Cyber Security
Contract W2
6 Months
No Travel Required
On-site
$75 - $95/hr


Technical Link
Fitment
Dice Job Match Score™
🤯 Applying directly to the forehead...
Job Details
Skills
- Cybersecurity Governance
- Risk Management
- Compliance Program Management
- GRC (Governance Risk Compliance)
- Information Security Compliance
- IT Compliance
- SOC 2 Type I and Type II
- ISO 27001 Implementation
- NIST 800-53
- NIST 800-171
- CIS Controls v8
- CMMC Compliance
- FedRAMP
Summary
Cybersecurity Governance, Risk & Compliance Consultant
Location: San Jose, CA
Duration: 6-month contract
Work Setup: Onsite 5 days/week
Employment Type: W-2 only
Duration: 6-month contract
Work Setup: Onsite 5 days/week
Employment Type: W-2 only
Job Description
Governance & Compliance Leadership:
- Develop and manage the overarching Compliance Program to ensure alignment with industry standards, including SOC 2, NIST 800-171, ISO 27001, and NIST 800-53.
- Partner with IT Security Operations to ensure security controls are properly designed, implemented, and operating effectively.
- Lead the end-to-end cybersecurity audit process, both internal and external, including preparation, response coordination, and execution of remediation plans.
- Develop and distribute high-level information security reports and compliance dashboards to key stakeholders.
Risk Management & Assessment:
- Lead comprehensive cybersecurity risk assessments across the enterprise, identifying vulnerabilities and recommending prioritized mitigation strategies.
- Develop and maintain the Corporate Risk Register, tracking risk acceptance, treatment plans, and residual risk.
- Perform quantitative and qualitative risk analysis to inform executive decision-making and resource allocation.
Identity & Access Governance:
- Oversee and collaborate with stakeholders to execute quarterly user access reviews and monthly user activity monitoring.
- Ensure timely completion, technical accuracy, and rigorous documentation of all access reviews to meet audit requirements.
- Analyze access trends and over-privileged accounts to recommend least privilege improvements and role-based access control refinements.
Third-Party Risk Management:
- Own and maintain third-party risk management evaluation practices.
- Ensure vendors are vetted against corporate security standards to mitigate supply-chain risk.
Policy & Process Engineering:
- Author, maintain, and update information security policies and Standard Operating Procedures to ensure alignment with evolving industry standards.
- Manage and govern change management processes to ensure security stability and compliance during technical transitions.
Requirements
- Minimum 10 years of experience managing cybersecurity compliance programs from inception to completion.
- Hands-on experience with SOC 2 and a deep understanding of IT technical security controls.
- Expert knowledge of industry-standard programs and frameworks, including ISO 27001, CIS v8.1, NIST 800-53, NIST 800-171, CMMC, and FedRAMP.
- Strong analytical thinking with the ability to prioritize complex tasks within a fast-paced, evolving environment.
- Excellent interpersonal, verbal, and written communication skills, with the ability to work effectively as a team player or independently.
- Strong foundation in IT security concepts, with heavy emphasis on security risk assessment.
- Relevant professional certifications such as CRISC, CISM, or CISA preferred.
- Ability to tailor complex technical communication for both technical audiences and non-technical executive leadership.
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
- Dice Id: 10308440
- Position Id: 9006721
- Posted 14 hours ago
Company Info
About Technical Link
Technical-Link North America is dedicated to excellence in engineering staffing, connecting top talent with leading companies. Whether you're an employer seeking skilled engineers or an engineer looking for your next contract opportunity, we have the expertise and resources to meet your needs.
Create job alert
Similar Jobs
It looks like there aren't any Similar Jobs for this job yet.
Search all similar jobs