IT Risk & Security Assessment Consultant
Job Description:
- Conduct security and risk assessments, providing practical recommendations for risk mitigation
- Ensure assessments align with industry standards (ISO, NIST, CIS, PCIDSS, SWIFT CSP, CSA CCM) and regulatory requirements (e.g., BSP circulars)
- Perform cybersecurity and IT maturity assessments
- Lead and participate in discovery workshops with consultants and business/IT stakeholders
- Present project updates to client teams and key stakeholders
- Facilitate security training and awareness sessions
Qualifications:
- 3+ years in IT with 23 years in security assessments (cloud, third-party, ISMS/NIST, SOC 2, RCSA, configuration, architecture, controls) mandatory
- Experience facilitating IT risk assessments, data privacy (PDPA, GDPR, DPA 2012), and security awareness/training
- 1+ year in consulting/advisory engagements (preferred)
- Strong knowledge in IT audits, maturity assessments, ISO 27001/2, NIST, CIS, PCI DSS, SWIFT CSP, and BSP regulations
- Familiar with cloud computing, storage, security, and virtualization best practices
- Skilled in communication, stakeholder engagement, technical writing, and reporting
- Strong time management and customer service orientation
- Preferably certified (CISSP, ISMS LA/LI, CISA, CRISC, PCI DSS, SWIFT, HITRUST, etc.)
G