Security advisory consultant
Summary
Advises clients on cybersecurity risks, conducts assessments, and translates findings into business-aligned recommendations using frameworks like NIST and ISO 27001.
Security Advisory Specialist orConsultant
A Security Risk Advisory Specialist orConsultant is responsible for identifying, assessing and mitigating securityrisks to help clients to protect their organization’s assets, people andinformation.
Key Responsibilities:
Client Advisory and Service Delivery
· Act as a trusted advisor toclients, understanding their business objectives and aligning securitystrategies
· Lead monthly or quarterlysecurity risk reviews
· Translate complex securityfindings into clear, actionable recommendations relevant to client’s businesscontext
· Ensure timely delivery of allcontractual security advisory deliverables
Security Assessment and Monitoring
· Conduct comprehensivecybersecurity assessment to provide the client’s current security posture basedon available data or information
· Collaborate with SOC teams toanalyze security events and incidents identified through Lumen platforms
· Generate executive levelreporting that demonstrates the value of our service
Service Improvement
· Contribute to the continuousimprovement of service offerings and delivery process
· Develop standardized templatesand methodologies for security reviews
· Stay current on emergingcybersecurity threats, technologies and compliance requirements
· Support client onboarding andensure smooth transition to operational teams
Technical Leadership
· Provide expert guidance on cybersecuritytechnologies selection and implementation
· Help align security programswith industry frameworks (NIST, ISO27001, CIS)
· Assist with securityarchitecture reviews and improvement recommendations
· Support security incidentresponse when significant events occur
Required Qualifications:
Experience
· 5+ years of cybersecurityexperience with at least 2 years in a consultative or advisory role
· Experience in an MSSP orsecurity service delivery environment
· Demonstrated ability totranslate technical security concepts into business value
Skills
· Strong technical knowledge ofsecurity frameworks, risk management tools, and compliance regulations
· Excellence in client facingcommunication and executive presentation
· Analytical skills to assesscomplex security data and develop actionable insights
· Project management capabilitiesto manage multiple client engagements simultaneously
· Service delivery mindset withfocus on client satisfaction and value demonstration
Certifications
· Required: One or more of CISSP,CISM, CRISC
· Desired: ISO 27001, cloudsecurity (CCSP/AWS/Azure/GCP security), ITIL.