Search Jobs
View current IT, supply chain, and manufacturing opportunities.
Cybersecurity Specialist - ERC Consultant
12580 West Creek Parkway Richmond, VA 23261 US
Job Description
Cybersecurity Specialist – ERC Consultant
1Â year Contract with excellent likelihood of future extensions!
2+ years experience as a "hands on" Cybersecurity Specialist technically implementing and carrying out strategic initiatives!Â
Deepen your consultative skills!Â
POSITION SUMMARY:
The Cybersecurity Risk and Compliance Specialist will help with implementing Cybersecurity initiatives at our client to directly  build the organization's security posture. This role acts as a trusted consultant to the organization’s Cybersecurity program and drives IT and Cybersecurity improvements and compliance with CIS/NIST maturity goals, NYDFS, Virginia Cybersecurity Regulations, Bureau of Insurance(BOI) and compliance applicable  to compliance to ensure successful audits, assessment outcomes and a heightened organization security posture.
By possessing skills required to understand the interplay between Cybersecurity Architecture, Governance, Risk, Compliance, and Enterprise Risk Management. This Specialist will develop, mature and implement robust policies, procedures, and methodologies to achieve and maintain stringent cybersecurity compliance standards.
Required Technical Skills:
- 2+ years of experience in Risk, and Compliance within the Information Security /IT Security department of a medium to large, complex organization.
- Skilled at Maintaining the IS Department’s Enterprise Risk Registry and process.
- Ability to Manage Service Provider and Third Party Risk in accordance with CIS 15 IG2 controls
- Experience to perform third-party cyber risk assessments and  leverage automated tools Third Party Risk Management Platform (TPRM) such or similar to Bitsight, Black Kite etc.
- Ability to review IT/security-related documents and agreements for Information security compliance in accordance with CIS, NIST and legal criteria’s, identify gaps, and recommend security and content to protect VAFB's best interests.
- Third-Party Risk Management program to assess and mitigate risks associated with third-party vendors including Service Provider Management
- Enterprise Cybersecurity Risk Process Management including Risk Registry Management
- Policy Lifecycle management -review routing, update and recertification
- Personal Attributes:
- Ability to work with all levels of IT staff inside and outside the organization.
- Ability to think through problems, visualize solutions and develop/implement concepts.
- Dependable and flexible when necessary.
- Good communication skills (written, verbal, and face-to-face)
- Bachelor’s Degree or equivalent  in Information Security/Cybersecurity, Cybersecurity Policy, Information Technology, Engineering, Business, or a related field preferred.
- Perform comprehensive policy gap and control assessments against CIS IG3 standards
- Develop compliance capability roadmaps and identify and deliver key results to achieve roadmap milestones.
- In-depth understanding of common cybersecurity frameworks and standards (e.g. CIS/NIST Controls/Benchmarks; ISO etc.).
- Mature the organization CIS-compliant third-party risk management program to assess and mitigate risks associated with third-party vendors.
- Experience solutions such as JIRA & Confluence for work management, Documentation, knowledge management.
Â
Meet Your Recruiter
Share This Job:
Related Jobs:
About Richmond, VA
Are you sure you want to apply for this job?
Please take a moment to verify your personal information and resume are up-to-date before you apply.