Cyber & Information Security Risk & Controls Specialist

Planet Group

New York (NY)

Remote

USD 176,000 - 182,000

Full time

2 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Planet Group is seeking an experienced Cyber & Information Security Risk & Controls Specialist to lead risk evaluation, control design, assessment, and remediation across multiple active workstreams. You will coordinate with security architects, IT engineering, and compliance teams to ensure controls meet industry standards and regulatory expectations.

The role requires strong project management, the ability to deliver milestones, and clear status reporting with KRIs and dashboards.

Qualifications

  • Bachelor's degree in cybersecurity, information systems, CS, or related field.
  • 5+ years of direct information security or IT risk experience.
  • Deep knowledge of cybersecurity risk frameworks, internal controls, threat/vulnerability management.
  • Proven project delivery across multiple stakeholders and workstreams.

Responsibilities

  • Control assessment and design against NIST CSF, ISO 27001, CIS Controls, SOC 2.
  • Lead risk assessments and remediation plans.
  • Ensure alignment with policies, regulatory requirements, and audit expectations.
  • Coordinate control testing and readiness for audits.
  • Develop dashboards and KRIs for management reporting.
  • Knowledge transfer and SOP/documentation for operations.

Skills

Risk management
Project management
Stakeholder management
Governance & compliance

Education

Bachelor's degree in Cybersecurity / Information Systems / CS / Business Admin

Job description

Location: ( Remote)
Pay Rate: $128.00-$132.00

Job Description

We are seeking an experienced Cyber & Information Security Risk & Controls Specialist with proven project management capabilities to join our team. In this role, you will lead the risk evaluation, control design, assessment, and remediation activities across 2 to 3 active cyber workstreams. Supported by dedicated internal teams and subject matter experts, you will ensure our security controls align with industry standards, regulatory mandates, and enterprise risk appetite. You will oversee delivery milestones, coordinate cross-functional workstream activities, and establish clear operational transition processes.

Responsibilities
Risk & Controls Management
  • Control Assessment & Design: Evaluate existing technical and operational security controls against industry frameworks (such as NIST CSF, ISO 27001, CIS Controls, SOC 2). Identify gaps and design robust, measurable controls.
  • Risk Identification & Mitigation: Lead risk assessments across core systems, applications, and processes. Collaborate with control owners to formulate effective remediation and risk treatment plans.
  • Governance & Compliance Alignment: Ensure control activities align with firm-wide information security policies, regulatory requirements, and audit expectations.
  • Testing & Readiness: Coordinate control testing, review evidence documentation, and prepare workstreams for internal and external cyber audits.
Project Management & Workstream Oversight
  • Multi-Workstream Execution: Manage planning, execution, and delivery across 2-3 concurrent cyber and information security workstreams.
  • Roadmap & Milestone Tracking: Maintain comprehensive project plans, schedules, action items, and risk/issue logs (RAID).
  • Cross-Functional Collaboration: Partner closely with internal cybersecurity architects, IT engineering, compliance teams, and external vendor partners.
  • Status Reporting & Metrics: Develop management dashboards, Key Risk Indicators (KRIs), and executive status updates highlighting progress, blockers, and residual risks.
  • Act with integrity, professionalism, and personal responsibility to uphold the firm's respectful and courteous work environment.
Operational Enablement & Transition
  • Process Documentation: Author standard operating procedures (SOPs), process workflows, control baseline definitions, and operational FAQ guides.
  • Knowledge Transfer: Facilitate structured knowledge transition and hand-off to downstream operational and support teams.
  • Continuous Improvement: Identify opportunities to automate control testing and streamline repetitive governance workflows.
Qualifications
  • Education: Bachelor's degree in Cybersecurity, Information Systems, Computer Science, Business Administration, or related field (or equivalent practical experience).
  • Experience: 5+ years of direct experience in information security, IT risk management, cyber compliance, or IT audit.
  • Risk & Controls Acumen: In-depth knowledge of cybersecurity risk frameworks, internal controls assessment, threat/vulnerability management concepts, and audit readiness.
  • Project Delivery: Demonstrated track record successfully managing complex security or technology initiatives involving multiple stakeholders and workstreams.
Preferred Qualifications & Certifications (not required)
  • Professional certifications in security, risk, or audit:
  • Certified Information Systems Auditor (CISA)
  • Certified Information Security Manager (CISM)
  • Certified in Risk and Information Systems Control (CRISC)

Certified Information Systems Security Professional (CISSP)

Project management certification
  • Project Management Professional (PMP), PMI-ACP, or Agile/Scrum certification.
  • Experience working within enterprise environments or professional services networks.
Core Competencies
  • Analytical Thinking: Ability to synthesize complex technical risks into clear, actionable business impacts.
  • Stakeholder Management: Exceptional communication skills with the ability to influence technical and non-technical stakeholders across varying seniority levels.
  • Agility & Organization: Strong organizational and prioritization capabilities, comfortably shifting between high-level project coordination and deep-dive control reviews.
  • Collaborative Leadership: Proven ability to build consensus, partner effectively with internal support teams, and drive shared accountability.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Cyber Risk Manager
Senior Cyber Risk Manager

Avantdigitalnow • San Francisco (CA)

On-site
USD 120,000 - 150,000
Information Security Risk Manager
Information Security Risk Manager

Bloomberg • New York (NY)

On-site
USD 120,000 - 180,000
CyberSecurity Specialist - GRC - W2 Only
CyberSecurity Specialist - GRC - W2 Only

Saransh Inc • Phoenix (AZ)

Hybrid
USD 110,000 - 160,000
Cyber Security Engineer
Cyber Security Engineer

Trinity Global Consulting • Springfield (VA)

On-site
USD 90,000 - 110,000
Senior Manager of Risk and Compliance
Senior Manager of Risk and Compliance

PTR Global • United States

On-site
USD 100,000 - 130,000
Cyber Security Project Manager
Cyber Security Project Manager

KTek Resourcing • Chicago (IL)

On-site
USD 89,544 - 103,320
Technology & Cybersecurity Risk Management Analyst
Technology & Cybersecurity Risk Management Analyst

Appathon • Plano (TX)

On-site
USD 55,000 - 61,000
Cyber Security Analyst
Cyber Security Analyst

Infobahn Softworld Inc • Oakland (CA)

On-site
USD 85,000 - 120,000
Interim Cybersecurity & IT Risk Lead Consultant
Interim Cybersecurity & IT Risk Lead Consultant

Fermi America • Dallas (TX)

Hybrid
USD 140,000 - 200,000
Remote Cyber Risk & Controls Program Lead
Remote Cyber Risk & Controls Program Lead

Planet Group • New York (NY)

Remote
USD 176,000 - 182,000