
Information Risk Consultant
Posted Jul 25

Posted Jul 25
This is a fully remote position, open to applicants in Louisiana, +4 more states.
• Perform Information Risk Assessments as assigned to the team.
• Solicit and evaluate documentation needed to conduct a thorough assessment and carry out necessary interviews to gather and review relevant materials essential for producing the assessment results.
• Document and communicate the results of the risk assessment clearly and concisely with requestors, security architects, and management as required.
• Develop and apply appropriate risk scoring related to threat, vulnerability, likelihood, impact, security controls/counter-measures, and more.
• Understand and contribute to the inventory of the risk register, including tracking, scoring, and associated risk statements.
• Execute follow-up activities concerning exceptions, risk acceptance, corrective action plans, and additional mitigation efforts.
• Communicate risk treatment methodologies, including risk avoidance, risk acceptance, risk transference, and risk mitigation to relevant groups.
• Collaborate with various projects and initiatives to implement security architecture requirements, create architectural solutions, integrate security into solution designs, assess risks associated with security gaps, and develop remediation strategies.
• Bachelor's Degree in Information Security, Information Systems, Information Assurance, Computer Science, or a related field.
• A minimum of 7 years of experience in Information Security, Governance, Risk, and/or Compliance.
• At least 3 - 5 years of experience in Information Security and/or Information Risk Management and/or Information Technology.
• 1 - 3 years of experience in Information Security Governance, Risk, and/or Compliance functions and activities.
• Familiarity with technologies such as Intrusion Prevention Systems (IPS), firewalls, endpoint protection, web/email filtering, Data Loss Prevention (DLP), digital rights management, encryption, Security Event and Incident Management (SEIM), and virtualization platforms.
• Knowledge of HITRUST CSF, NIST 800-83 cybersecurity framework, PCI, HIPAA, HITECH, COBIT, ISO 27001/2, and ITIL 3.
• Understanding of secure SDLC best practices.
• Strong teamwork and interpersonal skills.
• Health insurance
• 401(k) matching
• Paid time off
• Flexible work hours
• Professional development opportunities
Circana
Zero Hash
World Kinect
The Hartford
Get handpicked remote jobs straight to your inbox weekly.