tags

Sr. Consultant - Governance, Risk & Compliance (GRC) for CyberOne in Plano, TX (salary not disclosed)

Sr. Consultant - Governance, Risk & Compliance (GRC) for CyberOne in Plano, TX (salary not disclosed)

By Jody · October 25, 2023

Responsible for serving clients and ensuring the successful execution of Information Security & Privacy projects such as data privacy impact assessments, consulting on strategic initiatives to improve an organization’s security program, and much more.  Develop lasting relationships with client personnel and seek to further these relationships through quality product delivery.  Responsible for understanding their client’s business and continual demonstration of technical expertise in the Information Security & Privacy field. Develop contacts within the business community and serve as ambassadors of CyberOne in the market.

Essential Functions

    • Previous functional experience in the areas of Cybersecurity, privacy, data protection, and GRC management.
    • Engage with customers through Virtual CISO services to build cyber strategies aligning with business objectives while improving customer’s security position.
    • Experience with implementation of Information Security or Data Protection programs, including assessment of information security, privacy, and data protection controls across IT systems.
    • Experience with identification and assessment of security and data protection risks, including research, recommendation, and implementation of risk mitigation strategies.
    • Develop reporting metrics, dashboard, and evidence artifacts to address GRC program requirements.
    • Experience with communication of Cybersecurity topics (including risk) to management and business stakeholders.
    • Knowledge of information system architecture and security controls (i.e., Cloud, firewall, operating systems, wireless architectures, databases, 3rd party risk, information security policies and procedures).
    • Experience with one or more of the following information security frameworks (PCI, CMMC, ISO, NIST, etc.).
    • Experience with one or more of the following compliance regulations (GDPR, GLBA, HIPAA, CCPA).
    • Demonstrate in-depth technical capabilities and professional knowledge and demonstrate the ability to assimilate new knowledge proactively.
    • Remain current on new developments in GRC technology implementation services capabilities and industry knowledge.
    • Knowledge of present-day security topics and concerns.
    • Active participation in information security conferences.

Education/Experience/ Required Experience
8-10 years’ experience implementing and delivering GRC technology enablement services using GRC/IRM platforms, i.e., Policy and Compliance Management, Supplier Risk Management, Cyber-Risk Management, Audit Management, Business Continuity, and other risk management processes.
5-6 years’ experience performing supplier risk assessment and management services.
8+ years’ experience leading discussions and services with clients to create a risk-aware culture through proper technology enablement of risk-related processes using GRC/ IRM solutions.
8-10 years’ experience implementing and delivering GRC technology enablement services using GRC/IRM platforms, i.e., Policy and Compliance Management, Supplier Risk Management, Cyber-Risk Management, Audit Management, Business Continuity, and other risk management processes.
5-6 years’ experience performing supplier risk assessment and management services.
8+ years’ experience leading discussions and services with clients to create a risk-aware culture through proper technology enablement of risk-related processes using GRC/IRM solutions.
8-10 years’ experience designing and architecting solutions to automate client processes into GRC solutions to meet their unique requirements.5+ years of relevant consulting or industry experience, preferably in a professional services environment. (Big 4 is a plus).
5+ years' experience performing security and risk maturity assessments against the following frameworks and regulations, but not limited to,

- NIST Cybersecurity Framework (CSF)

- PCI DSS

- ISO 27001/27002

- CMMC

- GDPR and CCPA

- NIST 800-53

- Unified Compliance Framework (UCF)

- GLBA

- COBIT

- SOC Type 1 and 2

- Sarbanes Oxley

Preferred Education / Experience

Bachelor’s degree in relevant discipline (e.g.  MIS, CIS) preferred.

Certificate and License Requirements
Professional certifications such as CISSP, CISA, CRISC, CGEIT, GRCP. or other relevant certifications.

Skills/Abilities

    • Prior project management and supervisory skills ideal.
    • Demonstrated understanding of the importance of business ethics.
    • Sound job administration skills.
    • Above average written communication skills including documentation of findings and recommendations.
    • Strong analytical skills.
    • Ability to handle highly confidential information in a strictly professional manner.
    • Ability to maintain professional demeanor in times of high stress.
    • Excellent customer service skills to foster relationships and interact with local and remote clients in a persuasive and confident manner.
    • Above average organizational and time management skills.
    • Effective communication skills (verbal and written) including interaction with Sr. leadership, peers and team members.
    • Multi-Tasking and Time Management Skills; can adapt to a changing, fast-paced environment.
    • This role routinely uses standard office equipment such as laptop computers and smartphones.

Work Environment

    • Work is performed indoors in a climate-controlled environment.
    • Travel may be required up to 30%.
    • May be required to work evenings, weekends to meet company and customer needs.
    • Must be able to remain in a stationary position 50% of the time.
    • Must be able to move about inside a professional office environment.
    • An environment that empowers employees to contribute to an organization that embraces a fail-fast mentality.
    • An open, supportive, fast paced, and collaborative work environment.

For more info.: https://hubs.ly/Q026NB7L0

Ready to see your fabric?

Request a demo of ControlSight and see how Unified Compliance connects mandates, policies, and controls into one living fabric.