Principal Cybersecurity Consultant
Fidelity
This job is no longer accepting applications
See open jobs at Fidelity.See open jobs similar to "Principal Cybersecurity Consultant" Leadership Triangle.Job Description:
Position/Role Title
Principal, Cybersecurity Consultant
The Team
The Enterprise Cybersecurity (ECS) Regulatory & Audit team helps ECS and corporate partners manage firm-wide cybersecurity risk by providing key support services. As part of Cyber Regulatory & Audit, the ECS Internal Audit Engagement (IAE) team supports 25-30 internal audits annually. IAE seeks to reduce cyber risk through improved engagement and partnership with ECS Product Areas and Audit to ensure alignment, transparency, and efficiency throughout pre-audit, active audit, and post-audit efforts.
The Role
The ECS Internal Audit Engagement (IAE) team is seeking an experienced, passionate cybersecurity risk professional to support and partner with ECS Product Areas and Fidelity Corporate Audit. The role requires steadfast collaboration throughout the three phases of audit engagement: pre-audit (roadmap alignment, pre-audit control risk gap assessments, trend/theme analysis), active audit (risk quantification, drafting action plans, facilitating risk acceptances), and post-audit (action plan closure, reporting and metrics).
The Expertise and Skills You Bring
Technical Skills
- Demonstrated Risk Management and Mitigation experience
- Strong Risk, Process, Cyber Threat Analysis, and Control Gap Assessment skill
- Broad knowledge of cybersecurity threats and tactics
- In-depth understanding of NIST Cybersecurity Framework standards and practices, COBIT 5
- Knowledge of Operations & Technology (identity & access management; physical/personnel security; security ops assessments), Information Risk Management (vendor risk management; cloud computer security; data management), Software Development Life Cycle (SSDLC) and application security.
- Understanding of FAIR (Factor Analysis of Information Risk) cyber risk framework
- Familiarity with ECS Policies, Standards, and Technical Implementation Guides (TIGs)
- Familiarity with Archer GRC, Jira, and ServiceNOW
General Business Skills
- Experience working as corporate/internal auditor or working with corporate audit function
- Experience working within a Cyber Security organization
- Analyst mindset to deep dive into audit findings to understand and communicate risks and appropriate responses
- Strong communication skills (written, verbal, presentation) with technical expertise to influence others and drive outcomes
- Highly motivated, self-directed, independent thinker with strong attention to detail.
Responsibilities
- Partner w/ ECS teams to identify ECS control gaps
- Partner w/ Audit and ECS teams to confirm reported audit issues and perform FAIR quantitative risk assessments
- Partner with ECS Product Areas on drafting responses (Action Plans) to address valid audit observations
- Track ECS Product Areas progress toward on-time completion of action plans
- Identify opportunities to improve team processes to better support ECS Product Areas
- Manage ECS Risk Acceptances
- Maintain and leverage key metrics that support various reports and critical meetings
- Partner w/ ECS Product Areas to gain in-depth understanding of roadmaps, backlogs, etc.
Education and Experience
- Bachelor’s degree in technology, computer science, or engineering strongly preferred
- 7+ years experience in cybersecurity risk management, technology operations, system analysis, and/or project management
- Certification a plus: CISSP (Information Systems Security Professional), CEH (Certified Ethical Hacker), CISA (Certified Information Systems Auditor)
The base salary range for this position is $85,000-$179,000 per year.
Placement in the range will vary based on job responsibilities and scope, geographic location, candidate’s relevant experience, and other factors.
Base salary is only part of the total compensation package. Depending on the position and eligibility requirements, the offer package may also include bonus or other variable compensation.
We offer a wide range of benefits to meet your evolving needs and help you live your best life at work and at home. These benefits include comprehensive health care coverage and emotional well-being support, market-leading retirement, generous paid time off and parental leave, charitable giving employee match program, and educational assistance including student loan repayment, tuition reimbursement, and learning resources to develop your career. Note, the application window closes when the position is filled or unposted.
Certifications:
This job is no longer accepting applications
See open jobs at Fidelity.See open jobs similar to "Principal Cybersecurity Consultant" Leadership Triangle.