#2025-12105
onduct risk assessments, security readiness audits, gap analysis with compliance and regulatory frameworks
Assess compliance with industry standards and regulatory frameworks, such as, NIST 800-171/53, ISO 27001, COSO, CMMC, HIPPA, PCI, or some combination of these
Assist clients in developing risk management frameworks and mitigation strategies
Provide third-party risk assessments to evaluate client's supply chain, key vendors
Support the design and implementation of cybersecurity policies, procedures, and governance frameworks
Develop and refine security strategy assessments, security program plans, and POA&M
Translate security operational and technical risks into business implications with recommendations for stakeholders
Conduct workshops, stakeholder interviews, security awareness sessions and presentations with key client stakeholders
Collaborate with Principal Consultants and Technical Managers to support client objectives
Maintain clear documentation and reporting for security findings, analysis and recommendations
Stay updated on emerging cybersecurity, risk management, key technologies and regulations
Contribute to thought leadership through research, whitepapers and presentations
Effectively provide knowledge transfer and post-production support activities as necessary
What we're looking for
Bachelor's degree and approximately 5-7 years of related work experience, preferably in a prior consultancy role
Hold or pursue relevant certifications in the cybersecurity and risk management industry such as, CISSP, CISM, CRISC, CCSP, CMMC CCP/CCA, ISO 27001 (Lead implementer)
Strong understanding of cybersecurity frameworks (NIST, ISO 27001, CMMC, CIS, PCI, HIPPA, etc.)
Hands on experience with security assessments, risk management, compliance assessments, policy and standards and other related risk and compliance activities
Experience working in cyber resilience including, Business Continuity Planning, Disaster Recovery, Business Impact Analysis, Operational Resilience.
Strong analytical and problem-solving skills for cybersecurity challenges
Excellent communication and report writing skills for client engagements
Ability to manage multiple projects and work independently in a fast-paced environment
Willingness to travel to meet client needs
Valid driver's license in the US
The successful candidate must hold related professional certifications such as the CISSP, CISM, and/or CISA
#LI-SM1
What you can expect from Optiv
A company committed to championing Diversity, Equality, and Inclusion through our Employee Resource Groups.
Work/life balance
Professional training resources
Creative problem-solving and the ability to tackle unique, complex projects
Volunteer Opportunities. "Optiv Chips In" encourages employees to volunteer and engage with their teams and communities.
The ability and technology necessary to productively work remotely/from home (where applicable)
EEO Statement
Optiv is an equal opportunity employer (EEO). All qualified applicants for employment will be considered without regard to race, color, religion, sex, gender identity, sexual orientation, national origin, status as an individual with a disability, veteran status, or any other basis protected by federal, state, or local law.
Optiv respects your privacy. By providing your information through this page or applying for a job at Optiv, you acknowledge that Optiv will collect, use, and process your information, which may include personal information and sensitive personal information, in connection with Optiv's selection and recruitment activities. For additional details on how Optiv uses and protects your personal information in the application process, click here to view our Applicant Privacy Notice. If you sign up to receive notifications of job postings, you may unsubscribe at any time.