At Cream City Cyber, we understand the convergence of physical and digital risks and how they impact businesses and governments alike. Our battle-tested experts have been trusted advisors for decades, offering tailored security solutions to help clients navigate evolving landscapes. We strive to mitigate risks with confidence, enabling our partners to thrive in a connected world.
Technology Risk Management Consultant
Overview
We are seeking a skilled and detail-oriented Technology Risk Management Consultant to join our Risk & Compliance consulting team. The ideal candidate will have hands-on experience in risk assessment, regulatory compliance, vulnerability management, and governance support. This position requires a strong analytical mindset, effective communication skills, and the ability to work cross-functionally to support security objectives.
Key Responsibilities
Risk Management
- Perform preliminary assessments of technology and cybersecurity risks
- Document risk treatment plans and track mitigation progress
- Maintain risk registers and records of identified risks
Controls Management
Assist in implementing and testing security controlsIdentify gaps and improvement opportunities in existing controlsSupport audit preparation and control documentationEnsure alignment of controls with compliance requirements and project goalsVulnerability Management
Coordinate vulnerability remediation with stakeholdersTrack mitigation progress and maintain accurate documentationSupport report preparation and risk prioritizationMetrics and Reporting
Gather and analyze risk data for dashboards and presentationsEnsure data accuracy and consistencySupport stakeholder communication with clear data visualizationGRC Programs
Contribute to the development and maintenance of policies and proceduresEnsure documentation is current and aligned with operational needsParticipate in GRC program updates and process improvementsRegulatory Compliance
Assist in compliance assessments and gap analysesDraft and update documentationTrack remediation activities to ensure complianceCross-Functional Collaboration
Support integration of risk and compliance into project effortsShare insights with stakeholders to align on project objectivesPolicy Development
Conduct policy research and benchmark industry practicesDraft and update policy documentationClarify policy implications for team membersLeadership and Team Contribution
Own smaller tasks and projects with quality focusCollaborate and share knowledge with the teamParticipate in meetings and process improvement effortsProblem Solving
Apply structured analysis to identify trends and risksDevelop actionable insights and support solution developmentClearly communicate solutions to stakeholdersCareer Growth
Engage in self-directed learning and certificationsSeek challenging assignments to expand skills and business understandingRequired Qualifications
Bachelor's degree in Cybersecurity, Computer Science, Information Systems, or related field3+ years of experience in cybersecurity risk management or information securitySolid understanding of risk management principles, assessment methodologies, and control frameworksFamiliarity with compliance frameworks and regulations (NIST CSF, PCI-DSS, ISO / IEC 27001, SOC 2, GDPR, HIPAA)Strong written and verbal communication skillsAbility to engage technical and non-technical stakeholders effectivelyStrategic thinking and alignment of risk tasks with business goalsPreferred Qualifications
Degree or experience in Information Security, Business Administration, or a related fieldCertifications such as Security+, GRCP, CGRC, or similarExposure to regulated environments and compliance rolesFamiliarity with cloud security, vendor risk, and incident responseExperience with audit support and security awareness programsApplication
This is a full-time position offering growth opportunities, professional development, and the chance to work on meaningful cybersecurity initiatives. Apply now to be part of a collaborative, impact-driven team.
J-18808-Ljbffr