Cybersecurity Risk Management Consultant
Deloitte
Position Summary Our Deloitte Cyber team understands the unique challenges and opportunities businesses face in cybersecurity. Join our team to deliver powerful solutions to help our clients navigate the ever-changing threat landscape. Through powerful solutions and managed services that simplify complexity, we enable our clients to operate with resilience, grow with confidence, and proactively manage to secure success. Work You’ll Do As a US Delivery Center Delivery Senior Consultant, Software Engineering Solutions on the team, you will: Advise Government & Public Services clients in executing the National Institute of Standards and Technology (NIST) Risk Management Framework (RMF) lifecycle to mitigate cyber risk and threatsAdvise federal agency clients on cyber risk posture and RMF compliance strategies aligned to FISMA, NIST, and agency-specific requirementsLead the development and/or review of Authority to Operate (ATO) packages (e.g., System Security Plans (SSPs), Security Assessment Reports (SARs), and Plans of Action & Milestones (POA&Ms))Assess or develop an organization's cyber risk strategy as it relates to data risk, cyber risk management, risk frameworks and policies, and risk measures and reportingStrategically drive the development and execution of risk assessments and mitigation plans to enhance the client's ability to identify, evaluate, prioritize, and mitigate risksImplement risk management solutions aligned to the client's vision and strategic prioritiesDrive development and implementation of cyber strategies grounded in leading practices, industry frameworks, and targeted to the client's risk and business needsSynthesize technical findings and risk data into actionable reports and executive-level briefingsDevelop impactful presentations that support engagement goals, communicate technical findings clearly to both technical and executive audiencesDeliver key messages with clarity and confidence; tailor communication style to the audienceUnderstand how business functions operate and how industry trends impact a client's cyber posture and risk profileIdentify and evaluate complex business and technology risks, and connect findings to business impactProvide guidance and quality review to junior team members on RMF documentation, assessment artifacts, and deliverable developmentParticipate in team problem-solving efforts and offer ideas to address client challengesIdentify opportunities for efficiencies in work processes and innovative approaches to completing scope of workOwn assigned work products through final review, client submission, and resolution of quality-review commentsAssist in proposal development, as requested A successful candidate would possess these skills: Ability to work independently and collaborate as part of a teamEffective written and verbal communication skillsMeticulous attention to detail and quality of work productAbility to build and sustain professional relationshipsAbility to lead projects or workstreamsAbility to manage and prioritize multiple tasks in a fast-paced and dynamic environmentStrong interpersonal skills and professional demeanorAbility to meet deadlinesAbility to provide clear guidance to others The Team Deloitte’s Government & Public Services (GPS) practice – our people, ideas, technology and outcomes – is designed for impact. Serving federal, state, & local government clients as well as public higher education institutions, our team of professionals brings fresh perspective to help clients anticipate disruption, reimagine the possible, and fulfill their mission promise. Our Cyber Strategy & Transformation offering develops and transforms cyber programs in line with a client's strategic objectives, regulatory requirements, and risk appetite. It keeps the enterprise a step ahead of the evolving threat landscape and gives stakeholders confidence in the organization's cyber posture. Includes design of the cyber organization, governance, and risk assessments. This opportunity sits within our Deloitte US Delivery Center model, which is dedicated to driving impactful business services. It leverages Deloitte’s scale and talent, as well as a center delivery model to provide high-quality, cost-effective service with standardized processes and procedures to service businesses across Deloitte. The Deloitte US Delivery Center has a small-business feel with a big-business impact. With the resources of Deloitte and a community feel, the delivery center model provides high-quality services to our clients. USDC professionals work out of one of our specific delivery center locations, and each location presents dynamic career opportunities for professionals to focus on their work with nominal travel requirements. Qualifications Required: Bachelor’s degree in cybersecurity, information technology, information systems, computer science, risk management, business, mathematics, decision sciences, or a related field, or an equivalent combination of education, professional training, and relevant cybersecurity experience in accordance with applicable talent policies.Must be legally authorized to work in the United States without the need for employer sponsorship, now or at any time in the future 4+ years of professional experience in cybersecurity, information assurance, governance, risk and compliance, cybersecurity risk management, or federal security compliance, including at least 2 years supporting NIST RMF or an equivalent authorization process including participation in at least one end-to-end authorization cycle or multiple lifecycle phases across two or more systems.2+ years of experience applying NIST RMF concepts and NIST SP 800-37 to information-system authorization, security assessment, or continuous-monitoring activities, including 1+ year applying NIST SP 800-53 controls. Experience with the NIST CSF, FedRAMP, or agency-specific security requirements is preferred.2+ years of experience implementing, documenting, assessing, or managing NIST SP 800-53 security controls, including at least 1 year preparing control narratives, reviewing implementation evidence, documenting assessment results, or tracking remediation activities.2+ years of experience developing, updating, or quality-reviewing cybersecurity policies, procedures, standards, or implementation guidance mapped to NIST SP 800-53 controls or an equivalent federal security baseline, including experience supporting at least one moderate-impact information system.At least 2 years of experience in RMF documentation and control implementation, plus at least 1 year in three of the following: system categorization, boundary definition, control tailoring, continuous monitoring, risk assessment, vulnerability management, or GRC tool administration.Ability to obtain and maintain the level of federal security clearance or Public Trust designation required for client engagementsDelivery Center Location & Travel Requirements:Hybrid Work Model: Operate under a hybrid system requiring residence within a commutable distance to one of the US Delivery Center locations (Gilbert, Lake Mary, or Mechanicsburg) or Geo-Hub locations (Atlanta, Charlotte, Dallas, Houston, and Philadelphia)Co-location Expectation: Spend up to 30% of working time co-located at an assigned office for orchestrated opportunities, including projects, practice sessions, training, and Moments That Matter at a Deloitte Delivery Center location, Geo-Hub location, approved site, or project locationTravel Requirement: Maximum of 10% overnight travel for client or project purposesRelocation Requirement: If relocation is necessary, complete the move within 12 weeks from the start date to reside within a commutable distance Preferred: Previous federal or government consulting experience1+ year applying NIST SP 800-171, CMMC, or equivalent controlled-unclassified-information security requirements.1+ year of experience analyzing or documenting enterprise, mission-critical, cloud, or multi-system technology environments, including business processes, system dependencies, data flows, security vulnerabilities, or operational risks.1+ year of experience supporting a FedRAMP authorization, cloud security assessment, or RMF activity for AWS GovCloud, Azure Government, or an equivalent federal cloud environment.1+ year of experience delivering cybersecurity or RMF work in an Agile, hybrid-Agile, or iterative federal program environment, including sprint planning, backlog management, or incremental deliverable reviews.2+ years of experience in at least one technical domain relevant to RMF, such as security architecture, network security, cloud infrastructure, identity and access management, endpoint security, or vulnerability management.CISSP, CISM, CISA, or CEH certification Deloitte is committed to providing reasonable accommodations for people with disabilities. If you require a reasonable accommodation to participate in the recruiting process, please direct your inquiries to the Global Call Center (GCC) at View email address on click.appcast.io. Recruiting tips From developing a stand out resume to putting your best foot forward in the interview, we want you to feel prepared and confident as you explore opportunities at Deloitte. Check out recruiting tips from Deloitte recruiters. BenefitsAt Deloitte, we know that great people make a great organization. We value our people and offer employees a broad range of benefits. Learn more about what working at Deloitte can mean for you. Our people and culture Our inclusive culture empowers our people to be who they are, contribute their unique perspectives, and make a difference individually and collectively. It enables us to leverage different ways of thinking, ideas, and perspectives, and bring more creativity and innovation to help solve our clients' most complex challenges. This makes Deloitte one of the most rewarding places to work. Our purpose Deloitte’s purpose is to make an impact that matters for our people, clients, and communities. At Deloitte, purpose is synonymous with how we work every day. It defines who we are. Our purpose comes through in our work with clients that enables impact and value in their organizations, as well as through our own investments, commitments, and actions across areas that help drive positive outcomes for our communities. Learn more. Professional development From entry-level employees to senior leaders, we believe there’s always room to learn. We offer opportunities to build new skills, take on leadership opportunities and connect and grow through mentorship. From on-the-job learning experiences to formal development programs, our professionals have a variety of opportunities to continue to grow throughout their career. As used in this posting, "Deloitte" means Deloitte Transactions and Business Analytics LLP, a subsidiary of Deloitte LLP. Please see for a detailed description of the legal structure of Deloitte LLP and its subsidiaries. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability or protected veteran status, or any other legally protected basis, in accordance with applicable law. Requisition code: 366149 Job ID 366149 Engineering and Product | Software Engineering SolutionsSame job available in 8 locations
- Risk Management Analyst - Operations & Claims Location: Chandler, AZ Reports To: VP of Treasury Management Services FLSA Status: Exempt Position Summary The Risk Management Analyst is responsible for building, standardizing, and managing the company’s risk management...SuggestedWork at officeRemote workMonday to FridayMonday to Thursday
$104k - $166k
ResponsibilitiesPeraton is currently seeking a Senior Risk and Vulnerability Analyst.Location:... ...: Bachelor’s degree in Cybersecurity, Information Technology, or related field... ...experience in security operations, vulnerability management, or risk analysis. 6 years of experience...SuggestedContract workShift work- Vehere Business Development Manager\n\nLocation: This role is onsite at our HQ in Chandler, AZ from a hyrbid capacity. \n\nCompensation... ...Solutions Integrator with deep expertise in cloud, data, AI, cybersecurity, and intelligent edge, we guide organizations through complex...SuggestedFull timeLocal areaImmediate start
- ...sans-serif; color: black;\"\u003ePartner Business Development Manager, Honeywell \u0026amp; Bluest\u003c/span\u003e\u003c/strong\u00... ...Integrator\u003c/strong\u003e with deep expertise in cloud, data, AI, cybersecurity, and intelligent edge, we guide organisations through complex...SuggestedFull timeLocal areaImmediate start
- ...Requisition Number: 106194 Business Development Manager – Fortinet Location: Hybrid at an Insight office in Chandler, AZ... ...Solutions Integrator with deep expertise in cloud, data, AI, cybersecurity, and intelligent edge, we guide organizations through complex...SuggestedWork experience placementWork at officeLocal areaImmediate start
- Apex Systems, Inc in Chandler, AZ is hiring an IT Risk & Governance Analyst on a 12-month contract hybrid role. You will manage IT risk, inventory management systems, and enterprise infrastructure documentation, coordinating with engineering teams and security staff. The...Contract work
$100k - $179k
...Senior Risk Asset Review Specialist Wells Fargo is seeking a Senior Risk Asset Review... ...Risk, which independently oversees the management of credit risk exposures (including monitoring... ...requirements. Collaborate and consult with peers, colleagues, and managers to resolve...Work experience placementRelocation package- ...role:Wells Fargo is seeking a Lead Credit Risk Officer to support the rationalization,... ...expectations, the bank's risk appetite, and Policy Management requirements. The successful candidate... ...of supported businessesCollaborate and consult with peers, colleagues and managers to...Full timeWork experience placement
- ...loanDepot is hiring for an Enterprise Risk Management position located in Southfield, Michigan. This role is essential for executing fair lending risk management initiatives, including analytical reporting and compliance monitoring. The ideal candidate has over five years...
- ...continued evolution of Identity and Access Management (IAM) Operations.Identity and access... ...access at the right time while reducing risk across the enterprise.We're looking for... ...management. You'll partner across technology, cybersecurity, and business teams to execute critical...Full timeWork experience placementWork at officeWork from homeVisa sponsorship2 days per week3 days per week
$70k - $80k
...Requisition Number: 103813 Partner Business Development Manager, Lenovo Infrastructure Location: The role will be an on-site/hybrid... ...Solutions Integrator with deep expertise in cloud, data, AI, cybersecurity, and intelligent edge, we guide organisations through complex...Full timeLocal areaImmediate start$134.5k - $265.1k
Position Summary As a Senior Consultant in Deloitte Cyber’s Digital Trust & Privacy... ...quality of work product, ability to manage and prioritize multiple tasks in a fast... ..., Engineering, Information Technology, Cybersecurity, or a related field; alternatively, equivalent...Local areaVisa sponsorship$135.9k - $220k
...identifying emerging talent, fostering leadership skills, and managing stakeholders.Accountable for the operational management and day... ...improvement opportunities. Drives management of process documentation, risks, controls, metrics, governance routines, and audit activities....Full timeWork at officeDay shift$119k - $206k
...Lead Information Security Analyst in Cybersecurity supporting Identity and Access Management (IAM). Learn more about career... ...Provide advanced information security consultation for all aspects of information security compliance policy, risk management, and remediation...Work experience placementWork at officeRemote workRelocation package- ...contribute to the company’s success. As a Wealth Advisor in PNC Wealth Management, you will be based in Arizona.PNC is an in-office company that... ...information in creating customized customer solutions.Managing Risk - Assessing and effectively managing all of the risks...Full timeTemporary workPart timeWork experience placementWork at office
- ...individuals who want to be part of something meaningful while advancing their own professional journey. The position of Senior Risk Management Analyst supports the Risk Management Department and multi-industry operational subsidiaries in all aspects of the corporate...Contract workTemporary workWork at officeImmediate startWorldwide
- ...the company's success. As a Financial Advisor within PNC Wealth Management, you will be based in Gilbert, AZ.Financial Advisors are based... ...information in creating customized customer solutions.Managing Risk - Assessing and effectively managing all of the risks associated...Full timeTemporary workPart timeWork at office
- ...Solutions Integrator with deep expertise in cloud, data, AI, cybersecurity, and intelligent edge, we guide organisations through complex... ...analysis Creating commitment analysis and dashboards for IPS Management Providing cross‑functional engagement and support...InternshipLocal areaImmediate start
- ...the largest “Canadian-Owned” IT staffing/consulting company.Procom’s areas of staffing... ...include:• Application Development• Project Management• Quality Assurance• Business/Systems Analysis... ...• Infrastructure & Network Services• Risk Management & Compliance• Business Continuity...Permanent employmentContract workFor contractorsH1b
- ...Chandler, AZ is seeking an Operations Project Consultant to lead medium to large initiatives... ...analyze processes, and partner with senior management to propose changes and measure outcomes. The role emphasizes documentation, risk management, and cross-functional...Work at officeFlexible hours
$81.45k - $105.88k
...details Job Role Infrastructure Consultant 2 Career Role Consultant - Infrastructure Management - US Work Location Plano, TX... ...Technical Skills 2 Domain|Enterprise Risk Management|Regulations & Compliance...Full timeTemporary workRelocation$105.4k - $207.8k
...team to deliver powerful solutions to help our clients navigate the ever-changing threat landscape. Through powerful solutions and managed services that simplify complexity, we enable our clients to operate with resilience, grow with confidence, and proactively manage to...Local areaVisa sponsorship$84.3k - $173.3k
...Deloitte US Chinese Services Group (CSG) - Project Management Senior Consultant About US CSG Established in 2003, the Deloitte US Chinese... ...or personnel information with discretionIdentify execution risks or bottlenecks and escalate issues as appropriate The successful...Work at officeLocal areaVisa sponsorship$105.4k - $124k
...from Day One.Job DescriptionThe Fair and Responsible Banking Risk Consultant will support the Fair and Responsible Banking (FaRB) Program... ..., and develop practical guidance that promotes sound risk management. The individual in this role will support program initiatives...Full timeWork experience placementWork at officeLocal area3 days per week$105.4k - $207.8k
...opportunities businesses face in cybersecurity. Join our team to deliver... ...powerful solutions and managed services that simplify complexity... ...professional at Deloitte Consulting, you will be responsible for... ...delivery on track and surface risks early.Stay current on...Local areaVisa sponsorship- ...and recurring failure patterns. Experience performing impact assessments and risk evaluations. Excellent problem-solving and critical thinking skills. Production Support & Incident Management Business & Technical Analysis Root Cause Analysis Release & Change...
- ...ProgramsAbout this role:Wells Fargo is seeking a Business Execution Consultant to support the successful delivery of strategic ATM network... .... This role will support project planning, implementation, risk management, milestone tracking, and cross-functional coordination...Full timeFor contractorsWork experience placementRelocation
- ...Urgency, Deliver Excellence Minimum Qualifications Required: Deadline-oriented, self-motivated, and possessing the ability to manage multiple projects simultaneously Strong writing capabilities, organizational skills, interpersonal skills and follow-through...Full timeWork at officeLocal areaMonday to Friday
- ...Senior Business Execution Consultant / Learning and Development FacilitatorAt Wells Fargo,... ...Facilitator within the Training & Access Management function of Fraud & Claims Management (FCM... ...Fraud, Payment Fraud, and other high-risk fraud prevention and detection functions...Work experience placementWork at officeFlexible hours
- ...OverviewThe Senior AI and Emerging Tech Engagement Manager is a senior advisor and delivery leader... ...business outcomes.Serving as a trusted consultant, you will translate complex and ambiguous... ...functional teams (technology, analytics, risk, operations) to ensure solutions are...Temporary workWork at officeHome officeFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Cybersecurity Risk Management Consultant. Be the first to apply!


