JOB DESCRIPTION/MINIMUM REQUIREMENTS:
ROLE SUMMARY:
This role will establish and operationalize enterprise governance and compliance workflows for cybersecurity and technology risk management. The contractor will design and document an audit-ready enterprise risk register framework, define risk scoring and prioritization methods, and implement governance processes to intake, validate, accept/mitigate/transfer, and monitor risks across stakeholders.
KEY RESPONSIBILITIES / DELIVERABLES:
Define end-to-end governance workflows for risk identification/intake, review/validation, acceptance/mitigation/transfer, and ongoing monitoring/reassessment.
Establish roles and responsibilities for risk owners, reviewers, and governance bodies.
Design escalation and reporting processes for high-risk items and accepted risks.
Facilitate stakeholder working sessions/workshops across business, technology, security, and governance to validate requirements and socialize processes.
Support onboarding and initial population of risks into the enterprise risk register.
Produce clear, audit-ready documentation, including risk register structure/data definitions, scoring methodology, and governance workflows/decision authorities.
Provide knowledge transfer to designated security staff to support sustainability beyond the contract term.
Planned deliverables include:
- Enterprise Risk Register Framework (standardized template and taxonomy)
- Risk Scoring and Prioritization Model (likelihood/impact scales; scoring and prioritization logic)
- Risk Governance Model (workflows for intake, review, acceptance, monitoring; roles/responsibilities matrix)
- Initial Population of Risk Register (documented risks reflecting current cybersecurity and technology risk posture)
- Final Documentation Package (consolidated guidance and operating procedures for ongoing risk management)
MINIMUM REQUIREMENTS (Candidates must meet/exceed):
Years | Required/Preferred | Skills/Experience |
8 | Required | Experience with Risk Register Design and Framework |
8 | Required | Experience with Risk Scoring and Prioritization Model |
8 | Required | Experience with Governance Processes and Workflows |
8 | Required | Experience with Stakeholder and Enablement |
8 | Required | Demonstrated skill with documentation and knowledge transfer |