Cyber Security Consultant
Houston, TX
Contract
Overview:
The cybersecurity assurance and compliance role provides independent measurement and reporting of the organization''s cybersecurity compliance in alignment with corporate cybersecurity policies and standards, as well as with external regulations and compliance frameworks. The goal is to ensure the implementation, operations, and effective delivery of cybersecurity controls to meet policy and operational expectations. The role coordinates with the cybersecurity architect to ensure all IT and OT assets, services, and operations are compliant with internal policies, and with external regulators to ensure compliance with legal and contractual obligations. The role is responsible for performing continuous assessment, capturing gaps and communicating them to the risk team, who will log them in to the risk register and track them to closure.
Duties may include but are not limited to the following:
Compliance Monitoring and Management
- Coordinate with external regulatory bodies and industry groups to capture requirements that ensure adherence to regulatory requirements
- Coordinate with the cybersecurity architecture role to capture requirements and ensure adherence to internal policies and standards
- Coordinate with Legal and Procurement teams to capture contractual requirements we have committed to others
- Coordinate with Legal and Procurement teams to capture contractual requirements others have committed to us
- Manage regulatory mappings for all geographies of business operations to understand which regulations are applicable, including when and where
- Establish and maintain a compliance and assessment program aligned to the company''s selected frameworks and methodologies
- Manage and maintain a periodic assurance testing cycle based upon business criticality, regulatory exposure, and business risk.
- Develop and maintain evidence requirements and quality standards needed to prove cybersecurity compliance and assurance
- Develop, implement, maintain, and operate processes to collect evidence, assess evidence, and report on cybersecurity compliance and control effectiveness
- Coordinate with stakeholders to report compliance and effectiveness gaps, and follow-up through closure to ensure active progress on addressing gaps
- Manage and maintain a register of assurance findings, coordinating with business stakeholders to identify and complete corrective actions and plans
- Independently validate remediation of all findings prior to formal closure.
Audit Preparation and Management:
- Prepare and execute internal and external audits
- Provide evidence governance for audits, regulators, customers, and contractual attestations.
- Coordinate internal/eternal audit remediation tracking.
Risk Coordination:
- Coordinate with cybersecurity risk function to ensure any assurance/compliance gaps are captured as cybersecurity risks where relevant
Training and Awareness:
- Develop and/or procure training and awareness material regarding internal and external cybersecurity compliance
- Conduct training sessions to promote compliance awareness within the organization.
- Identify key areas to test and report on compliance and awareness
Control Assurance and Testing for Transformation / Major Changes
- Act as a focal point on major IT and OT projects where high assurance is required per policies and standards, to define assurance controls and criteria to be implemented by the project
- Design, implement, and execute assurance control testing and validation programs
- Identify external assessment needs, such as penetration testing, red team testing, and establish contracts, services, and relationships as needed to have such tests conducted, integrating results as part of the overall assurance and assessment program.
Requirements
- BS or MA in computer science, information security, cybersecurity or a related field
- Strong knowledge of cyber security framework and controls
- Audit & Testing
- Regulatory & Compliance knowledge
- Risk assessment
Vendor assurance
Minimum Experience:
- 7+ years It audit, cybersecurity assurance, or other compliance roles
- Experience with regulatory environments
- Control testing and audit execution
- Working with external auditors and regulators
Diverse Lynx LLC is an Equal Employment Opportunity employer. All qualified applicants will receive due consideration for employment without any discrimination. All applicants will be evaluated solely on the basis of their ability, competence and their proven capability to perform the functions outlined in the corresponding role. We promote and support a diverse workforce across all levels in the company.