> Markdown version of [/jobs/ext/112158-information-security-risk-consultant](https://www.wearedevelopers.com/jobs/ext/112158-information-security-risk-consultant). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Security Risk Consultant - **Company:** The Smart - **Location:** United States (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Cyber Security, Systems Development Life Cycle, Software Engineering, Software Security - **Published:** May 15, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=a346795c9079f819 ## About the Role Do you have experience in Third-party risk management?, * 5 or more years of experience in information security, risk management, or security consulting * Experience supporting secure software development life cycle activities * Experience conducting vendor risk assessments and due diligence reviews * Strong understanding of security controls, risk frameworks, and mitigation strategies * Experience working directly with business and technical stakeholders * Strong written and verbal communication skills, * Experience supporting divestiture, integration, or transformation programs * Familiarity with enterprise security assessment methodologies * Experience supporting physical security assessments * Experience working in regulated or large enterprise environments Core Skills & Attributes * Strong analytical and risk assessment capabilities * Ability to communicate complex security concepts to non-technical stakeholders * Strong organizational and reporting skills * Ability to manage multiple concurrent tasks in a demand-driven environment * Collaborative and consultative approach to problem solving * High attention to detail and accountability in security processes ## Description The Business Information Security Consultant provides advisory and hands-on support for security governance, risk management, and secure application development initiatives. This role supports ongoing security efforts for application implementations, third-party risk assessments, and business-facing security programs. The position interacts closely with business, technology, and security stakeholders to assess controls, facilitate risk mitigation activities, and deliver consistent security practices across multiple initiatives., Secure by Design & SDLC Support * Support secure-by-design initiatives by evaluating security controls within application implementations * Perform security-related SDLC activities using standardized security user stories * Provide ongoing consultation for in-scope applications to ensure alignment with security requirements * Assist development and project teams in understanding and applying security controls Risk Management & Third-Party Assessments * Conduct risk assessments and due diligence activities for third-party vendors * Identify risks and recommend mitigation strategies aligned with organizational standards * Support vendor risk management processes and ongoing monitoring activities Security Assessments & Governance Support * Support physical site security assessments on an as-needed basis * Facilitate Security Risk Acknowledgment and Action Planning activities * Provide ad-hoc security consultation through formal service request processes * Ensure consistent application of security governance practices across initiatives Reporting & Program Visibility * Prepare and deliver monthly reports summarizing security demand, activities, and outcomes * Track and communicate workload, trends, and key risk indicators * Provide updates to leadership on security initiatives and risk posture Stakeholder Collaboration & Advisory * Partner with business, IT, and security teams to align on risk, controls, and implementation strategies * Act as a trusted advisor for security-related decisions and risk acceptances * Support cross-functional communication and coordination on security initiatives ## Related Videos - [Software Security 101: Secure Coding Basics](https://www.wearedevelopers.com/videos/220-software-security-101-secure-coding-basics) - [The Avengers Initiative (Practical Ethics for Software Engineers)](https://www.wearedevelopers.com/videos/2070-the-avengers-initiative-practical-ethics-for-software-engineers) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Reporting Active Exploits in 24 Hours: Are You Ready for the CRA?](https://www.wearedevelopers.com/videos/100248-reporting-active-exploits-in-24-hours-are-you-ready-for-the-cra) - [Unleashing the Power of Developers: Why Cybersecurity is the Missing Piece?!?](https://www.wearedevelopers.com/videos/712-unleashing-the-power-of-developers-why-cybersecurity-is-the-missing-piece) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [7 Important Tips That Every Software Developer Should Know](https://www.wearedevelopers.com/magazine/101-7-important-tips-that-every-software-developer-should-know) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs)