Lead Security Solutions Consultant - Cyber Risk and Strategy

Posted Yesterday
Be an Early Applicant
Hiring Remotely in United States
Remote
137K-172K Annually
Expert/Leader
Cloud • Information Technology • Productivity • Security • Software
The Role
Leads complex cybersecurity Governance, Risk, and Compliance workstreams from discovery through delivery. Responsibilities include risk and control assessments, compliance readiness, policy governance, third-party risk, workshops, executive communications, client deliverables, roadmaps, and program design. The role serves as a trusted client advisor, coaches consultants, supports proposals and solution shaping, develops reusable practice assets, and manages scope, quality, risks, dependencies, and stakeholder expectations.
Summary Generated by Built In
Job Summary & Responsibilities

Qualifications:

Required

  • 7–12 years of experience in cybersecurity, IT risk, compliance, or security advisory with a clear focus on GRC; must include significant hands-on experience across at least three GRC domains and demonstrated ownership of client-facing workstreams
  • Advanced hands-on experience across GRC domains and platforms, including multiple areas such as:
    • Risk Management — enterprise and IT risk assessments, risk methodology design, risk register governance, risk appetite and tolerance, qualitative or FAIR-based quantification, treatment planning, KRI design, and executive risk reporting
    • Compliance Program Management — complex regulatory and framework gap assessments, controls mapping, audit and certification readiness, evidence and remediation governance, and sustainable compliance operating models across frameworks such as SOC 2, ISO 27001, FedRAMP, HIPAA, PCI DSS, DORA, or SOX ITGC
    • Policy & Control Governance — enterprise policy and standards development, control framework design and rationalization, control testing methodology, exception governance, control ownership models, and integration of NIST, CIS, ISO, or similar frameworks
    • Third-Party & Vendor Risk — program design, vendor segmentation and tiering, inherent and residual risk methods, assessment and contractual control review, issue remediation, ongoing monitoring, and governance reporting
    • GRC Platforms — ServiceNow GRC, Archer, OneTrust, Vanta, Drata, or equivalent: experience translating process requirements into workflows, data models, reporting, dashboards, assessment structures, or platform-enabled operating processes
  • Strong working knowledge of GRC and security frameworks: NIST CSF 2.0, NIST SP 800-53, NIST RMF, ISO 27001/27002, CIS Controls v8, SOC 2 Trust Services Criteria, COBIT, PCI DSS v4, HIPAA Security Rule, SOX ITGC, FedRAMP, and DORA
  • Advanced understanding of core GRC concepts: risk appetite and tolerance, control design and operating effectiveness, three lines of defense, audit lifecycle, regulatory change management, data privacy principles, governance operating models, and risk-based prioritization

Demonstrated consulting leadership competencies, including:

  • Structured discovery: ability to design and lead current-state discovery across multiple stakeholder groups, identify information gaps, challenge assumptions constructively, and synthesize complex evidence into a coherent view of risk and program maturity
  • Gap analysis: experience leading maturity and control assessments, calibrating findings, determining root causes, prioritizing gaps by risk and business impact, and converting analysis into practical recommendations and roadmaps
  • Executive and technical communication: ability to translate complex risk and compliance topics into clear written deliverables, presentations, and verbal recommendations for technical teams, business stakeholders, project sponsors, and senior leaders
  • Workshop facilitation: ability to independently plan and facilitate discovery sessions, risk workshops, prioritization discussions, and working groups; manage differing viewpoints and guide stakeholders toward decisions and next steps
  • Deliverable leadership: consistent track record of owning high-quality client deliverables from analysis through final presentation, including quality review of team outputs and accountability for consistency, clarity, and defensibility
  • Engagement leadership: direct day-to-day workstream execution, coordinate team activities, manage dependencies and delivery risks, mentor junior staff, and partner effectively with the engagement lead to maintain scope, quality, and client confidence

Preferred

  • Bachelor’s degree in Information Security, Risk Management, Business, or a related field
  • Industry certifications demonstrating advanced GRC or security knowledge: CISSP, CISM, CISA, CRISC, CGEIT, GRCP, or equivalent; platform certifications from ServiceNow, OneTrust, or Archer are a strong plus
  • Experience leading GRC work in complex enterprise environments across financial services, healthcare, retail, manufacturing, or public sector, particularly where compliance intersects with significant regulatory scrutiny
  • Substantial consulting experience at a professional services firm, systems integrator, audit/advisory firm, or equivalent client-facing role, including responsibility for workstream leadership and client presentations
  • Experience supporting pre-sales and solution shaping, including discovery, SOW development, effort estimation, staffing models, proposal creation, and transition from pursuit to delivery

Key Competencies

  • Broad GRC domain depth and independent workstream leadership
  • Client advisory judgment, delivery quality, and accountability for outcomes
  • Strong executive and technical communication, written and verbal
  • Team leadership, coaching, collaboration, and commercial awareness

Success in this role means independently leading complex GRC workstreams from discovery through recommendation, earning trusted-advisor credibility with client stakeholders, consistently delivering high-quality outcomes through both individual contribution and team leadership, strengthening the practice through coaching and reusable intellectual capital, and demonstrating the delivery, client, and commercial judgment required to progress toward a Principal or Senior Manager role.

Want to learn more about Consulting & Security Services? Check us out on our platform:

https://www.wwt.com/consulting-services

https://www.wwt.com/category/security-transformation

Certain states and localities require employers to post a reasonable estimate of salary range. A reasonable estimate of the current base pay range for this position is $137,200 to $171,500 annually. Actual salary will be based on a variety of factors, including shift, location, experience, skill set, performance, licensure and certification, and business needs. The range for this position in other geographic locations may differ. Certain positions may also be eligible for variable incentive compensation, such as bonuses or commissions, that is not included in the base pay. 

The well-being of WWT employees is essential. When it comes to our benefits package, WWT has one of the best. We offer the following benefits to all full-time employees:

  • Health and Wellbeing: Health (Medical & Prescription), Dental, and Vision Care, Onsite Health Centers (MO & IL), Employee Assistance Program, Wellness program
  • Financial Benefits: Competitive Pay, Profit Sharing, 401k Plan with Company Matching, Life and Disability Insurance, Flexible Spending Accounts, Tuition Reimbursement
  • Paid Time Off: PTO & Holidays, Parental Leave, Medical Leave, Military Leave, Bereavement, Day of Caring
  • Additional Perks: Family Planning Benefits, Nursing Mothers Benefits, Voluntary Legal, Voluntary Supplemental Accident/Illness/Hospital, Voluntary ID Theft, Pet Insurance, Employee Discount Program

Note: This is not an all-encompassing list and should not be used as a complete description of the plan’s benefits. For more information, see our US benefits website at wwt.com/us-benefits.We strive to create an environment where all employees are empowered to succeed based on their skills, performance, and dedication. Our goal is to cultivate a culture of belonging that encourages innovation, collaboration, and respect for all team members, ensuring that WWT
remains a great place to work for all!

If you require accessibility accommodation(s) or adjustment during any stage of the hiring process, please let your WWT Recruiter know. The recruiter will work with you to understand your needs and help ensure an accessible experience throughout the interview process.

World Wide Technology is an Equal Opportunity Employer.

If you have any questions or concerns about this posting, please email [email protected].

 

 

 

#LI-TB1

Preferred Qualifications

Why WWT? 

World Wide Technology (WWT) strives to make a new world happen. WWT's work benefits clients and partners as much as it does its people and community across the globe.

Founded in 1990, WWT brings together strategy, deep technical expertise and world-class partnerships to help public and private sector organizations design, build and scale intelligent AI, digital, cybersecurity, cloud and infrastructure solutions. Through its Advanced Technology Center (ATC)—a collaborative ecosystem featuring state-of-the-art hardware and software—WWT enables clients and partners to conceptualize, test and validate innovative technology and then deploy solutions at scale using its global integration and distributions capabilities.

With more than 14,000 team members and over 60 locations globally, WWT's culture—grounded in core values and leadership philosophies—has been recognized by Fortune® and Great Place to Work for its commitment to innovation, trust and creating a great place to work for all. WWT provides products and services to large enterprise, global service provider and public sector clients in up to 130 countries across six continents. Softchoice, a World Wide Technology company, supports commercial and SMB markets in the U.S. and Canada.

Want to work with highly motivated individuals on high-performance teams? Join WWT today!

What is the Solutions Consulting & Engineering (SC&E) Team and why join?

Solutions Consulting & Engineering is an organization that is Customer Focused and Solutions Led. We deliver end-to-end and emerging solutions to drive customer satisfaction, increase profitability and growth. Our success is enabled by our world-class management consulting, delivery excellence and engineering brilliance. Our goal is to bring together business acumen with full-stack technical know-how to develop innovative solutions for our clients' most complex challenges.

Position Overview:

The Lead Cyber Risk and Strategy Consultant is a senior individual contributor who owns complete delivery workstreams within WWT’s Governance, Risk, Strategy and Compliance practice. Positioned above the Senior Consultant, the Lead Consultant brings broad GRC domain depth, independently drives complex client work, and serves as a trusted advisor to client stakeholders while guiding the delivery team toward high-quality outcomes.

The Lead Consultant is accountable for translating client objectives into structured delivery plans, leading assessments and workshops, shaping practical recommendations and roadmaps, and ensuring workstream outputs meet WWT’s professional services standards. They work in partnership with Principals and Senior Managers, provide day-to-day direction and coaching to Senior Consultants and Consultants, and contribute meaningfully to pursuits, solution shaping, and practice development.

Essential Functions:

Engagement Delivery

  • Own end-to-end delivery of defined GRC workstreams, with accountability for scope, approach, quality, schedule, risks, dependencies, and client outcomes
  • Lead complex GRC assessments: design and conduct current-state discovery, direct control environment reviews, validate findings, calibrate maturity scoring, and ensure conclusions are supported by evidence and business context
  • Lead hands-on GRC program work across risk management, control and policy governance, compliance readiness, third-party risk, and related domains; determine the appropriate analysis approach and guide team execution
  • Own client-ready deliverables — assessment reports, risk registers, control gap registers, maturity scorecards, prioritized roadmaps, program designs, and executive summaries — and perform quality review of team outputs before client delivery
  • Plan and independently facilitate discovery sessions, stakeholder interviews, risk workshops, and working sessions; synthesize complex inputs into clear decisions, findings, and actionable recommendations
  • Lead strategy and program design activities: translate current-state findings into prioritized future-state recommendations, operating model improvements, governance structures, implementation roadmaps, and measurable program outcomes

Client Engagement

  • Build trusted relationships with client security, risk, compliance, audit, and technology leaders; serve as the primary day-to-day advisory contact for assigned workstreams and establish credibility through sound judgment and dependable delivery
  • Present findings, recommendations, and tradeoffs to project sponsors and working-group leadership; adapt communication for technical, operational, and executive audiences and confidently navigate challenge or ambiguity
  • Lead workstream status reporting, issue and risk management, meeting facilitation, decision tracking, and expectation management; escalate material delivery risks to the engagement lead with clear options and recommendations

Pursuit & Practice Support

  • Contribute materially to pre-sales and pursuit activities: lead discovery inputs, shape solution approaches, define workstream scope and deliverables, estimate level of effort, identify staffing needs, and develop proposal and SOW content in partnership with Principals and Senior Managers
  • Advance practice development by creating, improving, and governing reusable delivery assets, assessment methodologies, control libraries, accelerators, templates, and point-of-view content that increase consistency and scalability
  • Apply commercial awareness to delivery decisions: understand engagement economics, utilization, scope boundaries, staffing leverage, and change-control considerations; identify follow-on opportunities that naturally emerge from client needs without compromising advisory objectivity

Growth & Development

  • Maintain and expand advanced knowledge across GRC domains, regulatory frameworks, emerging risk topics, and relevant platforms through client work, certifications, research, and active participation in the practice
  • Seek and apply feedback from Principals and Senior Managers while demonstrating readiness for greater engagement leadership, broader client advisory responsibility, and increased contribution to solution development
  • Coach Senior Consultants and Consultants on analysis, facilitation, deliverable development, client communication, and WWT delivery standards; provide actionable review feedback and help raise overall team quality

Skills Required

  • 7-12 years of experience in cybersecurity, IT risk, compliance, or security advisory, with a clear GRC focus
  • Significant hands-on experience across at least three GRC domains
  • Ownership of client-facing workstreams
  • Advanced hands-on experience in risk management, compliance program management, policy and control governance, third-party and vendor risk, and GRC platforms
  • Strong working knowledge of GRC and security frameworks including NIST, ISO 27001, CIS Controls, SOC 2, COBIT, PCI DSS, HIPAA, SOX ITGC, FedRAMP, and DORA
  • Advanced understanding of risk appetite, control effectiveness, three lines of defense, audit lifecycle, regulatory change management, privacy principles, governance models, and risk prioritization
  • Ability to lead structured discovery, gap analysis, executive and technical communication, workshops, deliverables, and engagement execution
  • Bachelor's degree in Information Security, Risk Management, Business, or a related field
  • CISSP, CISM, CISA, CRISC, CGEIT, GRCP, equivalent, or relevant platform certifications
  • Experience leading GRC work in complex enterprise environments and regulated industries
  • Substantial consulting experience in a professional services, systems integration, audit/advisory, or equivalent client-facing role
  • Experience supporting pre-sales and solution shaping, including SOW development, estimation, staffing, proposals, and pursuit-to-delivery transition
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Chicago, IL

Similar Jobs

BAE Systems, Inc. Logo BAE Systems, Inc.

Manager, Legal Technology Solutions (Remote)

Aerospace • Hardware • Information Technology • Security • Software • Cybersecurity • Defense
Remote or Hybrid
El Paso, TX, USA
40000 Employees
122K-208K Annually

BAE Systems, Inc. Logo BAE Systems, Inc.

Senior Linux Administrator

Aerospace • Hardware • Information Technology • Security • Software • Cybersecurity • Defense
Remote or Hybrid
Mississippi, USA
40000 Employees
79K-135K Annually

Samsara Logo Samsara

Program Manager

Artificial Intelligence • Cloud • Computer Vision • Hardware • Internet of Things • Software
Easy Apply
Remote or Hybrid
Seattle, WA, USA
4000 Employees
116K-175K Annually

Samsara Logo Samsara

Operations Manager

Artificial Intelligence • Cloud • Computer Vision • Hardware • Internet of Things • Software
Easy Apply
Remote or Hybrid
United States
4000 Employees
126K-203K Annually

Similar Companies Hiring

Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees
Revel Thumbnail
Aerospace • Hardware • Robotics • Software
Marina Del Rey, California
70 Employees
Blee Thumbnail
Artificial Intelligence • Marketing Tech • Software
New York, New York
30 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account