Information Security Risk Consultant

The Smart
United States
3 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours
Job source

Tech stack

Cyber Security Systems Development Life Cycle Software Engineering Software Security

Job description

The Business Information Security Consultant provides advisory and hands-on support for security governance, risk management, and secure application development initiatives. This role supports ongoing security efforts for application implementations, third-party risk assessments, and business-facing security programs. The position interacts closely with business, technology, and security stakeholders to assess controls, facilitate risk mitigation activities, and deliver consistent security practices across multiple initiatives., Secure by Design & SDLC Support

  • Support secure-by-design initiatives by evaluating security controls within application implementations
  • Perform security-related SDLC activities using standardized security user stories
  • Provide ongoing consultation for in-scope applications to ensure alignment with security requirements
  • Assist development and project teams in understanding and applying security controls

Risk Management & Third-Party Assessments

  • Conduct risk assessments and due diligence activities for third-party vendors
  • Identify risks and recommend mitigation strategies aligned with organizational standards
  • Support vendor risk management processes and ongoing monitoring activities

Security Assessments & Governance Support

  • Support physical site security assessments on an as-needed basis
  • Facilitate Security Risk Acknowledgment and Action Planning activities
  • Provide ad-hoc security consultation through formal service request processes
  • Ensure consistent application of security governance practices across initiatives

Reporting & Program Visibility

  • Prepare and deliver monthly reports summarizing security demand, activities, and outcomes
  • Track and communicate workload, trends, and key risk indicators
  • Provide updates to leadership on security initiatives and risk posture

Stakeholder Collaboration & Advisory

  • Partner with business, IT, and security teams to align on risk, controls, and implementation strategies
  • Act as a trusted advisor for security-related decisions and risk acceptances
  • Support cross-functional communication and coordination on security initiatives

Requirements

Do you have experience in Third-party risk management?, * 5 or more years of experience in information security, risk management, or security consulting

  • Experience supporting secure software development life cycle activities
  • Experience conducting vendor risk assessments and due diligence reviews
  • Strong understanding of security controls, risk frameworks, and mitigation strategies
  • Experience working directly with business and technical stakeholders
  • Strong written and verbal communication skills, * Experience supporting divestiture, integration, or transformation programs
  • Familiarity with enterprise security assessment methodologies
  • Experience supporting physical security assessments
  • Experience working in regulated or large enterprise environments

Core Skills & Attributes

  • Strong analytical and risk assessment capabilities
  • Ability to communicate complex security concepts to non-technical stakeholders
  • Strong organizational and reporting skills
  • Ability to manage multiple concurrent tasks in a demand-driven environment
  • Collaborative and consultative approach to problem solving
  • High attention to detail and accountability in security processes

Benefits & conditions

  • Competitive salary

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · WWC 2022

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · WWC 2022

1:30 min

The universal and shared team responsibility of software security

Julia Wilson Julia Wilson +1 · WWC 2025

1:22 min

Understanding software engineering as more than just coding

Lilia Gargouri Lilia Gargouri · WWC Europe 2026

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

Videos

See all

Related articles

See all