About the Role
We are seeking an experienced L3 Cyber Risk & Compliance Advisor to support cyber risk management, compliance, and assurance activities across our US and International operations.
This role works closely with cybersecurity, IT, and operational technology (OT) stakeholders to identify, assess, communicate, and manage cyber risks while strengthening the organization's overall security posture.
As part of the Cyber Security function, you will contribute to risk and compliance initiatives, secure-by-design reviews, cyber awareness programs, and cyber resilience activities across a diverse technology landscape.
Key Responsibilities
Cyber Risk & Assurance
- Conduct cybersecurity assessments and risk evaluations across applications, infrastructure, projects, and vendors.
- Identify and document risks, control gaps, and remediation recommendations.
- Evaluate security controls against internal standards and industry frameworks.
- Support risk reporting, trend analysis, and cyber threat awareness activities.
Compliance & Governance
- Support the development and maintenance of cybersecurity policies, standards, and procedures.
- Ensure regulatory and compliance requirements are incorporated into assessments and recommendations.
- Participate in governance, reporting, and control assurance processes.
- Monitor remediation plans, risk treatment activities, and security exceptions.
Secure by Design
- Support secure-by-design reviews for new and evolving technologies.
- Provide risk-based guidance during architecture reviews and project lifecycle activities.
- Validate compliance with cybersecurity standards and baseline controls.
- Identify and escalate security risks and control deficiencies.
Stakeholder Engagement
- Partner with IT, cybersecurity, digital, operational, and business teams.
- Communicate security expectations and recommendations to project teams and system owners.
- Collaborate with vendors and third-party partners on risk and assurance activities.
- Present cybersecurity findings in both technical and business-friendly language.
Cyber Resilience & Awareness
- Support cyber awareness initiatives and promote a strong security culture.
- Assist during cyber incident and crisis management activities when required.
- Contribute to business continuity, resilience, and post-incident improvement efforts.
What You'll Bring
Required Experience
- 8-10 years of experience in Cybersecurity, IT Risk, Compliance, Audit, or related fields.
- Proven experience conducting cybersecurity assessments and risk management activities.
- Experience working within enterprise IT environments.
- Strong understanding of cybersecurity governance and assurance frameworks.
Technical Knowledge
Experience with:
- Identity & Access Management (IAM)
- Multi-Factor Authentication (MFA)
- Privileged Access Management (PAM)
- Network Security & Segmentation
- Endpoint Security
- Security Logging & Monitoring
- Vulnerability Management
- Risk Assessment and Remediation Processes
Knowledge of frameworks and standards including:
- NIST Cybersecurity Framework (CSF)
- ISO 27001
- CIS Controls
Education & Certifications
Required
- Bachelor's degree in Cybersecurity, Information Technology, Engineering, or a related field.
Preferred
- Master's degree in Cybersecurity, Computer Science, or a related discipline.
- One or more of the following certifications:
- CISSP
- CISM
- CRISC
- Security+
- ISO 27001 Certification (or working toward certification)