Interim Cybersecurity & IT Risk Lead Consultant

Fermi Inc

Dallas (TX)

Hybrid

USD 170,000 - 250,000

Full time

4 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Fermi Inc in Dallas seeks an experienced Cybersecurity & IT Risk Lead Consultant to establish and mature the cybersecurity, risk, and compliance function for a rapidly growing infrastructure organization. This senior internal role partners with executives to strengthen governance and reduce enterprise risk.

You will design policies, oversee MSSPs, manage SOX and SEC-related disclosure activities, and build scalable IAM, PAM, and incident response programs across on-prem and cloud environments.

Qualifications

  • 10+ years of progressive experience in cybersecurity, information security, IT risk, or security consulting.
  • Proven track record building or maturing cybersecurity programs within growing organizations.
  • Strong experience across IAM, PAM/PIM, and Microsoft Entra; endpoint security, cloud security, vulnerability management, security operations, incident response, and third-party/vendor risk management.

Responsibilities

  • Assess, design, and implement cybersecurity governance, policies, standards, and risk management frameworks.
  • Develop and execute a strategic cybersecurity roadmap aligned with business objectives and growth plans.
  • Lead enterprise cybersecurity risk assessments and remediation initiatives.
  • Oversee IAM, PAM/PIM, and Microsoft Entra projects to strengthen access controls.
  • Coordinate incident response and vulnerability management across internal teams and MSSPs.
  • Collaborate with Legal on data governance, eDiscovery, and SEC-related disclosures.
  • Partner with facilities and operations on OT/ICS security practices.

Skills

IAM
PAM/PIM
Microsoft Entra
Endpoint security
Cloud security
Vulnerability mgmt
Security operations
Incident response
Vendor risk mgmt
SOX/compliance

Job description

Description

We are seeking an experienced Cybersecurity & IT Risk Lead Consultant to help establish and mature the cybersecurity, risk, and compliance function for a rapidly growing infrastructure organization. This individual will serve as the senior internal cybersecurity leader, responsible for strengthening security governance, reducing enterprise risk, overseeing managed security providers, and building the foundation for a scalable security program. The ideal candidate brings a combination of hands-on technical expertise and strategic leadership, with experience operating in highly regulated, capital-intensive environments such as energy, industrial infrastructure, construction, utilities, critical infrastructure, or data center organizations. This role will partner closely with executive leadership, legal, compliance, operations, and external service providers to ensure cybersecurity, IT risk, and governance programs evolve alongside the organization’s growth.


Cybersecurity Program Leadership


  • Assess, design, and implement cybersecurity governance, policies, standards, and risk management frameworks.

  • Develop and execute a strategic cybersecurity roadmap aligned with business objectives and growth plans.

  • Establish security metrics, reporting, and executive-level risk visibility.

  • Build scalable cybersecurity processes suitable for a growing organization.


IT Risk & Compliance


  • Lead enterprise cybersecurity risk assessments and remediation initiatives.

  • Support regulatory, governance, and compliance requirements, including SOX controls and public-company cybersecurity expectations.

  • Assist with cybersecurity governance activities, risk reporting, and documentation aligned with SEC disclosure requirements.

  • Develop and maintain security policies, standards, and control frameworks.


Identity & Access Management


  • Oversee and enhance Identity and Access Management (IAM) and Privileged Access Management (PAM/PIM) programs.

  • Drive security best practices within Microsoft Entra and related identity platforms.

  • Improve access governance, authentication controls, and privileged account management.


Security Operations & Incident Response


  • Provide oversight of vulnerability management, endpoint security, cloud security, threat detection, and incident response programs.

  • Lead investigations, root cause analyses, and remediation efforts following security incidents or data-loss events.

  • Coordinate incident response activities across internal stakeholders and third-party providers.

  • Establish and refine security monitoring and response procedures.


Security Vendor & MSSP Management


  • Evaluate, select, and manage Managed Security Service Providers (MSSPs) and cybersecurity partners.

  • Hold external providers accountable for service delivery, performance metrics, and security outcomes.

  • Guide the long-term transition from outsourced services toward an internally developed security capability.


Legal, eDiscovery & Data Governance


  • Partner with Legal and external counsel regarding cybersecurity matters, investigations, and risk management.

  • Support eDiscovery, legal hold, records retention, and data governance initiatives.

  • Provide cybersecurity guidance related to information retention and protection policies.


Operational Technology & Physical Security


  • Collaborate with Facilities, Operations, and infrastructure teams to address cybersecurity risks associated with operational and physical environments.

  • Support governance surrounding access control systems, surveillance technologies, visitor management, and site security solutions.

  • Contribute to the development of OT/ICS security practices as operational infrastructure expands.


Requirements

Required Qualifications


  • 10+ years of progressive experience in cybersecurity, information security, IT risk, or security consulting.

  • Proven track record building or maturing cybersecurity programs within growing organizations.

  • Strong experience across:

    • IAM, PAM/PIM, and Microsoft Entra

    • Endpoint security

    • Cloud security

    • Vulnerability management

    • Security operations

    • Incident response

    • Third-party/vendor risk management



  • Experience managing MSSPs, security consultants, and external service providers.

  • Strong knowledge of cybersecurity governance, risk management, and control frameworks.

  • Experience supporting SOX controls and public-company cybersecurity requirements.

  • Hands-on experience with policy development, risk assessments, remediation programs, and security program implementation.

  • Ability to operate effectively as both a strategic leader and hands-on contributor.

  • Excellent communication skills with the ability to engage executives, business stakeholders, legal teams, and technical teams.


Preferred Qualifications


  • Experience within energy, utilities, industrial infrastructure, construction, critical infrastructure, data center, or other capital-intensive environments.

  • Knowledge of OT/ICS cybersecurity principles and industrial control environments.

  • Experience supporting cyber-physical security programs.

  • Familiarity with SEC cybersecurity governance and disclosure requirements.

  • Certifications such as CISSP, CISM, CRISC, GIAC, or similar credentials.


Ideal Candidate Profile


  • Builder mindset with experience creating structure in rapidly growing organizations.

  • Comfortable working in ambiguity and establishing processes from the ground up.

  • Capable of balancing strategy, governance, and hands-on execution.

  • Strong vendor management and stakeholder influence skills.

  • Collaborative leader who can partner across technology, operations, legal, compliance, and executive leadership teams.


Travel


  • Primarily Dallas-based hybrid role.

  • Limited travel required to operational sites.


Third-Party Submissions

We are not accepting unsolicited résumés from staffing agencies, recruiters, or other third parties for this position. Résumés submitted without a signed agreement will be considered our property, and no placement fee will be paid.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Interim Cybersecurity & IT Risk Lead Consultant
Interim Cybersecurity & IT Risk Lead Consultant

Fermi LLC • Town of Texas (WI)

Hybrid
USD 180,000 - 230,000
Interim Cybersecurity and IT Risk Lead Consultant
Interim Cybersecurity and IT Risk Lead Consultant

Ports North • Dallas (TX)

Hybrid
USD 140,000 - 200,000
Director of Cybersecurity
Director of Cybersecurity

WSP • Houston (TX)

On-site
USD 180,000 - 260,000
Director of Cybersecurity
Director of Cybersecurity

Kinect • Los Angeles (CA), California (MO)

On-site
USD 180,000 - 270,000
Senior Cybersecurity Risk & Governance Analyst
Senior Cybersecurity Risk & Governance Analyst

Mortgage-Trade-Holding-Company,-LL • Oxford (MS)

On-site
USD 110,000 - 150,000
Compliance Lead / SOC2 / ISO 27001 / hybrid onsite in Herndon, VA
Compliance Lead / SOC2 / ISO 27001 / hybrid onsite in Herndon, VA

Motion Recruitment Partners LLC • Herndon (VA)

Hybrid
USD 140,000 - 190,000
Medical, dental, and vision coverage
401(k) with company match
Paid vacation and holidays
+1
Senior Cybersecurity Risk & Governance Analyst
Senior Cybersecurity Risk & Governance Analyst

mTrade, LLC. • Oxford (MS)

On-site
USD 110,000 - 160,000
Cybersecurity Engagement Director
Cybersecurity Engagement Director

XCUTIVES INC. • United States

On-site
USD 130,000 - 160,000
Senior Director, Cybersecurity Operations & Compliance
Senior Director, Cybersecurity Operations & Compliance

Ddn • Santa Clara (CA)

On-site
USD 150,000 - 210,000
Lead, Cybersecurity Architecture & Operations
Lead, Cybersecurity Architecture & Operations

Culligan International • Northern (KY)

Hybrid
USD 140,000 - 180,000