Cyber & Risk Management Lead
Job Description:
- Lead recurring enterprise and division risk assessments through stakeholder interviews and reviews of incidents, audits, projects, operations, and emerging threats
- Identify strategic, operational, reporting, compliance, technology, and cybersecurity risks
- Maintain the enterprise risk register and apply likelihood/impact scoring
- Establish and monitor KRIs/KPIs, trends, emerging risks, and mitigation actions, including monthly follow-up with risk owners
- Develop Risk Assessment Reports (RARs), ERM dashboards, and senior-leadership/Risk Committee reporting
- Evaluate policies, processes, controls, audits, and compliance reviews to identify weaknesses, noncompliance, and control gaps
- Coordinate risk liaisons and process owners to define, track, and validate corrective and mitigation actions
- Provide ERM guidance, training, templates, tools, expectations, and deadlines to stakeholders
- Improve ERM procedures, dashboards, workflows, and automation
- Benchmark practices against COSO ERM, ISO 31000, and applicable Federal cybersecurity and risk requirements
Requirements:
- Bachelor’s degree in Cybersecurity, Information Systems, Computer Science, Engineering, Risk Management, or a related discipline
- Over 10 years of relevant enterprise risk management, cybersecurity/IT risk, information assurance, governance, compliance, or related experience
- Senior industry professional certification such as CISSP or equivalent
- Demonstrated technical/management leadership on major cybersecurity or risk assignments
- Experience establishing goals/plans, directing multidisciplinary activities, and interfacing with senior Government/client leadership
- Expert knowledge of enterprise/cybersecurity risk assessment, risk registers, likelihood/impact scoring, KRIs/KPIs, mitigation tracking, controls, compliance, and executive risk reporting
- Experience evaluating security/risk requirements, policies, controls, vulnerabilities, and compliance issues and recommending solutions or corrective actions
- Experience improving risk processes, tools, dashboards, workflows, templates, or automation
- Experience coordinating risk owners, liaisons, technical teams, and senior stakeholders
- Ability to obtain a 6c Public Trust
- At least an active Secret clearance is highly preferred
- U.S. Citizenship is required
Benefits:
- Certification incentive program
- PTO
- Floating federal holiday options
- HMO insurance options
- High Deductible health plans with Health Savings Accounts (HSAs)
- Flex Spending Accounts (FSAs)
- Full Dental Plans
- Vision insurance
- Short-term and long-term disability insurance
- Life Insurance
- 401k match
- Professional development through certification incentives
- Flexible Work Environment