- Company Name
- Focus Group
- Job Title
- Security and Governance Consultant
- Job Description
-
Job Title: Security and Governance Consultant
Role Summary:
Senior consultant responsible for leading security transformation, governance, and incident response across multiple enterprise clients. The role balances strategic advisory as a virtual CISO with hands‑off Security Manager duties for a flagship client, delivering comprehensive security roadmaps, risk frameworks, and compliance programs.
Expectations:
- Drive measurable security improvements through strategic planning and tactical execution.
- Communicate complex security concepts to C‑suite, board, and technical teams.
- Manage client portfolios and maintain high customer satisfaction.
- Lead incident response and forensic investigations, ensuring timely executive reporting.
Key Responsibilities:
- Serve as dedicated Security Manager for a primary client (50 % of time): define and enforce information security requirements, coordinate with client security partner, lead incident response, and produce monthly executive security reports.
- Provide Fractional CISO services (50 % of time): conduct security strategy assessments, develop roadmaps, build governance frameworks (ISO 27001, NIST, SOC 2, CE+), and advise on digital transformation security initiatives.
- Develop and maintain risk management and compliance programs, including PCI DSS and industry‑specific regulations.
- Integrate and optimize security tooling (SIEM/SOC), managed security services, and cloud security architecture for Azure and Microsoft 365.
- Mentor and guide internal security teams, fostering continuous improvement and cultural change.
Required Skills:
- Expertise in security governance frameworks (ISO 27001, SOC 2, CE+, NIST).
- Advanced cloud security knowledge (Azure, Microsoft 365).
- Proven incident response leadership and forensic investigation experience.
- Strong risk management and compliance program development.
- Executive‑level communication, presentation, and stakeholder management.
- Strategic thinking, analytical problem‑solving, and client‑relationship building.
- Leadership experience in mentoring teams and driving organizational security change.
Required Education & Certifications:
- Bachelor’s degree in Computer Science, Information Security, or related field (or equivalent experience).
- Senior security certification: CISSP, CISM, or comparable (e.g., CRISC, ISO 27001 Lead Implementer).
- Additional certifications in cloud security or incident response (e.g., Azure Security Engineer, GCIH) preferred.