Risk Management Consultant

Deloitte Williamsville, NY $72,900 - $134,300
Full Time Mid Level 3+ years Visa Sponsorship

Posted 1 week ago

Interested in this position?

Upload your resume and we'll match you with this and other relevant opportunities.

Upload Your Resume

About This Role

As an experienced Risk Management Consultant, you will collaborate with cross-functional client teams to identify, assess, and prioritize cyber risks. This role focuses on long-term, onsite client service delivery without extensive travel, contributing to the development and transformation of cyber programs.

Responsibilities

  • Collaborate with cross-functional client teams to Identify, assess, and prioritize risks
  • Maintain and refresh CIS' cyber risk register (e.g., risk owners, treatments, due dates)
  • Perform periodic risk and control assessments
  • Document and follow up upon risk treatment actions
  • Produce risk reporting for leadership
  • Communicate regularly with Engagement Managers (Directors), project team members, and representatives from various functional and / or technical teams

Requirements

  • 3+ Years Experience performing risk assessments (inherent/residual risk), documenting findings, and recommending mitigations
  • 3+ Years Familiarity with key cyber domains: identity and access management (IAM), vulnerability management, incident response, data protection, logging/monitoring
  • 3+ Years Strong written communication skills (clear risk narratives, executive-ready summaries) and stakeholder management
  • 3+ Years Experience in cybersecurity, technology risk, IT audit, GRC (governance, risk & compliance), or risk management
  • Bachelor's degree, preferably in Computer Science, Information Technology, Computer Engineering, or related IT discipline; or equivalent experience

Qualifications

  • Bachelor's degree, preferably in Computer Science, Information Technology, Computer Engineering, or related IT discipline; or equivalent experience
  • 3+ years of experience performing risk assessments, with familiarity in key cyber domains and strong written communication skills.

Nice to Have

  • Working knowledge of common control frameworks (e.g., NIST CSF, NIST 800-53, ISO 27001, CIS Controls) and how to map controls to risks
  • Familiarity with GRC tooling (e.g., ServiceNow GRC, OneTrust)
  • Relevant certifications (e.g., Security+, CISA, CISSP)

Skills

NIST 800-53 * ISO 27001 * NIST CSF * CIS Controls * ServiceNow GRC * OneTrust *

* Required skills

About Deloitte

A company transforming technology platforms, driving innovation, and transforming mission-critical operations for clients, especially in the Life Sciences sector.

Professional Services
View all jobs at Deloitte →