Cyber Security Consultant

2 months ago


New York, United States OTC Markets Group Full time

OTC Markets Group, a regulated fintech company, is seeking an Information Security Consultant for a period of 6 months in a full time capacity. Applicants for this role should have capability to travel to the NYC office whenever required.


Responsibilities:

• Policy and Procedure Management: Review, update, and enhance all relevant policies and procedures to ensure the company’s compliance with SEC Regulation SCI and ISO 27001 requirements. Develop and implement new policies as needed to address emerging security threats and regulatory changes.

• Risk Management: Assist with organizing and running external risk assessments, ensure proper documentation of identified risks, develop risk mitigation plans and follow through on their implementation. Implement continuous monitoring strategies with regular reports to senior management.

• Access and Identity Management: Enhance and implement procedures for reviewing access authorizations, especially during personnel transfers and third-party engagements. Enhance controls around privileged system accounts and administrative access. Conduct regular audits to ensure access controls are effective and compliant.

• Incident Response and Business Continuity: Enhance and formalize incident response plans, including regular testing and integration with other organizational plans. Enhance business continuity and disaster recovery plans, ensuring detailed procedures and roles are defined.

• Data Protection and Encryption: Implement data loss prevention controls and encryption protocols. Help improve policies for data classification, retention, and destruction. Conduct regular audits to ensure data protection measures are effective.

• Training and Awareness: Maintain a comprehensive security awareness training program, including insider threat and incident response training. Update training content to address new threats and compliance requirements.

• Vendor and Third-Party Management: Establish and enforce security requirements for third-party vendors. Conduct periodic assessments of vendors and review of applicable CUICs – Complimentary User Entity Controls.

• Governance, Risk, and Compliance (GRC): Enhance and implement a comprehensive GRC framework that integrates governance, risk management, and compliance activities across the organization. Ensure alignment with industry standards and regulatory requirements and facilitate regular GRC audits and assessments to identify and mitigate potential gaps.

• Security Operations: Assist with maintaining the firm’s security tools and daily processes such as security reviews, applications approvals, and change management approvals. Ensure security operations are aligned with organizational goals and regulatory requirements.

• Security Monitoring and Incident Detection: help manage security information and event management (SIEM) systems to monitor network and system activities for signs of security breaches. Ensure timely detection and response to potential security incidents.

• Threat Intelligence and Vulnerability Management: Continuously gather and analyze threat intelligence to stay ahead of emerging threats. Conduct regular vulnerability assessments and penetration testing to identify and remediate security weaknesses.

• Security Incident Response: Assist with the response to security incidents, including investigation, containment, eradication, and recovery. Maintain detailed incident logs and conduct post-incident reviews to improve response processes.

• Security Metrics and Reporting: Enhance and maintain security metrics to measure the effectiveness of security operations. Provide regular reports to senior management on security posture, incident trends, and areas for improvement. Use metrics to drive continuous improvement in security practices.



Requirements:

• Bachelor's degree in Information Security, Cybersecurity, or a related field. Advanced degree preferred.

• Relevant certifications such as CISSP, CISM, CISA, or ISO 27001 Lead Implementer are highly desirable.

• At least 5 years of experience in cybersecurity, information security, information technology, engineering, risk management, compliance or a related field, preferably within the financial services industry.

• Demonstrated experience with regulatory compliance such as SEC Regulation SCI requirements.

• Proficiency with ISO 27001 standard, CIS Benchmarks, risk assessment methodologies, and implementation of security controls.

• Proven successful track record of developing, documenting, and implementing security policies and procedures.

• Excellent risk assessment and management skills.

• Strong knowledge of access and identity management best practices.

• Experience in incident response, business continuity planning, capacity planning and stress testing.

• Demonstrated expertise in managing third-party vendor relationships, including conducting security assessments.

• Familiarity with data protection and encryption technologies.

• Excellent communication with the ability to present complex security issues to senior management and stakeholders.

• Excellent analytical skills with the ability to identify security gaps and develop effective remediation plans.

• High level of attention to detail in documenting and implementing security policies and procedures.


The compensation for this position is anticipated between $130-170/hr.


For more information about OTC Markets Group, please visit our public policy advocacy and careers page. No calls or e-mails please.



  • New York, United States hackajob Full time

    hackajob has partnered with a multi-faceted team focused on the evaluation, strategy definition, and execution of risk-minded solutions for leading organizations across the Financial Services industry. We are currently seeking for a Sr. Cybersecurity Consultant who can design and develop security policies, standards and procedures across various...


  • New York, United States Mission Staffing Full time

    Our client, a well-known financial services firm in Midtown, NY, is looking to add a Cyber Security Associate to their team! This person will be responsible for handling and responding to L1 and L2 SOC tickets, running security threat investigations, and managing and remediating the firm's Vulnerability Management Process. The ideal candidate will have at...


  • New York, United States Mission Staffing Full time

    Our client, a well-known financial services firm in Midtown, NY, is looking to add a Cyber Security Associate to their team! This person will be responsible for handling and responding to L1 and L2 SOC tickets, running security threat investigations, and managing and remediating the firm's Vulnerability Management Process. The ideal candidate will have at...


  • New York, New York, United States ION Group Full time

    We are seeking a Cyber Security Consultant to join our newly created sub-practice, dedicated to serving a mature and impactful long-term client in the financial services industry. This role requires a balance of independent work and teamwork, focusing on advancing the client's agenda. The ideal candidate will possess some understanding of the financial...


  • New York, New York, United States WithSecure Full time

    About the RoleWe are seeking a highly skilled and experienced Cyber Security Sales Executive to join our team at WithSecure. As a key member of our sales team, you will be responsible for driving new business growth and expanding our presence in the enterprise cyber security consulting market.Key ResponsibilitiesSales and Business Development: Identify and...


  • New York, United States Iceberg Cyber Security Full time

    I’m currently representing an upcoming leader in cybersecurity, providing cutting-edge solutions and testing services. Their current mission is to venture into the world of hardware and embedded testing and they are looking for a leader to join as a principal Embedded Security Tester and develop new offensive security offerings.As an Embedded Security...


  • New York, New York, United States IIT, Inc. Full time

    Job Overview: This role focuses on the design and implementation of robust security architectures and frameworks to safeguard enterprise information.Key Responsibilities:Assess security needs by analyzing business objectives and requirements; conduct comprehensive security evaluations and vulnerability assessments.Design security infrastructures by...


  • New York, New York, United States Booz Allen Hamilton Full time

    Job Number: R0197452Cyber Strategy and Risk Advisory ConsultantThe Opportunity: The cyber landscape is continuously changing due to several driving factors such as dynamic cyber threats, hyperconnected technologies such as IT, OT, IoT, and Product, technology change, cloud migration, and regulatory reform. As a result, organizations are facing increased...


  • New York, New York, United States IIT, Inc. Full time

    Job Overview: This role focuses on the design and implementation of robust security architectures and solutions to safeguard enterprise information.Key Responsibilities:Assess security needs by analyzing business strategies and requirements; review information security standards; conduct security assessments and vulnerability evaluations; and identify...


  • New York, United States Booz Allen Hamilton Full time

    Job Number: R0197452 Cyber Strategy and Risk Advisory Consultant The Opportunity: The cyber landscape is continuously changing due to several driving factors such as dynamic cyber threats, hyperconnected technologies such as IT, OT, IoT, and Product, technology change, cloud migration, and regulatory reform. As a result, organizations are facing...


  • New York, United States Itech Edge Llc Full time

    Job DescriptionJob Description Find attached the JD for Cyber Security Architect Role. Please note that candidates must be a US Citizen Please fill out the attached Skillset matrix for the candidate you are submitting along with the resume for quicker response. Cyber Security Architect Job details Requirement Candidate must be a US Citizen Schedule 8 hour...

  • Cyber Security Manager

    2 months ago


    New York, United States StaffHost digital Full time

    Cyber Risk Manager - Global Leading Consultancy - New York, USCompany:StaffHost have been exclusively selected by our client to assist in growing their cybersecurity practice. Our client is one of the most recognisable companies globally, with one of the fastest growing cyber practices in New York.Our client is looking Managers/Senior Managers to win, advise...


  • New York, New York, United States Iceberg Cyber Security Full time

    Become a Key Player as a Litigation Support Counsel at Iceberg Cyber SecurityAre you a meticulous legal expert with a strong interest in litigation and evidence management? We are looking for a talented Litigation Support Counsel to enhance our innovative legal team at Iceberg Cyber Security.About Us: Iceberg Cyber Security is a premier firm recognized for...


  • New York, New York, United States IFM Investors Full time

    About the RoleWe are seeking an experienced Executive Director to lead our Information Technology function in the northern hemisphere. This strategic leadership role will be responsible for the management and execution of our IT operations, providing strategic direction and leadership to drive a culture of excellence within the Global Operations and IT...


  • New York, New York, United States IIT, Inc. Full time

    Job Overview: This role focuses on the design and implementation of robust security architectures and solutions tailored to meet organizational needs.Key Responsibilities:Assess security requirements by analyzing business strategies and conducting comprehensive security evaluations.Design security systems by evaluating existing technologies and developing...


  • New York County, New York, United States Aon Corporation Full time

    Position Overview:Aon Corporation is seeking a Cyber Security Senior Advisor specializing in Defense and Transformation.This role within the Defense and Transformation service line will be integral to a collaborative Proactive Security Services team, responsible for executing and delivering a variety of Security Advisory projects for our clientele.Aon's...


  • New York, New York, United States IIT, Inc. Full time

    Position Overview: The role focuses on the design and implementation of robust security architectures to safeguard enterprise information.Key Responsibilities:Assess security needs by analyzing business objectives and requirements; reviewing security standards; performing system security evaluations; examining architecture/platform; identifying integration...


  • New York, New York, United States IIT, Inc. Full time

    Position Overview: The role focuses on the design and implementation of robust security architectures and frameworks to safeguard enterprise information.Key Responsibilities:Assess security needs by analyzing business strategies and requirements, conducting vulnerability assessments, and identifying integration challenges.Design security systems by...


  • New York, New York, United States Cyber Spring Full time

    Cyber Spring is seeking an experienced Information Security Compliance Manager to enhance our cybersecurity initiatives.This pivotal role involves conducting comprehensive gap assessments, analyzing security controls, and reviewing documentation to provide critical security recommendations across the organization. The successful candidate will collaborate...


  • New York, New York, United States Capital One Financial Corp Full time

    Location: United States of AmericaPosition: Lead Cyber Security Logging SpecialistCompany Overview: Capital One Financial Corp is seeking a Lead Cyber Security Logging Specialist to become a vital part of our Cyber Security Logging team. This team plays a crucial role in facilitating extensive cyber surveillance. We ensure that standardized log events are...