Find your next role
Strengthen your profile
Dale WorkForce Solutions
Staffing & Recruiting
See how your profile stacks up against this role.
We compared the job requirements to your profile to show where you're strong and where you fall short.
Job Description:
We are seeking an experienced Cyber & Information Security Risk & Controls Specialist with proven project management capabilities to join our team. In this role, you will lead the risk evaluation, control design, assessment, and remediation activities across 2 to 3 active cyber workstreams.
Supported by dedicated internal teams and subject matter experts, you will ensure our security controls align with industry standards, regulatory mandates, and enterprise risk appetite. You will oversee delivery milestones, coordinate cross-functional workstream activities, and establish clear operational transition processes.
Key Responsibilities
Risk & Controls Management
• Control Assessment & Design: Evaluate existing technical and operational security controls against industry frameworks (such as NIST CSF, ISO 27001, CIS Controls, SOC 2). Identify gaps and design robust, measurable controls.
• Risk Identification & Mitigation: Lead risk assessments across core systems, applications, and processes. Collaborate with control owners to formulate effective remediation and risk treatment plans.
• Governance & Compliance Alignment: Ensure control activities align with firm-wide information security policies, regulatory requirements, and audit expectations.
• Testing & Readiness: Coordinate control testing, review evidence documentation, and prepare workstreams for internal and external cyber audits.
Project Management & Workstream Oversight
• Multi-Workstream Execution: Manage planning, execution, and delivery across 2–3 concurrent cyber and information security workstreams.
• Roadmap & Milestone Tracking: Maintain comprehensive project plans, schedules, action items, and risk/issue logs (RAID).
• Cross-Functional Collaboration: Partner closely with internal cybersecurity architects, IT engineering, compliance teams, and external vendor partners.
• Status Reporting & Metrics: Develop management dashboards, Key Risk Indicators (KRIs), and executive status updates highlighting progress, blockers, and residual risks.
• Act with integrity, professionalism, and personal responsibility to uphold the firm's respectful and courteous work environment.
Operational Enablement & Transition
• Process Documentation: Author standard operating procedures (SOPs), process workflows, control baseline definitions, and operational FAQ guides.
• Knowledge Transfer: Facilitate structured knowledge transition and hand-off to downstream operational and support teams.
• Continuous Improvement: Identify opportunities to automate control testing and streamline repetitive governance workflows.
Qualifications
Required Experience & Education
• Education: Bachelor's degree in Cybersecurity, Information Systems, Computer Science, Business Administration, or related field (or equivalent practical experience).
• Experience: 5+ years of direct experience in information security, IT risk management, cyber compliance, or IT audit.
• Risk & Controls Acumen: In-depth knowledge of cybersecurity risk frameworks, internal controls assessment, threat/vulnerability management concepts, and audit readiness.
• Project Delivery: Demonstrated track record successfully managing complex security or technology initiatives involving multiple stakeholders and workstreams.
Preferred Qualifications & Certifications (not required)
Professional certifications in security, risk, or audit:
• Certified Information Systems Auditor (CISA)
• Certified Information Security Manager (CISM)
• Certified in Risk and Information Systems Control (CRISC)
• Certified Information Systems Security Professional (CISSP)
Project management certification:
• Project Management Professional (PMP), PMI-ACP, or Agile/Scrum certification
• Experience working within enterprise environments or professional services networks.
Core Competencies
• Analytical Thinking: Ability to synthesize complex technical risks into clear, actionable business impacts.
• Stakeholder Management: Exceptional communication skills with the ability to influence technical and non-technical stakeholders across varying seniority levels.
• Agility & Organization: Strong organizational and prioritization capabilities, comfortably shifting between high-level project coordination and deep-dive control reviews.
• Collaborative Leadership: Proven ability to build consensus, partner effectively with internal support teams, and drive shared accountability.
After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.
Marcus Rivera
Chief Revenue Officer

Trinity Health Mid-Atlantic

Tompkins Insurance

TD Bank

Broadridge

Crypto.com

Dale WorkForce Solutions

Dale WorkForce Solutions

Dale WorkForce Solutions