Principal Security Consultant- Cyber Risk Transformation Services
GuidePoint Security LLCAbout the role
GuidePoint Security provides trusted cybersecurity expertise, solutions and services that help organizations make better decisions and minimize risk. By taking a three-tiered, holistic approach for evaluating security posture and ecosystems, GuidePoint enables some of the nation’s top organizations, such as Fortune 500 companies and U.S. government agencies, to identify threats, optimize resources and integrate best-fit solutions that mitigate risk.
This individual will develop and deliver solutions that bind together strategy, leadership, transformation expertise to address enterprise level cyber risk. They enable clients to identify and plan cyber risk posture improvements tailored to the clients unique needs.
Role and Responsibilities:
- Deliver successful consulting engagements while maintaining a high degree of customer satisfaction.
- Develop GPS methodologies and deliverables.
- Engage with client executive teams and boards as part of service delivery.
- Consult and deliver cybersecurity risk transformation programs; assess existing cyber risk programs and help clients mature their enterprise cyber risk mitigation strategies.
- Consult and deliver cybersecurity risk intelligence systems; metrics programs geared toward executive leadership and board members; assess existing metrics reporting programs, and help clients mature their risk intelligence and reporting programs. This includes multiple reporting levels within a typical organization, inclusive of board risk reporting.
- Perform enterprise cyber risk governance assessments, including threat modeling techniques such as attack tree analysis, and quantitative risk analysis.
- Consult and deliver cybersecurity risk services to enable organizations with their merger and acquisitions (M&A) and divestiture business activities.
- Consult and deliver security architecture services to enable organizations to align their business objectives with their enterprise architecture requirements.
- Consult and deliver security services to enable organizations evaluate their security investments, and make recommendations for adjustments as required to help organizations transform their programs while prioritizing on the key initiatives to drive risk reduction.
- Execute on security transformation programs in leadership role, typically with multiple peer GPS practice teams.
- Serve as a vCISO to assess and help develop and/or maintain customer security programs.
- Establish strong relationships and trust with customers to understand customer’s business environments and requirements.
- Work with other GuidePoint Security practices as part of a cohesive cross-functional team.
Experience and Education:
- Minimum 5 years of experience performing GRC-related consulting services for clients of various verticals and sectors, including SLED, financial and insurance, retail, healthcare, service providers (SaaS, PaaS, etc.), manufacturing, critical infrastructure/energy, etc. Large multi-national experience is preferred.
- Minimum of 7 years of combined GRC experience across consulting and private/public sector.
- Minimum 7 years direct cyber risk management experience within multiple verticals to include SLED, financial and healthcare.
- Strong understanding and working knowledge of risk management frameworks such as SNIST RFM, ISO 31000, COBIT, COSO ERM, FAIR, PMI RMF, ISACA Risk IT Framework, ITIL, CMMI, ISO 27K, PRINCE2, and others.
- Experience engaging with external regulatory agencies auditing cyber risk programs, including OCC, HHS-OCR and other Federal agencies, and international authorities.
- Strong understanding and working knowledge of security frameworks including, NIST CSF, ISO 27001, HiTrust, and others.
- Strong understanding and experience with Enterprise Architecture practices and Security Architecture practices, including TOGAF and SABSA.
- Strong understanding of all the functions within a security program, the ability to assess the maturity of a security program, and how to provide strategic recommendations and direction to senior leadership.
- Strong understanding and working knowledge of various risk assessment methodologies, using qualitative and quantitative risk analysis.
- Strong demonstrated experience leading the transformation and maturation of a security program within large organizations.
- Extensive experience developing information security documentation for organizations and mapping requirements to various compliance and security best practice frameworks.
- Strong written and oral communication, which includes articulating thoughts and distilling complex problems into digestible information to be consumed by anyone from technical resources to the highest level of management; proven experience
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s