Associate Director - Risk Advisory (Cybersecurity & Privacy) (NY)
New York, NY
Full Time Mid-level / Intermediate USD 142K - 278K
CrossCountry Consulting
Our commitment to our people has earned us numerous awards including Inc5000's Fastest Growing Companies and Glassdoor's Best Places to Work. Explore what our employees have to say about our unique culture by clicking here.
By joining our rapidly growing Risk Advisory practice you will serve as a trusted partner to our clients. You’ll bring your first-hand experience, unique perspectives, and functional knowledge to deliver tailored integrated solutions that solve today's challenges and set the foundation for future success. With support from experienced leaders and a dedicated coach, you will join a collaborative community that invites you to contribute beyond the scope of client delivery.
In this role, you will drive positive impacts through the design, build, execution, and assessment of risk programs across cyber, technology, and operational risk (non-financial risk) domains. You will be an integral part of our leadership team: driving the growth of our client base, leading client engagements, and continuously improving our capabilities. We are looking for self-starters who enjoy learning and staying current with industry trends and technologies, excel at team leadership and mentorship, and are eager to help our clients strategically solve complex risk challenges.
What You'll Do:
- Provide hands-on project leadership and apply specialized knowledge across a diverse range of engagements spanning:
- Cybersecurity Assessment & Strategy: Cyber maturity assessments and roadmaps; risk assessments; operating models; executive advisory
- Resilience: Incident Response, Business Continuity, and Disaster Recovery planning; tabletop exercise design and facilitation
- Third Party Risk Management: TPRM program assessments; TPRM program designs (processes, tooling); vendor risk assessments
- Data Security & Privacy: privacy program assessments; data protection plans and roadmaps; privacy and data security tool/technology implementation
- Regulatory Compliance: Regulatory mapping and horizon scanning; compliance readiness and remediation activities; exam and reporting support
- Reporting & Metrics: KPI and KRI development; automation and operations; dashboards and reporting; risk appetite analysis
- Apply specialized knowledge in particular non-financial risk domains, and broad acumen across facets of all domains including cybersecurity, technology, cloud, operational resiliency, data, third party, privacy, and product risk
- Lead the Risk Advisory practice, leveraging expertise in cyber, technology, and operational risk to expand our client base and team
- Oversee accounts and client relationships across various industries, including financial services and emerging growth companies
- Conduct research and analysis, leveraging data to derive valuable insights and actionable recommendations for clients
- Drive development of solutions and deliverables, combining technical depth with management consulting skills to influence and deliver results to business executives and technical professionals
- Serve as a coach and mentor to team members, fostering their professional growth and development
What You'll Bring:
- 9+ years prior experience in professional services (public accounting, advisory firm, or management consulting firm)
- Experience with the major cybersecurity, technology, and operational risk frameworks and standards such as NIST CSF, CRI Cybersecurity Profile, CSA Cloud Controls, ISO 27000 series, COBIT, and Basel Operational Risk Principles
- Experience delivering security solutions across major cloud service provider (AWS, Azure, GCP) platforms
- Knowledge of comprehensive risk management programs including governance, policy, architecture, processes, and controls
- Experience mentoring and developing junior team members and helping project teams resolve multifaceted issues
- Demonstrated desire for continued learning about new and emerging technologies and staying current with trends in cyber, technology, and operational risk management
Qualifications:
- Bachelor’s degree from an accredited university.
- Professional certification (CISA, CISM, CISSP, CIPT, CIPP, CIPM).
- Willingness to travel domestically up to 20%-30% (varies by client).
- Willingness to be on client site or in CrossCountry’s office as needed to meet client needs and deliver excellent work (CrossCountry is in a hybrid posture; clients vary).
For applicants located in New York, CrossCountry Consulting is required to include an estimate of the compensation range for this role. The following range takes into account a wide range of factors including but not limited to, skills, experience, education, licenses, certifications, business needs, and internal equity. An estimate of the current range is $142,500 - $278,000 per year + annual bonus + additional benefits.
Benefits SummaryThe CrossCountry total rewards package includes comprehensive healthcare options, including medical, dental, and vision coverage; flexible spending accounts; and a 401(k) with company matching. Additionally, employees can take advantage of generous parental and maternity leave policies, technology stipends, and wellness reimbursement programs, all designed to support both professional growth and personal well-being.
Equal Employment Opportunity (EEO)CrossCountry provides equal employment opportunities (EEO) to all employees and applicants for employment and believes that respect and fair treatment are critical to creating a productive, diverse, and inclusive workplace.
As an equal opportunity employer, CrossCountry is fully committed to comply with all federal, state, and local laws and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, pregnancy, genetics, sexual orientation, protected veteran status, gender identity or expression or any other characteristic protected by federal, state or local laws. This policy also complies with pay transparency and labor laws and applies to all terms and conditions of employment, including recruiting, hiring, placement, promotion, termination, layoff, recall, transfer, leaves of absence, compensation, and training.
Tags: Automation AWS Azure CIPP CISA CISM CISSP Cloud COBIT Compliance GCP Governance Incident response ISO 27000 NIST Privacy Risk assessment Risk management Strategy
Perks/benefits: Career development Equity / stock options Flexible spending account Health care Medical leave Parental leave Salary bonus Transparency Wellness
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.