Cyber Security Advisory

CSA Group International, LLC
United States
about 2 months ago
Apply on www.dice.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours
Job source

Tech stack

Microsoft Access Amazon Web Services Cloud Computing Cyber Security Information Technology Audit PCI Data Security Standards IT General Controls (ITGC) Infrastructure Automation Frameworks Information Technology RSA Archer Platform

Job description

In today’s dynamic environment, business leaders face constantly shifting risks. Riveron helps organizations implement leading governance, risk and compliance practices by combining deep expertise with pragmatic partnership, using a hands-on approach to understand the specific needs of the organization and create tailored solutions to address key compliance risks.

Our Cyber Security Advisory (CSA) services include building GRC/Cybersecurity programs from the ground up, framework readiness, design and maintenance of critical security domains, managed internal controls testing and monitoring, co-sourced/outsourced internal audit, segregation of duties and access risk review, policy and procedure development, enterprise risk management, and IT and cybersecurity risk assessment.

The Manager level position for Riveron’s CSA group will work collaboratively with senior team members and provide guidance, coaching, and direction. Managers are expected to conduct the majority of day-to-day project management activities on all of their engagements, including project plan development, reviewing staff work for quality, status updates to clients and mentoring Senior Associates and Associates. The role includes leading the implementation of GRC/Cybersecurity programs, assessing the design and operating effectiveness of IT General Controls (ITGC), developing and executing remediation roadmaps, directing incident response tabletop exercises, and performing IT risk assessments., * You have a passion for developing and maintaining client relationships

  • You get the job done and have fun doing it
  • You communicate skillfully with a variety of audiences and can create compelling stories from data
  • You thrive in an ever-changing, dynamic work environment
  • You readily identify problems and instinctively look for solutions
  • You enjoy participating in internal and external company initiatives such as community service, training, recruiting, and firm events

What You’ll Do:

  • Lead client engagements implementing cybersecurity programs aligned with SOC 2, ISO 27001, and other security and privacy frameworks
  • Conduct compliance readiness assessments and assist with external audits
  • Maintain day-to-day compliance, security, and privacy operations, including incident response tabletop exercises and formalizing response and notification procedures
  • Assist clients with key security and compliance initiatives, including risk assessments, business continuity planning, cloud configurations, user access reviews, and asset inventories
  • Implement and manage GRC platforms (e.g., Drata GRC platform, Vanta compliance automation platform, Tugboat Logic platform)
  • Perform vendor risk reviews, including analyzing SOC 2 reports and managing security questionnaires
  • Develop and maintain security policies and standard operating procedures (SOPs) across key domains
  • Coordinate project activities, set priorities, and track progress against timelines, budgets, and deliverables
  • Communicate regularly with clients to manage expectations and provide project status updates
  • Deliver clear written and verbal presentations, including recommendations for operational and financial improvements to executive stakeholders
  • Conduct interviews with prospective Associates and Senior Associates, assessing candidate suitability while serving as a brand ambassador for the CSDP practice and Riveron
  • Stay current on emerging risks and evolving control practices
  • Build and maintain strong industry relationships to support long-term business development

Requirements

  • Bachelor’s and/or Master’s degree in Information Technology (IT), Computer Information Systems (CIS), Management Information Systems (MIS), or a related field
  • Relevant certification preferred, such as CISA, CISM, CISSP or AWS Cloud Practitioner
  • 5+ years of experience in an IT Audit, Cybersecurity or IT Risk Advisory role
  • Demonstrated knowledge of compliance frameworks such as SOC 2, ISO 27001, HIPAA, PCI-DSS, NIST, FedRAMP, CMMC
  • Familiarity with GRC solutions, tools, and technologies

About the company

At Riveron, we partner with clients-from global multinationals to high-growth private entities-to solve complex finance challenges, guided by our DELTA values: Drive, Excellence, Leadership, Teamwork, and Accountability. Our entrepreneurial culture thrives on collaboration, diverse perspectives, and delivering exceptional outcomes. We are committed to fostering growth, both for our clients and our people, through mentorship, integrity, and a client-centric approach. This inclusive environment offers flexibility, progressive benefits, and meaningful opportunities for impactful work that supports well-being in and out of the office.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.dice.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:07 min

Summarizing critical actions for organizational cybersecurity compliance readiness

Matthew Brady Matthew Brady · World Congress 2026 Europe

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

2:27 min

Introduction to WebAssembly in a cloud computing context

Edo Edo · World Congress 2024

3:24 min

Testing applications with Microsoft accessibility insights tool

Dennie Declercq · LIVE

5:03 min

Navigating new cybersecurity compliance frameworks and laws

Kurt Eder · LIVE

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

Videos

See all

Related articles

See all