Principal, Cybersecurity Consultant

4 weeks ago


Boston, United States Fidelity Investments Full time
Job Description:

Position/Role Title

Principal, Cybersecurity Consultant

The Team

The Enterprise Cybersecurity (ECS) Regulatory & Audit team helps ECS and corporate partners manage firm-wide cybersecurity risk by providing key support services. As part of Cyber Regulatory & Audit, the ECS Internal Audit Engagement (IAE) team supports 25-30 internal audits annually. IAE seeks to reduce cyber risk through improved engagement and partnership with ECS Product Areas and Audit to ensure alignment, transparency, and efficiency throughout pre-audit, active audit, and post-audit efforts.

The Role

The ECS Internal Audit Engagement (IAE) team is seeking an experienced, passionate cybersecurity risk professional to support and partner with ECS Product Areas and Fidelity Corporate Audit. The role requires steadfast collaboration throughout the three phases of audit engagement: pre-audit (roadmap alignment, pre-audit control risk gap assessments, trend/theme analysis), active audit (risk quantification, drafting action plans, facilitating risk acceptances), and post-audit (action plan closure, reporting and metrics).

The Expertise and Skills You Bring

Technical Skills
  • Demonstrated Risk Management and Mitigation experience
  • Strong Risk, Process, Cyber Threat Analysis, and Control Gap Assessment skill
  • Broad knowledge of cybersecurity threats and tactics
  • In-depth understanding of NIST Cybersecurity Framework standards and practices, COBIT 5
  • Knowledge of Operations & Technology (identity & access management; physical/personnel security; security ops assessments), Information Risk Management (vendor risk management; cloud computer security; data management), Software Development Life Cycle (SSDLC) and application security.
  • Understanding of FAIR (Factor Analysis of Information Risk) cyber risk framework
  • Familiarity with ECS Policies, Standards, and Technical Implementation Guides (TIGs)
  • Familiarity with Archer GRC, Jira, and ServiceNOW


General Business Skills
  • Experience working as corporate/internal auditor or working with corporate audit function
  • Experience working within a Cyber Security organization
  • Analyst mindset to deep dive into audit findings to understand and communicate risks and appropriate responses
  • Strong communication skills (written, verbal, presentation) with technical expertise to influence others and drive outcomes
  • Highly motivated, self-directed, independent thinker with strong attention to detail.


Responsibilities
  • Partner w/ ECS teams to identify ECS control gaps
  • Partner w/ Audit and ECS teams to confirm reported audit issues and perform FAIR quantitative risk assessments
  • Partner with ECS Product Areas on drafting responses (Action Plans) to address valid audit observations
  • Track ECS Product Areas progress toward on-time completion of action plans
  • Identify opportunities to improve team processes to better support ECS Product Areas
  • Manage ECS Risk Acceptances
  • Maintain and leverage key metrics that support various reports and critical meetings
  • Partner w/ ECS Product Areas to gain in-depth understanding of roadmaps, backlogs, etc.


Education and Experience
  • Bachelor's degree in technology, computer science, or engineering strongly preferred
  • 7+ years experience in cybersecurity risk management, technology operations, system analysis, and/or project management
  • Certification a plus: CISSP (Information Systems Security Professional), CEH (Certified Ethical Hacker), CISA (Certified Information Systems Auditor)


The base salary range for this position is $85,000-$179,000 per year.
Placement in the range will vary based on job responsibilities and scope, geographic location, candidate's relevant experience, and other factors.

Base salary is only part of the total compensation package. Depending on the position and eligibility requirements, the offer package may also include bonus or other variable compensation.

We offer a wide range of to meet your evolving needs and help you live your best life at work and at home. These benefits include comprehensive health care coverage and emotional well-being support, market-leading retirement, generous paid time off and parental leave, charitable giving employee match program, and educational assistance including student loan repayment, tuition reimbursement, and learning resources to develop your career. Note, the application window closes when the position is filled or unposted.

Certifications:

Company Overview

Fidelity Investments is a privately held company with a mission to strengthen the financial well-being of our clients. We help people invest and plan for their future. We assist companies and non-profit organizations in delivering benefits to their employees. And we provide institutions and independent advisors with investment and technology solutions to help invest their own clients' money.

Join Us

At Fidelity, you'll find endless opportunities to build a meaningful career that positively impacts peoples' lives, including yours. You can take advantage of flexible benefits that support you through every stage of your career, empowering you to thrive at work and at home. Honored with a , we have been recognized by our employees as a top 10 Best Place to Work in 2024. And you don't need a finance background to succeed at Fidelity-we offer a range of opportunities for learning so you can build the career you've always imagined.

blends the best of working offsite with maximizing time together in person to meet associate and business needs. Currently, most hybrid roles require associates to work onsite all business days of one assigned week per four-week period (beginning in September 2024, the requirement will be two full assigned weeks).

At Fidelity, we value honesty, integrity, and the safety of our associates and customers within a heavily regulated industry. Certain roles may require candidates to go through a preliminary credit check during the screening process. Candidates who are presented with a Fidelity offer will need to go through a background investigation, , and may be asked to provide additional documentation as requested. This investigation includes but is not limited to a criminal, civil litigations and regulatory review, employment, education, and credit review (role dependent). These investigations will account for 7 years or more of history, depending on the role. Where permitted by federal or state law, Fidelity will also conduct a pre-employment drug screen, which will review for the following substances: Amphetamines, THC (marijuana), cocaine, opiates, phencyclidine.

We invite you to Find Your Fidelity at .

Fidelity Investments is an equal opportunity employer. We believe that the most effective way to attract, develop and retain a diverse workforce is to build an enduring culture of inclusion and belonging.

Fidelity will reasonably accommodate applicants with disabilities who need adjustments to participate in the application or interview process. To initiate a request for an accommodation, contact the HR Accommodation Team by sending an email to .

We welcome those with experience in jobs such as General, General, and General and others in the General to apply.

  • Boston, Massachusetts, United States Fidelity Investments Full time

    Job Overview:Position Title: Principal, Cybersecurity ConsultantTeam Overview:The Enterprise Cybersecurity (ECS) Regulatory & Audit division plays a crucial role in assisting ECS and corporate partners in managing comprehensive cybersecurity risks by delivering essential support services. Within the Cyber Regulatory & Audit framework, the ECS Internal Audit...


  • Boston, MA, United States Fidelity Investments Full time

    Principal, Cybersecurity Consultant The Enterprise Cybersecurity (ECS) Regulatory & Audit team helps ECS and corporate partners manage firm-wide cybersecurity risk by providing key support services. As part of Cyber Regulatory & Audit, the ECS Internal Audit Engagement (IAE) team supports 25-30 internal audits annually. IAE seeks to reduce cyber risk...


  • Boston, Massachusetts, United States Liberty Mutual Insurance Full time

    Join Liberty Mutual as a Cybersecurity SpecialistCompensation PhilosophyThe standard starting salary range for this position is influenced by various factors including skills, experience, education, and geographical location. The comprehensive salary range reflects market value and provides opportunities for advancement as you develop in the role. Certain...


  • Boston, Massachusetts, United States Fidelity Investments Full time

    Job Overview:Position Title: Principal, Cybersecurity ConsultantTeam Overview:The Enterprise Cybersecurity (ECS) Regulatory & Audit division plays a crucial role in assisting ECS and corporate partners in managing comprehensive cybersecurity risks by delivering essential support services. Within the Cyber Regulatory & Audit framework, the ECS Internal Audit...


  • Boston, United States Liberty Mutual Insurance Full time

    Pay Philosophy The typical starting salary range for this role is determined by a number of factors including skills, experience, education, certifications and location. The full salary range for this role reflects the competitive labor market value for all employees in these positions across the national market and provides an opportunity to...


  • Boston, Massachusetts, United States Liberty Mutual Insurance Full time

    Join Liberty Mutual as a Principal Cybersecurity EngineerCompensation PhilosophyThe standard starting salary range for this position is influenced by various factors including expertise, experience, education, and geographical location. The comprehensive salary range reflects market value and provides opportunities for advancement as you grow in this role....


  • Boston, Massachusetts, United States Liberty Mutual Insurance Full time

    Join Liberty Mutual as a Cybersecurity Solutions PrincipalCompensation PhilosophyThe standard starting salary range for this position is influenced by various factors including expertise, experience, education, and geographical location. The comprehensive salary range reflects market value and provides opportunities for advancement as you grow in the role....


  • Boston, Massachusetts, United States Chenega Corporation Full time

    Overview Cybersecurity Risk Management Consultant Chenega Corporation Chenega Analytic Business Solutions (CABS) specializes in delivering reliable insights into Records and Information Management, Administrative Solutions, Information Technology, Engineering, and Training. Established to cater to federal and commercial clients, CABS is recognized...


  • Boston, United States Fidelity TalentSource LLC Full time

    Cybersecurity Consultant (Internal Audit Facilitator)Fidelity TalentSource is your destination for discovering your next temporary role at Fidelity Investments! We are currently sourcing for a Sr. Cybersecurity Consultant (Regulatory & Audit) to work in Fidelity’s Enterprise Cybersecurity division in Boston, MA!The TeamThe Enterprise Cybersecurity (ECS)...


  • Boston, United States Fidelity TalentSource LLC Full time

    Cybersecurity Consultant (Internal Audit Facilitator) Fidelity TalentSource is your destination for discovering your next temporary role at Fidelity Investments! We are currently sourcing for a Sr. Cybersecurity Consultant (Regulatory & Audit) to work in Fidelity’s Enterprise Cybersecurity division in Boston, MA! The Team The Enterprise Cybersecurity...


  • Boston, Massachusetts, United States Fidelity Investments Full time

    Job Overview:Position Title: Principal, Cybersecurity ConsultantTeam Overview:The Enterprise Cybersecurity (ECS) Regulatory & Audit team plays a crucial role in assisting ECS and corporate partners in managing comprehensive cybersecurity risks by delivering essential support services. Within the Cyber Regulatory & Audit framework, the ECS Internal Audit...

  • Cybersecurity Engineer

    17 hours ago


    Boston, Massachusetts, United States Liberty Mutual Insurance Full time

    About the RoleWe are seeking a highly skilled Cybersecurity Engineer to join our team at Liberty Mutual Insurance. As a key member of our security team, you will be responsible for designing, implementing, and managing our organization's overall security posture.Key ResponsibilitiesSupport secure application development initiatives, requiring innovation,...


  • Boston, United States EPMA Full time

    Our client is currently seeking a Cybersecurity Engineer to join their team. This individual will provide engineering and cybersecurity consulting to the customers and project teams. The individual will also support the growth of cybersecurity services, working closely with the business development team.Title: Cybersecurity Engineer (OT Network)Type: Full...

  • Principal Consultant

    1 month ago


    Boston, United States Momentum ABM Full time

    About Momentum ITSMAMomentum's mission is clear: to empower organizations to center everything they do on clients and cultivate stronger, more resilient relationships. We understand that relationships require dedication and effort to thrive. They can easily stagnate, sour, or fade away if not nurtured and evolved over time. Our client growth services across...

  • Principal Consultant

    3 months ago


    Boston, United States Momentum ITSMA Full time

    Job DescriptionJob DescriptionAbout Momentum ITSMAMomentum's mission is clear: to empower organizations to center everything they do on clients and cultivate stronger, more resilient relationships. We understand that relationships require dedication and effort to thrive. They can easily stagnate, sour, or fade away if not nurtured and evolved over time....


  • Boston, New York, United States >AMBIT Full time

    About AmbitAmbit is a healthcare technology and services company that provides data, analytics, consulting, and platform-based offerings to biopharma companies with a focus on rare and specialty diseases.Ambit's capabilities include strategy development, digital transformation, analytics, and patient identification and activation.About Ambit LeadershipAmbit...


  • Boston, United States Motion Recruitment Full time

    Job Title: Principal C++ Software Engineer Location: Greater Boston About Us: Our client is dedicated to pioneering advanced security solutions that help keep the world a safer place. They are seeking a Principal C++ Software Engineer to join them in their mission to create cutting-edge, high-performance security solutions. Position Overview: As a Principal...


  • Boston, United States Boston Consulting Group Full time

    Who We AreBoston Consulting Group partners with leaders in business and society to tackle their most important challenges and capture their greatest opportunities. BCG was the pioneer in business strategy when it was founded in 1963. Today, we work closely with clients to embrace a transformational approach aimed at benefiting all stakeholders-empowering...


  • Boston, United States Ramboll Group AS Full time

    This position is located in the Boston, Massachusetts area.Applicants must be currently authorized to work in the United States on a full-time basis. No sponsorship is available for this position.We invite you to bring your Environmental Consulting experience along with your strong leadership skills as you contribute to innovative and sustainable...


  • Boston, United States Slalom Full time

    Business Delivery - Principal, Senior Consultant At Slalom, personal connection meets global scale. Our vision is to enable a world in which everyone loves their work and life. We help organizations of all kinds redefine what's possible, give shape to the future-and get there. Our Business Delivery team is comprised of consultants with the expertise to...