Cybersecurity Risk Management Consultant
Deloitte
Position Summary Our Deloitte Cyber team understands the unique challenges and opportunities businesses face in cybersecurity. Join our team to deliver powerful solutions to help our clients navigate the ever-changing threat landscape. Through powerful solutions and managed services that simplify complexity, we enable our clients to operate with resilience, grow with confidence, and proactively manage to secure success. Work You’ll Do As a US Delivery Center Delivery Senior Consultant, Software Engineering Solutions on the team, you will: Advise Government & Public Services clients in executing the National Institute of Standards and Technology (NIST) Risk Management Framework (RMF) lifecycle to mitigate cyber risk and threatsAdvise federal agency clients on cyber risk posture and RMF compliance strategies aligned to FISMA, NIST, and agency-specific requirementsLead the development and/or review of Authority to Operate (ATO) packages (e.g., System Security Plans (SSPs), Security Assessment Reports (SARs), and Plans of Action & Milestones (POA&Ms))Assess or develop an organization's cyber risk strategy as it relates to data risk, cyber risk management, risk frameworks and policies, and risk measures and reportingStrategically drive the development and execution of risk assessments and mitigation plans to enhance the client's ability to identify, evaluate, prioritize, and mitigate risksImplement risk management solutions aligned to the client's vision and strategic prioritiesDrive development and implementation of cyber strategies grounded in leading practices, industry frameworks, and targeted to the client's risk and business needsSynthesize technical findings and risk data into actionable reports and executive-level briefingsDevelop impactful presentations that support engagement goals, communicate technical findings clearly to both technical and executive audiencesDeliver key messages with clarity and confidence; tailor communication style to the audienceUnderstand how business functions operate and how industry trends impact a client's cyber posture and risk profileIdentify and evaluate complex business and technology risks, and connect findings to business impactProvide guidance and quality review to junior team members on RMF documentation, assessment artifacts, and deliverable developmentParticipate in team problem-solving efforts and offer ideas to address client challengesIdentify opportunities for efficiencies in work processes and innovative approaches to completing scope of workOwn assigned work products through final review, client submission, and resolution of quality-review commentsAssist in proposal development, as requested A successful candidate would possess these skills: Ability to work independently and collaborate as part of a teamEffective written and verbal communication skillsMeticulous attention to detail and quality of work productAbility to build and sustain professional relationshipsAbility to lead projects or workstreamsAbility to manage and prioritize multiple tasks in a fast-paced and dynamic environmentStrong interpersonal skills and professional demeanorAbility to meet deadlinesAbility to provide clear guidance to others The Team Deloitte’s Government & Public Services (GPS) practice – our people, ideas, technology and outcomes – is designed for impact. Serving federal, state, & local government clients as well as public higher education institutions, our team of professionals brings fresh perspective to help clients anticipate disruption, reimagine the possible, and fulfill their mission promise. Our Cyber Strategy & Transformation offering develops and transforms cyber programs in line with a client's strategic objectives, regulatory requirements, and risk appetite. It keeps the enterprise a step ahead of the evolving threat landscape and gives stakeholders confidence in the organization's cyber posture. Includes design of the cyber organization, governance, and risk assessments. This opportunity sits within our Deloitte US Delivery Center model, which is dedicated to driving impactful business services. It leverages Deloitte’s scale and talent, as well as a center delivery model to provide high-quality, cost-effective service with standardized processes and procedures to service businesses across Deloitte. The Deloitte US Delivery Center has a small-business feel with a big-business impact. With the resources of Deloitte and a community feel, the delivery center model provides high-quality services to our clients. USDC professionals work out of one of our specific delivery center locations, and each location presents dynamic career opportunities for professionals to focus on their work with nominal travel requirements. Qualifications Required: Bachelor’s degree in cybersecurity, information technology, information systems, computer science, risk management, business, mathematics, decision sciences, or a related field, or an equivalent combination of education, professional training, and relevant cybersecurity experience in accordance with applicable talent policies.Must be legally authorized to work in the United States without the need for employer sponsorship, now or at any time in the future 4+ years of professional experience in cybersecurity, information assurance, governance, risk and compliance, cybersecurity risk management, or federal security compliance, including at least 2 years supporting NIST RMF or an equivalent authorization process including participation in at least one end-to-end authorization cycle or multiple lifecycle phases across two or more systems.2+ years of experience applying NIST RMF concepts and NIST SP 800-37 to information-system authorization, security assessment, or continuous-monitoring activities, including 1+ year applying NIST SP 800-53 controls. Experience with the NIST CSF, FedRAMP, or agency-specific security requirements is preferred.2+ years of experience implementing, documenting, assessing, or managing NIST SP 800-53 security controls, including at least 1 year preparing control narratives, reviewing implementation evidence, documenting assessment results, or tracking remediation activities.2+ years of experience developing, updating, or quality-reviewing cybersecurity policies, procedures, standards, or implementation guidance mapped to NIST SP 800-53 controls or an equivalent federal security baseline, including experience supporting at least one moderate-impact information system.At least 2 years of experience in RMF documentation and control implementation, plus at least 1 year in three of the following: system categorization, boundary definition, control tailoring, continuous monitoring, risk assessment, vulnerability management, or GRC tool administration.Ability to obtain and maintain the level of federal security clearance or Public Trust designation required for client engagementsDelivery Center Location & Travel Requirements:Hybrid Work Model: Operate under a hybrid system requiring residence within a commutable distance to one of the US Delivery Center locations (Gilbert, Lake Mary, or Mechanicsburg) or Geo-Hub locations (Atlanta, Charlotte, Dallas, Houston, and Philadelphia)Co-location Expectation: Spend up to 30% of working time co-located at an assigned office for orchestrated opportunities, including projects, practice sessions, training, and Moments That Matter at a Deloitte Delivery Center location, Geo-Hub location, approved site, or project locationTravel Requirement: Maximum of 10% overnight travel for client or project purposesRelocation Requirement: If relocation is necessary, complete the move within 12 weeks from the start date to reside within a commutable distance Preferred: Previous federal or government consulting experience1+ year applying NIST SP 800-171, CMMC, or equivalent controlled-unclassified-information security requirements.1+ year of experience analyzing or documenting enterprise, mission-critical, cloud, or multi-system technology environments, including business processes, system dependencies, data flows, security vulnerabilities, or operational risks.1+ year of experience supporting a FedRAMP authorization, cloud security assessment, or RMF activity for AWS GovCloud, Azure Government, or an equivalent federal cloud environment.1+ year of experience delivering cybersecurity or RMF work in an Agile, hybrid-Agile, or iterative federal program environment, including sprint planning, backlog management, or incremental deliverable reviews.2+ years of experience in at least one technical domain relevant to RMF, such as security architecture, network security, cloud infrastructure, identity and access management, endpoint security, or vulnerability management.CISSP, CISM, CISA, or CEH certification Deloitte is committed to providing reasonable accommodations for people with disabilities. If you require a reasonable accommodation to participate in the recruiting process, please direct your inquiries to the Global Call Center (GCC) at View email address on click.appcast.io. Recruiting tips From developing a stand out resume to putting your best foot forward in the interview, we want you to feel prepared and confident as you explore opportunities at Deloitte. Check out recruiting tips from Deloitte recruiters. BenefitsAt Deloitte, we know that great people make a great organization. We value our people and offer employees a broad range of benefits. Learn more about what working at Deloitte can mean for you. Our people and culture Our inclusive culture empowers our people to be who they are, contribute their unique perspectives, and make a difference individually and collectively. It enables us to leverage different ways of thinking, ideas, and perspectives, and bring more creativity and innovation to help solve our clients' most complex challenges. This makes Deloitte one of the most rewarding places to work. Our purpose Deloitte’s purpose is to make an impact that matters for our people, clients, and communities. At Deloitte, purpose is synonymous with how we work every day. It defines who we are. Our purpose comes through in our work with clients that enables impact and value in their organizations, as well as through our own investments, commitments, and actions across areas that help drive positive outcomes for our communities. Learn more. Professional development From entry-level employees to senior leaders, we believe there’s always room to learn. We offer opportunities to build new skills, take on leadership opportunities and connect and grow through mentorship. From on-the-job learning experiences to formal development programs, our professionals have a variety of opportunities to continue to grow throughout their career. As used in this posting, "Deloitte" means Deloitte Transactions and Business Analytics LLP, a subsidiary of Deloitte LLP. Please see for a detailed description of the legal structure of Deloitte LLP and its subsidiaries. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability or protected veteran status, or any other legally protected basis, in accordance with applicable law. Requisition code: 366149 Job ID 366149 Engineering and Product | Software Engineering SolutionsSame job available in 8 locations
- Goldman Sachs Technology Risk leads threat and risk management initiatives that help to protect the firm and our clients from information and cyber... ...risk analysis and control frameworks (e.g., NIST Cybersecurity Framework, ISO 27001/27701).Understanding of relational...SuggestedLocal area
- ...Security (Privileged Access Management)Location: Dallas, Texas (Hybrid... ...) | Practice Area: Business Consulting | Type: PermanentHelp... ...bridging business objectives with cybersecurity solutions that improve... ...operational efficiency, and risk management.What You’ll DoFacilitate...Suggested
$48k
...Risk Management Advisor (College Graduate Program) $73,000+ Year-1 Target Earnings | $48,000 Base + 50% Commission on New Business Full-time | In-Office | Dallas, TX Start your career building a professional network and growing a book of business advising clients...SuggestedFull timeWork at office$48k
...Job Description Job Description Risk Management Advisor Full-Time, In-Office WHAT WILL YOU DO? As an Advisor you are building a book of business starting from zero (with a competitive base salary). Not afraid to prospect, your business grows out of your networks...SuggestedFull timeWork at office$130k - $150k
...Business Development Partner – Cybersecurity & Risk Advisory (Hybrid/Remote) Join a rapidly growing consulting and advisory firm helping enterprise and mid-market organizations... ..., Risk & Compliance (GRC), enterprise risk management, compliance, and digital transformation...SuggestedContract workRemote work2 days per week3 days per week- ...and address complex business risk . This role is focused on... ...growth. Solutions may include cybersecurity risk advisory, responsible AI... ...CAIOs, CROs, and CIOs. Lead consultative discovery conversations... ...and which can be accepted or managed over time? How could cybersecurity...Immediate start
- DEPARTMENT OVERVIEW The Model Risk Management (MRM) group is a multidisciplinary group of quantitative experts at Goldman Sachs with presence in New York, Dallas, London, Birmingham, Warsaw, Hong Kong, Bangalore, and Hyderabad. The MRM group is responsible for independent...
$55 - $60 per hour
...GorusuCompany: SRI Tech SolutionsTitle: Third Party Risk AnalystLocation: Dallas TXDuration:... ...:The Analyst/ Sr Analyst, Cybersecurity Risk is part of the Technology Division.... ...protecting digital ecosystem by identifying and managing cybersecurity risks. You will help shape...Hourly payFull timeContract work- ...the business, and facilitation of executive reporting.Proactively identify potential business risks, process deficiencies, and potential gaps/ weaknesses in risk management standards.Develop process and controls environment (inventory and maps) across asset management...
$62k - $100k
...across our audit, tax, and consulting groups. That’s why we continuously... ...: Analyze business, risk, compliance, audit, security... ...opportunities. Support IT audits, cybersecurity assessments, compliance... ...processes such as change management, logical access, IT...Full timeLocal areaWorldwide- Asset & Wealth Management Divisional Overview A career with Goldman Sachs Asset & Wealth Management is an opportunity to help clients across... ...outside the box? Associates on the Asset & Wealth Management Risk Team will gain exposure and access to senior managers, build...Private practiceWork at office
$87.36k - $131.04k
...164753056Posted: 2026-09-04Location: Irving, Texas, United StatesSalary: $87,360.00 - $131,040.00Category: Risk ManagementCompany: CitiSummary:The Risk Management Country Sr. Analyst supports the oversight and execution of country risk management activities by conducting...Full timeFlexible hours- OverviewWe are seeking a highly motivated and detail-oriented Operational Risk Associate to join our AM Private Operational Risk team. This position plays an integral role in supporting the risk management framework across multiple business segments within the Goldman Sachs...Work at office
- RISK Goldman Sachs’ Risk Division develops comprehensive programs and processes to identify, monitor, assess and manage financial and non-financial risks in support of the firm’s risk appetite statement and strategic business plans. Risk teams play a critical function for...Work experience placement
$114.72k - $172.08k
Job ID: 100494888176Posted: 2026-09-11Location: Irving, Texas, United StatesSalary: $114,720.00 - $172,080.00Category: Risk Management, ProfessionalCompany: CitiAn individual in Enterprise Risk Management plays a critical role in managing the bank's diverse risks to ensure...Full timeInterim role$75k - $110k
Risk Management Analyst At Prologis, we don’t just lead the industry—we define it with a 1.3 billion square foot portfolio and an annual throughput of approximately $3.2 trillion. We create the intelligent infrastructure that powers global commerce, seamlessly connecting...Full time- ...integrated full-service solutions leverage a 99-year legacy in event management as well as new technologies to deliver moments that matter. Summary Professional analyst role that supports the Enterprise Risk Management (ERM) program under limited supervision. Identifies,...Work at officeLocal area2 days per week3 days per week
- ...operations specialist, you will play a key role in supporting and managing the employee life cycle and business needs in delivering... ...region including postings on Root Cause Analysis, initiation of Risk Tickets etc.Transactional Management for all employee lifecycle...
- ...world's trusted infrastructure consulting firm, partnering with... ...innovators, program and construction managers and other professionals... ...support function within the Cybersecurity Engineering team, with an initial... ..., enterprise reporting and risk visibility remain core to...Work at officeLocal areaRemote workWorldwideFlexible hours
- ...that are currently available and apply online.Job SummaryLead Risk Analyst - Modeling & Valuation is responsible for analyzing and... ...relevant experience.•3-5 years of experience in Structuring, Risk Management, or Trading preferred•Proficiency in programming languages such...Full timeLocal area
$91k - $202.8k
...success. As a(n) Technology Risk Advisor within PNC's Technology... ...technology risk management practices within the Line of... ...risk exposures, including:· Cybersecurity events· System failures and... ...organizational risk appetite. Provides consultation to support the...Full timeTemporary workPart timeWork experience placementWork at office- ...future of North America's energy landscape.ERM is seeking a Managing Consultant, Project Manager based in the Gulf Coast region (Louisiana) to... ...depends on strong leadership, regulatory expertise, and effective risk management. In this role, you will serve as a trusted advisor...Full timeWork at officeLocal area
- ...issues across the business, and facilitation of executive reporting.Analyze potential business risks, process deficiencies, and potential gaps/ weaknesses in risk management standards.Support developing process and controls environment (inventory and maps) across asset...
- Asset Management Public Operational RiskThe Asset Management Public Operational Risk team is a First Line of Defense (1LoD) risk function responsible for identifying, assessing, managing, and monitoring operational risks within the Asset Management Public business. The...Shift work
- ...Business Credit organization, you will be based in Dallas, TX. Managing Director, Sponsor & Direct Coverage - PNC Business CreditPosition... ...the client's financing requirements meet PNC parameters. Manages risk/return and actively identifies and mitigates different types of...Full timeTemporary workPart timeWork experience placementWork at officeFlexible hours
- ...the largest “Canadian-Owned” IT staffing/consulting company.Procom’s areas of staffing... ...include:• Application Development• Project Management• Quality Assurance• Business/Systems Analysis... ...• Infrastructure & Network Services• Risk Management & Compliance• Business Continuity...Permanent employmentContract workFor contractorsH1b
- ...Personal Risk Specialist The Personal Risk Specialist is an outside sales position focused on serving the... ...net worth individuals, with the ability to provide consultative advice to tailor personal risk management solutions accordingly. Achieve new business sales...Temporary workLocal areaFlexible hours
- The Goldman Sachs Group is seeking an Associate in Richardson, Texas, to manage risk and compliance as part of the Marcus US Deposits Business Controls. The role involves executing key control deliverables and collaborating with cross-functional teams to ensure regulatory...
- ...Goldman Sachs Group is seeking an energetic self-starter for a role in their Risk Division in Dallas, Texas. This position involves liaising with senior stakeholders, executing risk management programs, and contributing to governance framework design. Candidates should...
- Goldman Sachs Group, Inc. in Dallas is seeking an Internal Auditor to enhance governance and risk management. The role offers diverse opportunities to assess and improve internal controls, with a focus on market risk and regulatory compliance. Ideal candidates will have...
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Cybersecurity Risk Management Consultant. Be the first to apply!
- cyber security consultant Dallas, TX
- cyber security specialist Dallas, TX
- it risk analyst Dallas, TX
- risk consultant Dallas, TX
- third party risk analyst Dallas, TX
- risk analyst Dallas, TX
- transaction risk analyst Dallas, TX
- operational risk specialist Dallas, TX
- risk officer Dallas, TX
- senior quantitative risk analyst Dallas, TX



