Sr. Technology Risk Consultant

4 weeks ago


Seattle, United States ITmPowered, LLC Full time

Sr. Technology Risk Consultant – Medical Device / IoT Cybersecurity – ITmPowered Serve as Sr. Technology Risk Consultant on behalf of Technology Risk Management organization in support of a national Medical Device / IoT Cybersecurity Program. Technology Risk consultant helping the medical device cybersecurity program and clinical healthcare technology group understand the cyber and regulatory landscape and how best to align with cyber, privacy and industry framework requirements including but not limited to: NIST CSF, NIST SP 800-53, HIPAA, FDA cybersecurity, Cyber Executive Orders, etc. Help build an effective Medical Device cybersecurity risk management program that helps the Clinical Technology group manage the risks against control framework commitments, regulatory obligations, and cyber threats to their Board/stakeholders. Responsibilities: Perform Medical Device cyber risk assessments to determine whether NIST Controls, HIPAA, regulatory and cybersecurity requirements are being effectively met through control design and execution. Lead and facilitate cyber risk assessments end to end; Scoping, Planning, Fieldwork (NIST controls testing and evidence gathering), and Reporting findings, risks, remediation / corrective action plans. Advise on Cyber Risk Controls design, risk mitigation design, compensating controls, and risk reduction. Consult on Medical Device Cybersecurity Controls baselines and hardening guides across device families. Perform risk assessments on Med Device cybersecurity program tools (IAM, PAM, micro firewalls, netseg). Advise on integration of baseline security practices into corporate medical device security framework in alignment with NIST 800-53 and HIPAA, frameworks. Advise on mapping IT Risk processes to Medical Device Cyber Risk processes, intake, workflows, workloads, process steps, actions, documentation, and reporting. Provide Risk Advisory guidance to Medical Device cyber program practitioners on effective risk assessment processes, controls frameworks and standards, hardening guides and baselines, risk reporting and remediation. Set upfront expectations with stakeholders on assessment process, scope, plan, schedule, stakeholder involvement, assessment reports, remediation planning, corrective action plans – to drive risk reduction. Write clear, effective, succinct, Cyber Risk Assessment documentation and templates including Cyber Risk Assessment Reports, Executive Summaries, Detailed Risk Reports, Remediation plans, Corrective Action Plans, and clear recommendation guidance on effective Controls Design and implementation. Communicate fluidly with Clinical Healthcare Technology Managers, medical device cybersecurity operations with clear, succinct, digestible information that resonates with each audience and drives risk reduction. Qualifications / Skills / Abilities: Education: Bachelor’s Degree in information systems is preferred or 5+ years of equivalent work experience. 5+ years of IT Audit, Risk Management, Risk Assessment, or Cybersecurity Risk Assessment experience. CISA, CISM, and/or CISSP Certifications are preferred. IoT / Med Device Cybersecurity background – Assessing patient monitoring devices, Wearable Med Devices, Laboratory / Imaging /radiology devices, Medical Facility Controls (Badging, cameras, doors, elevators). Experience with risk / control frameworks / standards: NIST SP 800-53, NIST CSF, HITRUST, etc. Familiarity with HIPAA Security, IT controls, and controls mapping. FDA cybersecurity guidance preferred. Familiarity with OWASP Top 10, CIS Top 20 Controls. Ability to lead and facilitate end to end cyber risk assessments (Scope, Plan, Kickoff, Fieldwork, Report). Ability to manage multiple assessment projects with broad scope, ambiguity, and high degree of difficulty. Strong writing and verbal communication skills to convey technical and risk concepts to non-experts. Flexibility in the face of changing priorities and business needs. Independently research new topics and present executive summaries. Preferred Experience / Nice to have: Prior experience IT Auditing / Cyber / Risk Assessing – Medical Devices. Background in Clinical Healthcare Technology Management (CHTM / CBET / etc.). Familiarity with CMMS / Medical device asset management systems, FDA/TJC regulations, medical device vendor cybersecurity (MDS2/CBOM), CHTM asset onboarding and certification processes. #J-18808-Ljbffr



  • Seattle, United States ITmPowered, LLC Full time

    Sr. Technology Risk Consultant – Medical Device / IoT Cybersecurity – ITmPowered Serve as Sr. Technology Risk Consultant on behalf of Technology Risk Management organization in support of a national Medical Device / IoT Cybersecurity Program. Technology Risk consultant helping the medical device cybersecurity program and clinical healthcare technology...


  • Seattle, Washington, United States ITmPowered, LLC Full time

    Position Overview:The Senior Consultant for Technology Risk Management will play a pivotal role in the Technology Risk Management organization, focusing on a national initiative related to Medical Device and IoT Cybersecurity. This position involves guiding the medical device cybersecurity program and clinical healthcare technology teams in navigating the...


  • Seattle, Washington, United States ITmPowered, LLC Full time

    Position Overview:The Senior Consultant for Technology Risk Management will play a pivotal role in the Cybersecurity division at ITmPowered, focusing on the national initiative for Medical Device and IoT Cybersecurity. This position is integral in guiding the clinical healthcare technology sector through the complexities of cyber threats and regulatory...


  • Seattle, Washington, United States CrossCountry Consulting Full time

    Join CrossCountry Consulting's Expanding Risk and Compliance PracticeOur Technology Risk Advisory team is experiencing significant growth. We specialize in delivering comprehensive services that encompass IT governance, risk management, cybersecurity, cloud solutions, privacy, data protection, system implementations, third-party risk oversight, data...


  • Seattle, United States Amazon Full time

    Sr. Risk Analyst, Global Risk Management and Claims Amazon’s Global Risk Management and Claims team is seeking a Sr. Risk Analyst to assist with the development and management of Amazon’s global insurance programs, including supporting global insurance program management (Property, Builders Risk and Owner Controlled Insurance Program - OCIP, and other...


  • Seattle, Washington, United States Apple Full time

    About the RoleWe are seeking a highly skilled and experienced Enterprise Risk Manager - Technology to join our team at Apple. As a key member of our risk management function, you will be responsible for leading a team that develops and coordinates the overall technology risk management framework for the company.Key ResponsibilitiesLead a team that supports,...


  • Seattle, Washington, United States Ksense Technology Group Full time

    Job OverviewCompany IntroductionKsense Technology Group is a prominent software development and consulting organization based in the U.S., dedicated to delivering tailored business operations software solutions. Our expertise lies in comprehensive workflow assessments aimed at resolving operational challenges across diverse sectors.Role SummaryWe are in...

  • Associate Director

    1 month ago


    Seattle, United States CrossCountry Consulting Full time

    From the beginning, our goal was to establish an advisory firm that stands apart from the rest – one that is grounded in our Core Values and dedicated to creating a positive experience not just for our clients, but for our people too. We firmly believe in the strength of collaboration, enthusiasm, generosity, and perseverance as the driving forces behind...


  • Seattle, Washington, United States Edjuster Full time

    Position OverviewEdjuster is seeking a Tech Due Diligence Consultant to engage in a freelance, part-time capacity focused on assessing software design, architecture, and engineering methodologies.This role is ideal for seasoned professionals looking to leverage their extensive experience in a dynamic environment that values the latter stages of a career.Role...

  • Principal Consultant

    2 weeks ago


    Seattle, United States Infosys Consulting Full time

    Position: Risk and Controls - GRCRole: PrincipalAbout the RoleThe Principal Consultant role is within the Infosys Consulting unit in the Financial Services vertical of Infosys. The Infosys Consulting unit focuses on partnering with senior business and technology stakeholders of our clients to help craft and execute their strategy.Role expects you to:Lead...

  • Principal Consultant

    2 weeks ago


    Seattle, United States Infosys Consulting Full time

    Position: Risk and Controls - GRC Role: Principal About the Role The Principal Consultant role is within the Infosys Consulting unit in the Financial Services vertical of Infosys. The Infosys Consulting unit focuses on partnering with senior business and technology stakeholders of our clients to help craft and execute their strategy. Role expects you...


  • Seattle, Washington, United States Edjuster Full time

    Position OverviewAs a Tech Due Diligence Consultant at Edjuster, you will engage in a freelance, part-time role focused on assessing software design, architecture, and engineering methodologies.This position is ideal for seasoned professionals looking to leverage their extensive experience in a collaborative environment.Key ResponsibilitiesIn this role, you...


  • Seattle, Washington, United States Databricks Full time

    CSQ225R71This position can be remote.As a Sr. Solutions Consultant in our Professional Services team, you will work with customers on short to medium term customer engagements on their big data challenges using the Databricks platform. You will be in a customer-facing role that requires deep hands-on expertise in Apache SparkTM and data engineering, along...


  • Seattle, Washington, United States Aldridge Full time

    Job DescriptionAre you a passionate technologist who prefers consulting with clients over administering networks and servers? Do you thrive when you are learning about new businesses, building relationships, and guiding clients to understand how technology can accelerate their success? If so, read on.Job Summary:Aldridge is seeking a highly skilled Principal...


  • Seattle, Washington, United States AXA Group Full time

    Senior Risk Management Consultant - Property In today's intricate and unpredictable environment, large enterprises require a reliable partner to enhance their risk management strategies. AXA XL Risk Consulting, a division of AXA XL Insurance, provides support in the following areas: Assisting underwriters in evaluating the risks associated with AXA XL's...


  • Seattle, Washington, United States Amazon Full time

    About Amazon: At Amazon, our mission is to be the most customer-focused organization globally, which includes safeguarding our customers and their information. Role Overview: We are in search of a skilled technology auditor to join our Internal Audit team, focusing on audits across our diverse business units. Key Responsibilities: Conduct comprehensive...


  • Seattle, Washington, United States XL CATLIN Full time

    Position Overview - Senior Property Risk Consultant – Field EngineerJob Number: D In an increasingly intricate and unpredictable environment, large corporations require a dependable partner to enhance their risk management strategies. AXA XL Risk Consulting, a segment of AXA XL Insurance, provides essential support to:Underwriters in evaluating the risks...


  • Seattle, Washington, United States XL CATLIN Full time

    Position Overview - Senior Property Risk Consultant – Field EngineerJob Number: DIn an increasingly intricate and unpredictable environment, large corporations require a dependable partner to enhance their risk management strategies. AXA XL Risk Consulting, a division of AXA XL Insurance, is dedicated to supporting:Underwriters in evaluating the risks...


  • Seattle, Washington, United States ITmPowered, LLC Full time

    Position Overview:The Senior Cybersecurity Risk Consultant will play a pivotal role within the Technology Risk Management division, focusing on a national initiative for Medical Device and IoT Cybersecurity. This role is essential in guiding the clinical healthcare technology sector through the complexities of the cyber and regulatory environment, ensuring...


  • Seattle, United States Artmac Soft LLC Full time

    Job DescriptionJob DescriptionWho We Are: Artmac Soft is a technology consulting and service-oriented IT company dedicated to providing innovative technology solutions and services to customers.Job Description Job Title : Sr. SAP FICO Consultant - Financial & Controlling Systems SpecialistJob Type : W2 Experience : 8 - 12 years Location : Seattle,...