and other team members to identify information security risks and challenges and provide actionable recommendations and solutions • Demonstrate consistency, versatility, and adaptability while managing simultaneous client engagements and priorities and delivering quality results in a timely fashion • Work with the internal team to develop and plan engagement strategies, define objectives, identify and provide recommendations to address client risks • Create client-facing presentations, reports, and analytics • Develop long-term roadmaps to assist clients in reaching their desired maturity level • Perform business impact analyses and develop Business Continuity Plans and Disaster Recovery Plans • Assist leadership in the creation of proposals, budgets, work plans, and other business development efforts • Establish exceptional internal and client relationships using strong communication skills • Produce thought leadership for the organization's website blog on a regular basis • Actively engage in the cybersecurity community by attending or speaking at local or national conferences Your knowledge, skills, and abilities: • 5+ years of related experience in the cybersecurity industry • Strong experience assessing clients against industry frameworks and certification standards, specifically ISO 27001/2, CMMC, and SOC2. • Focus on Governance, Risk, and Compliance planning, development, and management • Knowledge of GRC Platforms/Tools to assist with Assessments and Compliance Management • Risk management experience, including performing assessments and audits, designing information security controls and processes, and evaluating and prioritizing risk • Experience with a variety of information security frameworks and best practices (e.g., CIS, NIST, PCI, CMMC, ISO, GLBA, FFIEC, SOX, SOC, HIPAA, HITRUST, etc.) • Experience with incident response, business continuity, and disaster recovery planning is preferred • Project Management experience preferred • Certifications recommended: CISSP, CISA, CISM, or similar certification • Ability to manage and prioritize multiple projects simultaneously and adapt in a demanding and changing environment • Although this is not a technical oriented role, knowledge of Cloud systems, applications, security services/tools (e.g., EDR, MDR, SIEM, Vulnerability Scanning, Email Security, Backup/DR, MDM), Firewalls, Basic Networking, Data Security, IAM/SSO, etc., will be beneficial in an advisory capacity • Displays intellectual curiosity by seeking opportunities to develop and demonstrating a willingness to learn • Strong attention to detail and superior analytical, technical, and problem-solving skills • Excellent verbal and written communication skills with experience crafting professional messages and adjusting communication style based on audience • Preferred experience working with financial services, healthcare, or regulated industries • Applicants must have authorization to work in the United States without current or future visa sponsorship. Preferred Qualifications: • A Bachelor's Degree in a relevant IT or Cybersecurity major • Large consulting firm experience (Big 4 or equivalent) • Strong background in developing incident response plans, playbooks, and tabletop exercises • Experience in client-facing roles with an ability to successfully manage multiple projects at once Why Echelon? We are committed to creating an inclusive environment for our team with unquestioned integrity. If you have a special need that requires accommodation, please let your recruiter know. One of our core values in "People with Personality" and we want to allow you the space to bring your full self to work. We currently offer the following benefits: • Access to medical, dental, and vision insurance through Cigna with the majority of the employee cost covered by the employer • Employer funding to HSA accounts and FSA access • Access to a 401(k) through Vanguard with a guaranteed employer contribution • Flexible vacation policy that allows you to manage your schedule and rest and recharge when you need to. • 11 holidays with flexibility based on what is important for you and those you love • Employer-paid short-term and long-term disability, employer-paid life insurance, and access to additional life insurance, hospital coverage, accidental coverage, discounted mental health support, and more. • Support on individual development through certifications, continued learning, conferences, and more We value a diverse workforce and a culture of inclusivity and belonging. All employment decisions shall be made without regard to age, race, creed, color, religion, gender, national origin, ancestry, disability status, veteran status, sexual orientation, gender identity or expression, genetic information, marital status, citizenship status or any other basis as protected by federal, state, or local law. Echelon Risk + Cyber is an Equal Opportunity Employer.
Create tailored applications specifically for Echelon Risk + Cyber with our AI-powered resume builder
Get Started for Free