hero

Explore thousands of opportunities across Tech:NYC’s member network.

674
companies
10,810
Jobs

Security Consultant-Risk & Compliance

IBM

IBM

IT, Legal
Posted on Jan 30, 2025
Introduction

Information and Data are some of the most important organizational assets in today’s businesses. As a Security Consultant, you will be a key advisor for IBM’s clients, analyzing business requirements to design and implement the best security solutions for their needs. You will apply your technical skills to find the balance between enabling and securing the client’s organization with the cognitive solutions that are making IBM the fastest growing enterprise security business in the world.

In this role, you'll work in one of our IBM Consulting Client Innovation Centers (Delivery Centers), where we deliver deep technical and industry expertise to a wide range of public and private sector clients around the world. Our delivery centers offer our clients locally based skills and technical expertise to drive innovation and adoption of new technology.

Your role and responsibilities

As a Security Expert you will support multiple projects to ensure compliance with Security & Privacy regulations. Among the responsibilities for the role are the following:
• Engage with projects as a “perform resource” for project duration
• Work with PM to attend Risk Assessments
• Review and understand project scope to identify client and regulatory requirements
• Identify, design and implement foundational, client, and regulatory controls by developing detailed processes and procedures based on most current Data Security & Privacy framework requirements
• Document and maintain a Risk / Incident Management Log and ensure project leadership review
• Work with project team to effectively execute controls per timing in Framework
• Perform continuous monitoring for compliance
• Drive any gap remediation activities
• Coordinate execution of end-of-project security activities

Required education
Bachelor's Degree
Preferred education
Bachelor's Degree
Required technical and professional expertise
  • Familiarity with one or more project management methodologies – mandatory
  • Awareness or experience of various industry standard methodology (ISO27001, NIST, COBIT, etc)
  • Capable of delivering work that meets/performs to functional requirements based on business requirements defined and approved by the client
  • Strong Communication Skills (English) – mandatory

Preferred technical and professional experience
  • Exposure to full life-cycle experience in large projects
  • IT General Control, Data Privacy work, ISO27001, SOX, InfoSec Frameworks and regulations; IT Risk and audit experience
  • Preferred CISSP, CISA, CDPSE, CRISC, or PCI SQA Certified