Sr. Risk Management Consultant
12 hours ago
Remote - except for week 1 and quarterly
What are the top 3 skills required for this role?
o Assurance guidelines, risk factors, Risk is controlled and managed across projects.
o Risk Assessment, Security Policy being met, Any Risk being highlighted, managed and documented in ISG tool GRC ( ServiceNow, Archer)
o Represent ISG to follow Risk Constitution
Job Description/ Responsibilities
Specific responsibilities include:
1. Senior individual contributor for information security risk management projects. Sample projects/programs could include but are not limited to:
a) Control design and assessment for high-demand technical areas such as ERP, IT Service Management, Identity and Access Management, IT Resiliency, Cloud, etc.
b) Compliance framework mapping and implementation,
c) Risk remediation management,
d) Information Security risk reporting and monitoring
e) Creation of roadmaps to mature or advance Information Security Strategies/Programs/Controls
f) Design and enablement of cyber controls functions and processes
g) Direct experience as a power user of Cybersecurity GRC/ solutions, tools, and technologies, specifically ServiceNow and Archer
h) Projects or roles requiring coordination across lines of defense working with technical, business, compliance, risk, and audit teams to deliver solutions.
2. Delivery of information security risk assessments for large-scale IT implementation projects including consulting with security architecture function for threat modeling, appropriate tiering of N tier products/platforms, design of infrastructure security controls to protect system components.
3. Practical use of risk management concepts and principles - including assessment, prioritization, delivery of treatment plans, tracking and reporting. Experience with NIST-SP800-30, ISO 27001/2, ISO 27005, COBIT.
4. Consult and review the implementation of authentication, authorization (fine grained and coarse grained), and cryptography (PKI, SSL, Kerberos, crypto algorithms) mechanisms within applications.
5. Consult with security assurance function on the delivery of technical security standards, configuration baselines and related procedures for the hardening of both cloud and non-cloud application and infrastructure components, tools, and techniques to ensure the security of application and infrastructure components such as LINUX/Windows servers, Web servers (IIS, Apache, tomcat), app servers, Databases (Oracle and MS SQL), endpoints (MAC, Windows, Apple IOS, etc.), and Web Application Firewalls.
6. Collaborate with other security functions e, g. security architecture, security assurance, offensive security team (red/purple team), application security penetration testing team, to review and apply appropriate risk levels to the output of the assessments performed by the functions.
7. Maintain impartiality around IT systems to produce unbiased reports on information security risk.
8. Works closely with IT project teams to develop implementation plans for new security-related products and services.
9. Conducts quality assurance reviews of security requirements for the implementation of identified solutions.
10. Define/enhance process and procedures for using external security service providers including scoping, management of services, remediation tracking, and exception management.
11. Effectively communicates requirements and trains staff and managers in IT divisions to identify and manage risks throughout the project lifecycle.
12. Where applicable, manages the engagement process of external risk assessment providers and acts as a liaison with internal IT project teams and business units.
13. As an advocate of information security, works closely and proactively with IT project team leaders, service providers, and business units to provide security-related technical solutions. Identifies opportunities to improve business practices or IT security-related processes.
14. Other ad hoc responsibilities may include:
a) Analyzes, recommends, and implements process improvements within the context of information security.
b) Support governance activities for Identity and Access Management, where requested.
Experience must include:
1. Prior work in a technical cybersecurity risk management function at organizations with security related regulatory requirements.
2. Practical use of risk management concepts and principles - including assessment, prioritization, delivery of treatment plans, tracking and reporting, and metrics (accreditation and certification). Experience with NIST-SP800-30, ISO 27001/2, ISO 27005, COBIT.
3. Embedding security into processes such as SDLC, Project Lifecycle, ITIL, etc.
4. Demonstrated cybersecurity expertise with infrastructure, applications, and database system technologies.
5. Basic IT consultancy skills. Ability to consult and deliver on the security hardening of application and infrastructure components, including tools, and techniques to ensure the security of application, database, and infrastructure components.
6. Pragmatic security expert with an inherent ability to balance security demands with business reality. Ability to quickly grasp how new technologies work and how security controls should be applied to achieve business goals.
7. Knowledge of security solutions, latest threats, and countermeasures.
Required Soft Skills
1. Familiarity with a broad range of security technologies supplemented by in-depth knowledge in specific areas of relevance.
2. Ability to quickly grasp how new technologies work and how they might be applied to achieve business goals.
3. Analytical skills that enable synthesis of inputs from many sources and allow for strategic thinking and tactical implementation.
4. Pragmatic security expert with an inherent ability to balance security demands with business reality.
5. Excellent relationship management skills
6. Ability to think laterally and to have input to / propose detailed, complex solutions to technical issues.
Required Soft Skills
1. Analytical skills that enable synthesis of inputs from many sources and allow for strategic thinking and tactical implementation.
2. Spoken and written communications that are compelling, convincing, and reassuring, and skills to articulate complex technical ideas to non-technical stakeholders.
3. Ability to think laterally and to have input to / propose detailed, complex solutions to technical issues.
4. Interpersonal skills that create openness and trust among colleagues.
5. Ability to work well under pressure and to meet tight deadlines. Demonstrates a high level of motivation, confidence, integrity, and responsibility.
6. Ability to be organized, responsive and to be able to effectively multi-task with a focus on driving results.
7. Demonstrate excellent interpersonal and relationship management skills. This includes the ability to work independently, effectively in a team/task force as a team member or leader, and with senior staff and managers.
8. Ability to work well under pressure and to meet tight deadlines, whilst demonstrating a high level of motivation, confidence, integrity, and responsibility.
9. Excellent relationship management skills. Facilitation and conflict management skills that enable effective working relationships.
Education
1. Bachelor's degree in information security, computer science, engineering, mathematics, business, or related field of study plus a minimum of 12 years of relevant experience in regulated industries working as an information risk manager or IT security architect; OR
2. Advanced degree in Information Security, computer science, engineering, mathematics, business, or related field of study plus a minimum of 6 years of relevant experience in regulated industries working as an information risk manager or IT security architect.
Certifications: (Minimum plus at least 2 preferred)
1. CISSP or CISM (minimum required)
2. CCSP (preferred)
3. Microsoft Certified: Cybersecurity Architect Expert (preferred)
4. Other Microsoft cloud security related certifications at the Expert level (preferred)
5. GIAC certifications (preferred)
6. Offensive security related certifications (preferred)
Diverse Lynx LLC is an Equal Employment Opportunity employer. All qualified applicants will receive due consideration for employment without any discrimination. All applicants will be evaluated solely on the basis of their ability, competence and their proven capability to perform the functions outlined in the corresponding role. We promote and support a diverse workforce across all levels in the company.
-
Risk Engineering Consultant
4 weeks ago
Washington, DC, USA, United States Apple & Associates Full timeJob Title: Sr Field Property Risk Engineering ConsultantJoin Apple & Associates as a Sr Field Property Risk Engineering Consultant and take on a challenging role that requires a unique blend of technical expertise and business acumen. As a key member of our team, you will be responsible for performing property/natural hazard risk assessments and risk...
-
Senior Risk Management Consultant
2 weeks ago
Washington, Washington, D.C., United States Dice Full timeJob Title: Senior Risk Management ConsultantWe are seeking a highly skilled Senior Risk Management Consultant to join our team at Dice. As a Senior Risk Management Consultant, you will be responsible for providing expert-level risk management services to our clients.Key Responsibilities:Develop and implement risk management strategies to mitigate potential...
-
Senior Risk Management Consultant
7 days ago
Washington, Washington, D.C., United States Diverse Lynx Full timeJob Title: Senior Risk Management ConsultantJob Summary:We are seeking a highly skilled Senior Risk Management Consultant to join our team at Diverse Lynx LLC. As a Senior Risk Management Consultant, you will be responsible for providing expert advice and guidance on risk management strategies and practices to ensure the security and integrity of our...
-
Washington, Washington, D.C., United States Tantus Technologies Full timeJob SummaryTantus Technologies, Inc. is seeking a highly experienced Sr. Oracle Financial Management Systems Consultant to provide expert consulting to senior officials within the Office of Finance. The ideal candidate will have a deep understanding of financial management processes and be able to advise on policy, strategy, and process improvement in...
-
Senior Risk Management Consultant
7 days ago
Washington, Washington, D.C., United States Dice Full timeJob Title: Senior Risk Management ConsultantJob Summary:We are seeking a highly skilled Senior Risk Management Consultant to join our team at Dice. As a Senior Risk Management Consultant, you will be responsible for managing and mitigating risks across various projects, ensuring the security and integrity of our clients' systems and data.Key...
-
Senior Risk Management Consultant
2 weeks ago
Washington, DC , USA, United States Diverse Lynx Full timeJob Description:Sr. Risk Management ConsultantRemote Work Arrangement:Except for week 1 and quarterly, this role offers a remote work arrangement, allowing for flexibility and work-life balance.Key Skills:Three essential skills for this role are:Assurance guidelines, risk factors, and risk management across projects.Risk Assessment, Security Policy...
-
Senior Clinical Risk Consultant
2 weeks ago
Washington, Washington, D.C., United States The Jacobson Group Full timeJob Title: Senior Clinical Risk ConsultantJob Summary:The Jacobson Group is seeking a Senior Clinical Risk Consultant to join our team. As a key member of our risk management department, you will be responsible for providing ongoing risk management support to assigned accounts, including physicians, clinics, hospitals, and multi-specialty health systems.Key...
-
Senior Clinical Risk Consultant
7 days ago
Washington, Washington, D.C., United States The Jacobson Group Full timeJob Title: Senior Clinical Risk ConsultantJob Summary:The Senior Clinical Risk Consultant is a key member of our team at The Jacobson Group, responsible for providing ongoing risk management support to our clients. This role involves conducting risk evaluations and risk assessments, developing relevant risk management content, and driving change to reduce...
-
Cybersecurity Risk Management Consultant
2 weeks ago
Washington, DC , USA, United States Dice Full timeJob DescriptionDice is seeking a highly skilled Cybersecurity Risk Management Consultant to join our team. As a key member of our client's organization, you will be responsible for managing and mitigating information security risks across various projects.Key Responsibilities:Design and implement risk management frameworks to ensure compliance with...
-
Senior Clinical Risk Consultant
7 days ago
Washington, Washington, D.C., United States The Jacobson Group Full timeJob Title: Senior Clinical Risk ConsultantJob Summary:The Senior Clinical Risk Consultant is a key member of our team at The Jacobson Group, responsible for providing ongoing risk management support to our clients in the healthcare industry. This role involves conducting risk evaluations and assessments, developing relevant risk management content, and...
-
Washington D.c., United States ACI Group, Inc. Full timeSr. Oracle Financial Management Systems Consultant, Hybrid/Washington DCContract to HireHybrid: Will be supporting a client in Washington, DC. Seeking a local candidate able to come on-site 2 times a weekAbility to obtain a Public Trust Clearance.NO THIRD PARTY RECRUITERS PLEASE! CANDIDATES MUST BE SELF-REPRESENTED.DescriptionSeeking a Sr. Oracle Financial...
-
Security Risk Consultant
1 week ago
Washington, Washington, D.C., United States Infojini Full timeJob SummaryAs a Security Risk Consultant at Infojini, you will be responsible for performing detailed architectural reviews and risk analysis of security-related requests to make sound decision-making recommendations. This includes network design and information flow, system and data access models, review of firewall rule requests, baseline configuration...
-
Senior Property Risk Engineering Consultant
4 weeks ago
Washington, Washington, D.C., United States Zurich Insurance Company Ltd Full timeJob Title: Senior Property Risk Engineering ConsultantZurich's Risk Engineering Property Great Lakes Regional Team is seeking a highly skilled Property Field Risk Engineering Consultant with large property highly protected risk (HPR) experience.Key Responsibilities:Provide field risk engineering to meet underwriting requirements.Develop and implement...
-
Washington, Washington, D.C., United States The ACI Group, Inc. Full timeJob DescriptionWe are seeking a highly skilled Sr. Oracle Financial Management Systems Consultant to join our team at The ACI Group, Inc.This is a unique opportunity to work with a leading staffing firm and contribute to the success of our clients.About the RoleProvide expert consulting to senior officials within the Office of Finance, focusing on improving...
-
Risk Control Technical Consultant
4 weeks ago
Washington, Washington, D.C., United States Travelers Insurance Company Full timeAbout the RoleWe are seeking a highly skilled Risk Control Technical Consultant to join our team at Travelers Insurance Company. As a Risk Control Technical Consultant, you will play a critical role in helping our customers manage and mitigate risk.Key ResponsibilitiesPartner with Underwriting to select, retain, and grow a profitable book of business.Build...
-
Sr. Program Manager
11 hours ago
Washington, United States Improvix Technologies, Inc. Full timeTitle: Senior Program ManagerLocation: Washington, DCRemote: HybridCertification: PMPClearance: Secret, w/eligibility for Top SecretPosition Description: The Sr. Program Manager is the government's primary point-of-contact and the company's primary officer accountable for contract performance and delivery, overseeing all areas of Team Improvix's activity...
-
Senior Clinical Risk Consultant
2 weeks ago
Washington, DC , USA, United States Physicians Insurance Full timeJob Title: Senior Clinical Risk ConsultantPhysicians Insurance is seeking a highly skilled Senior Clinical Risk Consultant to join our team. As a national boutique mutual insurance company, we are dedicated to protecting, defending, and supporting our Members. Our team is passionate about serving our Members and partners with our suite of medical...
-
Risk Management Specialist
4 weeks ago
Washington, Washington, D.C., United States Dexis Consulting Group Full timeAbout Dexis Consulting GroupDexis Consulting Group is a professional services firm dedicated to solving complex social challenges in global environments. Our mission is to create a more secure and prosperous world by providing expert solutions to pressing issues.Job Title: Risk Management SpecialistWe are seeking a highly skilled Risk Management Specialist...
-
Senior Clinical Risk Consultant
4 days ago
Washington, DC , USA, United States Physicians Insurance Full timeSenior Clinical Risk Consultant Job DescriptionWe are seeking a highly skilled Senior Clinical Risk Consultant to join our team at Physicians Insurance. As a national boutique mutual insurance company, we are dedicated to protecting, defending, and supporting our Members.Key Responsibilities:Conduct risk evaluations and onsite risk assessments for assigned...
-
Senior Clinical Risk Consultant
2 weeks ago
Washington, DC , USA, United States The Jacobson Group Full timeJob Description:The Senior Clinical Risk Consultant is responsible for providing ongoing risk management support to assigned account types, including physicians, clinics, hospitals, and multi-specialty health systems. This role involves conducting risk evaluations and assessments, developing relevant risk management content, and driving change to reduce risk...