Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

JD 10 - Security, Risk & Compliance | Senior Consultant

Part-time

Sumeru Solutions

JD 10 - Security, Risk & Compliance | Senior Consultant

The Depository Trust & Clearing Corporation | | Source Row 72 | RR(s): RR-0708212

Client Name (Column AD)

The Depository Trust & Clearing Corporation

Job Description (Column W)

Included below under Role Scope & Key Responsibilities

Role Specialization (Column G)

Security, Risk & Compliance

Role Experience (Column F)

Senior Consultant - L6, 8+ years relevant experience

Role Summary

Lead AWS Security Agent implementation and operationalization for financial services migration, specializing in multi-account security guardrails, IAM/SSO policy design, and regulatory compliance (NIST CSF 2.0, DORA, PCI DSS, SEC cyber rules). Architect threat modeling frameworks (STRIDE/PASTA) across 15+ AWS services, design penetration testing validation workflows, and establish AWS Backup logical air gap architectures. Author DTCC-aligned security requirements, operational runbooks, and security baseline configurations for Amazon EKS environments while ensuring compliance with financial services regulatory standards.

Role Scope & Key Responsibilities (from Column W)

Primary Responsibilities:

  • Security Agent Leadership (WS-1): Design and implement AWS Security Agent access control models, author DTCC-aligned custom security requirements, validate penetration testing findings, and establish operational security baselines
  • Identity & Access Management: Configure AWS IAM Identity Center (SSO) with federated authentication, design per-Agent-Space IAM deny policies, implement least-privilege Service Control Policies (SCPs), and establish cross-account access patterns
  • Threat Modeling Leadership (WS-4): Lead STRIDE/PASTA threat modeling workshops across up to 15 AWS services, produce comprehensive threat registers, prioritize security control backlogs, and map controls to identified threats
  • Security Documentation: Author Security Agent Architecture & Design Document, operational runbooks, security implementation guides, and compliance validation frameworks aligned with DTCC security standards
  • Amazon EKS Security: Design and implement Amazon EKS security baseline configurations, pod security policies/standards, network policies, secrets encryption, and lab environment security controls
  • Backup & Recovery Security: Design AWS Backup logical air gap architectures with WORM vault locking, cross-account/cross-region backup strategies, and immutable backup validation
  • Regulatory Compliance: Review and incorporate customer organizational security requirements into AWS deliverables, validate implementations against NIST CSF 2.0, DORA, PCI DSS, and SEC cyber rules
  • Penetration Testing Coordination: Coordinate penetration testing activities via Security Agent, validate findings, prioritize remediation, and implement security hardening measures

Key Deliverables:

  • Security Agent Architecture & Design Document
  • IAM Identity Center SSO configuration with per-Agent-Space policies
  • STRIDE/PASTA threat registers and prioritized security control backlogs
  • Security Agent operational runbooks and implementation guides
  • Amazon EKS security baseline and lab environment configurations
  • AWS Backup logical air gap architecture design
  • Compliance validation reports (NIST CSF 2.0, DORA, PCI DSS, SEC)

Penetration testing validation reports and remediation plans

AWS Skills & Services (added)

Security & Compliance:

  • AWS Security Hub: Centralized security findings aggregation, compliance standards (CIS, PCI-DSS, NIST), automated remediation workflows, custom insights, and cross-account security posture management
  • AWS IAM Identity Center (SSO): SAML/OIDC federation, multi-account access management, permission sets, session policies, MFA enforcement, and identity provider integration
  • AWS IAM: Advanced policy authoring (identity-based, resource-based, permission boundaries), SCP design for multi-account guardrails, deny policies, least-privilege access patterns, and cross-account roles
  • AWS Organizations: Multi-account strategy, OU structure design, SCP policies, consolidated billing, and cross-account governance
  • AWS GuardDuty: Threat detection, malware protection, runtime monitoring, S3 protection, EKS protection, and automated threat response
  • Amazon Macie: Sensitive data discovery, PII detection, S3 bucket classification, compliance reporting, and data loss prevention
  • AWS Config: Configuration compliance, conformance packs (NIST, PCI-DSS), remediation actions, resource inventory, and drift detection
  • AWS CloudTrail: Multi-region trails, log file validation, CloudTrail Insights, event history analysis, cross-account logging, and immutable audit trails
  • AWS Audit Manager: Compliance framework automation (NIST CSF 2.0, DORA, PCI DSS, SEC), evidence collection, audit-ready reports, and continuous compliance monitoring
  • AWS Security Lake: Centralized security data lake (OCSF format), log aggregation, threat hunting, and SIEM integration
  • AWS Secrets Manager: Secure credential management, secret rotation, cross-account access, and integration with IAM policies
  • AWS KMS: Customer Managed Keys (CMKs), key policies, cross-region key replication, envelope encryption, CloudHSM integration, and FIPS 140-2 compliance

Backup & Disaster Recovery:

  • AWS Backup: Centralized backup management, WORM vault locking (Vault Lock), logical air gap design, cross-account/cross-region backup, 3-2-1 backup strategy, and compliance reporting
  • AWS Backup Audit Manager: Compliance framework design, backup policy enforcement, audit reporting, and validation testing
  • Amazon S3: Object Lock (WORM compliance), versioning, cross-region replication, Glacier Vault Lock, and immutable storage configurations

Container & Compute Security:

  • Amazon EKS: Cluster hardening, pod security policies/standards, IRSA (IAM Roles for Service Accounts), network policies, secrets encryption (AWS Secrets Manager/KMS integration), runtime security (Falco/Sysdig), and security baseline configurations
  • Amazon ECR: Image scanning (basic/enhanced), vulnerability assessment, immutable tags, lifecycle policies, encryption, and private registry configurations
  • AWS Systems Manager: Patch Manager, Session Manager (bastion replacement), Parameter Store encryption, Run Command, and hardened AMI automation

Networking & Isolation:

  • Amazon VPC: Advanced networking, security groups, NACLs, VPC Flow Logs, VPC peering, PrivateLink, Transit Gateway route isolation, and network segmentation
  • AWS Network Firewall: Stateful/stateless rules, intrusion prevention, domain filtering, TLS inspection, and threat intelligence integration
  • AWS WAF: Web application protection, managed rule groups, rate limiting, bot control, and custom rule sets
  • AWS Shield: DDoS protection (Standard/Advanced), attack mitigation, cost protection, and incident response
  • AWS PrivateLink: Service endpoint isolation, cross-account connectivity without internet exposure

Threat Modeling & Penetration Testing:

  • STRIDE Methodology: Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, Elevation of Privilege threat modeling
  • PASTA Framework: Process for Attack Simulation and Threat Analysis across AWS services
  • AWS Inspector: Vulnerability scanning for EC2/ECR, network reachability analysis, and compliance assessments
  • Amazon Detective: Security investigation, graph-based analysis, threat hunting, and incident response

Monitoring & Observability:

  • Amazon CloudWatch: Security metrics, log aggregation, anomaly detection, alarms, dashboards, and CloudWatch Logs Insights
  • AWS X-Ray: Distributed tracing for security event correlation
  • Amazon EventBridge: Event-driven security automation, cross-account event routing, and automated remediation workflows
  • AWS Step Functions: Automated incident response workflows, security orchestration, and compliance validation

Governance & Compliance:

  • AWS Control Tower: Landing zone automation, guardrails, Account Factory, compliance dashboards, and multi-account governance
  • AWS Service Catalog: Compliance-approved resource templates, self-service provisioning, and security baseline enforcement
  • AWS Resource Access Manager (RAM): Cross-account resource sharing with security controls
  • Financial Services Compliance:
  • NIST Cybersecurity Framework (CSF) 2.0: Identify, Protect, Detect, Respond, Recover, Govern framework implementation on AWS
  • DORA (Digital Operational Resilience Act): ICT risk management, incident reporting, operational resilience testing, third-party risk management
  • PCI DSS: Payment Card Industry Data Security Standard compliance (network segmentation, encryption, access control, monitoring)

SEC Cybersecurity Rules: Incident disclosure, risk management, governance, and cybersecurity expertise requirements

Financial Services & Industry Skills (added)

  • Large regulated financial-services delivery with formal change-control, audit and risk governance
  • Operational resilience expectations including RTO/RPO, multi-region DR and evidence for audit review
  • Awareness of applicable controls and regulations such as DORA, NIST CSF 2.0, PCI DSS, SEC cyber rules, RegSCI and SIFMU/FMI expectations where relevant
  • Ability to create Tech Risk-ready documentation including ADRs, runbooks, design docs, threat models and validation evidence
  • Clear communication with client engineering, security, SRE, data and platform stakeholders as an embedded SME

Certifications / Qualifications

  • AWS Certified Security - Specialty
  • AWS Certified Solutions Architect - Professional
  • AWS Certified Advanced Networking - Specialty nice to have

General Requirements

  • 8+ years of relevant hands-on delivery experience at L6 scope
  • Prior delivery in a large regulated enterprise environment, preferably financial services
  • Ability to write architecture decision records, design documents, runbooks and test evidence for client Tech Risk review
  • Strong stakeholder communication across engineering, security, operations, SRE and delivery teams
  • Compliance with AWS ProServe and client onboarding, security, vetting and time-zone overlap requirements

Vacancy posted 1 day ago
Similar jobs that could be interesting for youBased on the JD 10 - Security, Risk & Compliance | Senior Consultant in Dallas, TX vacancy
  •  ...Role Summary Lead security architecture design and threat modeling for FICC (Fixed...  ...deployments on AWS with financial services compliance focus. Role Scope & Key...  ...from Column W) Threat Modeling & Risk Assessment: Conduct STRIDE-based threat... 
    Senior
    Part time

    Sumeru Solutions

    Dallas, TX
    1 day ago
  • Crunchyroll is seeking an experienced Risk Analyst to support our Information Security GRC team. This role emphasizes governance, risk, and compliance, ensuring technology evolution aligns with employee needs and strategic goals. Successful candidates will have over 8... 
    Senior
    Flexible hours

    Crunchyroll

    Dallas, TX
    5 days ago
  • Capital Markets Regulatory Change - Consultant / Senior ConsultantLocation: Dallas, Texas (Hybrid) | Practice Area: Capital Markets...  ...of front-to-back functions (e.g., Front Office, Risk, Operations, Finance, Compliance)Knowledge of key products such as OTC derivatives, Fixed... 
    Senior

    Capco

    Dallas, TX
    8 hours ago
  •  ...Governance, Risk, and Compliance (GrC) Senior Associate Weaver is a full-service national accounting, advisory, and consulting firm with opportunities for professionals in many different fields. We seek to bring a human element to the world of accounting, which includes... 
    Senior
    Flexible hours

    Weaver

    Dallas, TX
    1 day ago
  •  ...hybrid schedule after training***JOB OVERVIEW**The Senior Compliance Officer reports directly to the Risk and Compliance Operations Officer and plays a pivotal...  ...CERTIFICATIONS*** FINRA Series 7, 24, and 63 securities licenses.* Series 4, 14, 51 or 53 securities licenses... 
    Senior
    Work at office

    Equity Trust Company

    Dallas, TX
    3 days ago
  •  ...Canadian-Owned” IT staffing/consulting company.Procom’s...  ...& Network Services• Risk Management & Compliance• Business Continuity & Disaster Recovery• Security & PrivacySpecialties•...  .../Finance. 8-10 years total experience...  ...TechnologyExperience level: Mid-Senior LevelIndustry:... 
    Senior
    Permanent employment
    Contract work
    For contractors
    H1b

    ProCom

    Richardson, TX
    1 day ago
  • $260k - $365k

     ...an exciting full-time employment opportunity for a senior level Associate in the Financial Regulatory & Compliance Practice. They can be based in our Miami, DC, New...  ...regulations (e.g., BSA/AML, sanctions, third-party risk management, and consumer compliance). Enforcement... 
    Senior
    Full time
    Temporary work
    Work at office
    Flexible hours

    Greenberg Traurig LLP

    Dallas, TX
    4 days ago
  • Covered Compliance, part of Covered Care Holdings Inc., is seeking a Compliance Analyst in Dallas, TX, on-site (Monday through Friday). The...  ...framework within FinTech and BaaS contexts. You will lead risk assessments, regulatory analysis, monitoring, testing, and reporting... 
    Senior
    Monday to Friday

    Westlake Services, LLC

    Addison, TX
    2 days ago
  • RSM US LLP is seeking a Technology Compliance & Emerging Risk Senior Associate to join the team in strengthening technology compliance, cybersecurity governance, and risk management, including AI and digital transformation initiatives. The role involves planning engagements... 
    Senior

    RSM US LLP

    Dallas, TX
    1 day ago
  • Works with Enterprise Security and Fraud subdivisions and business units as the technical...  ...Security and fraud capabilities.Works with Compliance and Regional Security and Fraud teams to...  ...approaches and dashboards to predict risk issues, develop solutions, and partner with... 
    Full time
    Work experience placement

    Vanguard

    Dallas, TX
    1 day ago
  • Capital Markets Regulatory Change - Consultant/Senior Consultant About the Team: Capco is a fully...  ...helps clients reduce costs and manage risk and regulatory change while increasing...  ...offering, including e.g. Finance, Risk and Compliance, Financial Crime, Core Banking etc. We... 
    Senior
    Contract work
    For contractors
    For subcontractor
    Work at office
    Work visa

    Capco

    Dallas, TX
    1 day ago
  • $87.2k - $130.8k

    A telecommunications company in Dallas, Texas, is seeking a Sr Specialist Compliance Analyst. This role involves overseeing compliance programs, conducting risk assessments, and ensuring adherence to regulatory standards. Candidates should have a Bachelor's degree and... 
    Senior

    AT&T

    Dallas, TX
    2 days ago
  • NorthMark Compute & Cloud (NMC²) is seeking a GRC Analyst to join the Information Security team in Dallas. You will own the security change management review, conduct risk and vendor assessments, maintain the enterprise risk register, and manage the policy library. Day... 

    NorthMark Strategies

    Dallas, TX
    4 days ago
  • $61.8k - $89.6k

     ...Office, part of Information Technology, Information Security, is seeking a Privacy and Security Compliance Specialist to join our dynamic and innovative team....  ...passionate about the evolving landscape of data privacy, risk management, and regulatory compliance, we invite you... 
    Full time
    For contractors
    Work experience placement
    Work at office
    Remote work
    Flexible hours

    Penn State University

    University Park, TX
    1 day ago
  •  ...is hiring a GRC Analyst to join the Information Security team in Dallas, TX. You will drive governance processes, risk assessments, policy library management, and...  ...maintain the enterprise risk register, ensuring compliance and effective risk mitigation across the organization... 

    NorthMark Strategies LLC

    Dallas, TX
    2 days ago
  •  ..., State, and Local income tax compliance requirements for the tax year....  ...advice, and metrics, and manage risk and controversy. You will...  ...practicesWhat You Will Bring: Experience ​10+ years of progressive and...  ...Innovation. Our unique consulting model allows you the radical flexibility... 
    Local area

    Resources Global Professionals (RGP)

    Dallas, TX
    1 day ago
  • $124k - $280k

     ...ApplicableSpecialismCybersecurity & PrivacyManagement LevelSenior ManagerJob Description & SummaryThe OpportunityAs a Security Risk & Engineering - Tech and Cyber Risk & Compliance - Senior Manager, you will play a pivotal role in guiding clients through complex regulatory landscapes,... 
    Senior
    Full time
    H1b

    PwC

    Dallas, TX
    2 days ago
  •  ...the position of a full-time Information Security Risk and Compliance Analyst at our Dallas, TX location....  ...discrepancies, and potential control gaps to senior team members for evaluation. Support...  ...or moving items weighing up to 10 pounds. Vision requirements include close... 
    Full time

    Sunflower Financial Inc.

    Dallas, TX
    3 days ago
  •  ...a full-service national accounting, advisory and consulting firm with opportunities for professionals in many...  ...Position Profile Weaver is looking for a Governance, Risk, and Compliance (GRC) Experienced Associate or Senior Associate to join our growing contract compliance... 
    Senior
    Contract work
    Flexible hours

    Weaver

    Dallas, TX
    4 days ago
  • $95.86k - $208.27k

     ...is currently seeking a Senior Associate, SAP Business Process Controls & Security to join our Advisory Technology...  ...controls, reduce risk, and support clean-core...  ...in SAP functional consulting, business process transformation...  ..., and risk and compliance capabilities Experience... 
    Senior
    H1b
    Local area

    KPMG

    Dallas, TX
    4 hours ago
  • NorthMark Compute & Cloud in Dallas, TX is seeking a GRC Analyst to join the Information Security team. You will manage security change reviews, perform risk and vendor assessments, and maintain the enterprise risk register, aligning policies with frameworks to protect... 

    NorthMark Compute & Cloud

    Dallas, TX
    2 days ago
  •  ...“Canadian-Owned” IT staffing/consulting company. Procom’s areas of staffing...  ...& Network Services • Risk Management & Compliance • Business Continuity & Disaster Recovery • Security & Privacy Specialties• Contract...  ...in Accounting/Finance. 8-10 years total experience. Someone... 
    Senior
    Permanent employment
    Contract work
    For contractors
    H1b

    Procom Services

    Richardson, TX
    4 days ago
  • $100.8k - $168k

     ...is an impact-driven, Fortune 10 company that touches virtually...  ...Summary) We are seeking a SOX Compliance professional to support the McKesson...  ...priorities. Reporting to the Senior Director of SOX Governance,...  ...industry trends, emerging risks, and opportunities (including... 
    Senior

    McKesson

    Irving, TX
    2 days ago
  • BERRY Appleman & Leiden (BAL) is seeking a GRC/Information Security professional to lead internal audits and manage ISO 27001/27701 programs from its Richardson, TX location. You’ll drive risk-based audits, support privacy operations, and help shape AI governance and vendor... 
    Senior

    BAL

    Richardson, TX
    5 days ago
  •  ...is seeking an experienced GRC/Audit professional to help manage security, privacy, and AI governance across the firm. You will lead audits...  ...collaborate with cross-functional teams, manage third-party risk, and support incident response, DLP operations, BC/DR exercises,... 
    Senior

    Berry Appleman & Leiden

    Richardson, TX
    2 days ago
  • Berry Appleman & Leiden (BAL) in Richardson, TX, is seeking an experienced Information Security, GRC, or Privacy professional to lead audits, risk assessments, and policy governance within our ISO-aligned program. You will partner with security, legal, and operations teams... 
    Senior

    Socket.dev

    Richardson, TX
    4 days ago
  • ## Senior Compliance Investigations ConsultantApplylocations: 8435 Stemmons Bldg.time type: Full...  ...* The Senior Compliance Investigations Consultant is responsible for effectively carrying...  ...and the application of the compliance risk analysis and corrective action recommendations... 
    Senior
    Work at office

    Parkland Community Health Plan Inc

    Dallas, TX
    2 days ago
  •  ...now the largest “Canadian-Owned” IT staffing/consulting company. Procom’s areas of staffing...  ...Intelligence • Infrastructure & Network Services • Risk Management & Compliance • Business Continuity & Disaster Recovery • Security & Privacy Specialties• Contract Staffing (Staff... 
    Senior
    Permanent employment
    Contract work
    For contractors

    Procom Services

    Dallas, TX
    3 days ago
  •  ...Farther is looking for a sharp, detail-oriented compliance professional to join our growing team as a Senior Regional Compliance Associate. In this role, you'll...  ...higher Bonus Points Series 7 and Series 9/10 previously held or currently active Experience... 
    Senior
    Remote work

    Farther LLC

    Irving, TX
    5 days ago
  •  ...An established industry player is seeking a seasoned network security professional with over 10 years of experience. This role demands hands-on expertise in configuring and managing Cisco and Palo Alto firewalls, alongside a robust understanding of various security technologies... 
    Senior

    TechDigital Group

    Dallas, TX
    1 day ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to JD 10 - Security, Risk & Compliance | Senior Consultant. Be the first to apply!