Information Security Risk Consultant
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
Job description
The Business Information Security Consultant provides advisory and hands-on support for security governance, risk management, and secure application development initiatives. This role supports ongoing security efforts for application implementations, third-party risk assessments, and business-facing security programs. The position interacts closely with business, technology, and security stakeholders to assess controls, facilitate risk mitigation activities, and deliver consistent security practices across multiple initiatives., Secure by Design & SDLC Support
- Support secure-by-design initiatives by evaluating security controls within application implementations
- Perform security-related SDLC activities using standardized security user stories
- Provide ongoing consultation for in-scope applications to ensure alignment with security requirements
- Assist development and project teams in understanding and applying security controls
Risk Management & Third-Party Assessments
- Conduct risk assessments and due diligence activities for third-party vendors
- Identify risks and recommend mitigation strategies aligned with organizational standards
- Support vendor risk management processes and ongoing monitoring activities
Security Assessments & Governance Support
- Support physical site security assessments on an as-needed basis
- Facilitate Security Risk Acknowledgment and Action Planning activities
- Provide ad-hoc security consultation through formal service request processes
- Ensure consistent application of security governance practices across initiatives
Reporting & Program Visibility
- Prepare and deliver monthly reports summarizing security demand, activities, and outcomes
- Track and communicate workload, trends, and key risk indicators
- Provide updates to leadership on security initiatives and risk posture
Stakeholder Collaboration & Advisory
- Partner with business, IT, and security teams to align on risk, controls, and implementation strategies
- Act as a trusted advisor for security-related decisions and risk acceptances
- Support cross-functional communication and coordination on security initiatives
Requirements
Do you have experience in Third-party risk management?, * 5 or more years of experience in information security, risk management, or security consulting
- Experience supporting secure software development life cycle activities
- Experience conducting vendor risk assessments and due diligence reviews
- Strong understanding of security controls, risk frameworks, and mitigation strategies
- Experience working directly with business and technical stakeholders
- Strong written and verbal communication skills, * Experience supporting divestiture, integration, or transformation programs
- Familiarity with enterprise security assessment methodologies
- Experience supporting physical security assessments
- Experience working in regulated or large enterprise environments
Core Skills & Attributes
- Strong analytical and risk assessment capabilities
- Ability to communicate complex security concepts to non-technical stakeholders
- Strong organizational and reporting skills
- Ability to manage multiple concurrent tasks in a demand-driven environment
- Collaborative and consultative approach to problem solving
- High attention to detail and accountability in security processes
Benefits & conditions
- Competitive salary
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on indeed.comGood distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
9 Ways to Make Money Hacking
Understanding and Mitigating Common Web Vulnerabilities
Walking Into The Era of Supply Chain Risks
7 Important Tips That Every Software Developer Should Know