Interim Cybersecurity & IT Risk Lead Consultant

Fermi LLC

Town of Texas (WI)

Hybrid

USD 180,000 - 230,000

Full time

5 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Fermi LLC, based in the Dallas area, seeks an experienced Cybersecurity & IT Risk Lead Consultant to establish and mature the cybersecurity, risk, and compliance function for a rapidly growing infrastructure organization. This senior leader partners with executives, legal, compliance, operations, and external providers to ensure security programs evolve with growth.

The ideal candidate has 10+ years in cybersecurity and risk, a hands-on yet strategic mindset, and a track record building security

Qualifications

  • 10+ years of progressive experience in cybersecurity, information security, IT risk, or security consulting.
  • Proven track record building or maturing cybersecurity programs within growing organizations.
  • Experience with IAM, PAM/PIM, Microsoft Entra; endpoint, cloud, vulnerability management, security operations, incident response, and third-party risk.

Responsibilities

  • Lead cybersecurity governance, risk management, and policy development.
  • Develop a strategic cybersecurity roadmap aligned with business growth.
  • Establish metrics, reporting, and executive risk visibility.
  • Oversee IAM, PAM/PIM, and access governance enhancements.
  • Oversee vulnerability management, endpoint security, cloud security, and incident response.
  • Manage MSSPs and cybersecurity partners.
  • Coordinate with Legal, compliance, and operations.
  • Support data governance, eDiscovery, and SEC disclosure readiness.
  • Travel: primarily Dallas-based hybrid role; limited site visits.

Skills

IAM, PAM/PIM, Microsoft Entra
Endpoint security
Cloud security
Vulnerability management
Security operations
Incident response
Third-party/vendor risk management
Vendor management

Job description

Description

We are seeking an experienced Cybersecurity & IT Risk Lead Consultant to help establish and mature the cybersecurity, risk, and compliance function for a rapidly growing infrastructure organization. This individual will serve as the senior internal cybersecurity leader, responsible for strengthening security governance, reducing enterprise risk, overseeing managed security providers, and building the foundation for a scalable security program. The ideal candidate brings a combination of hands-on technical expertise and strategic leadership, with experience operating in highly regulated, capital-intensive environments such as energy, industrial infrastructure, construction, utilities, critical infrastructure, or data center organizations. This role will partner closely with executive leadership, legal, compliance, operations, and external service providers to ensure cybersecurity, IT risk, and governance programs evolve alongside the organization's growth.

Cybersecurity Program Leadership
  • Assess, design, and implement cybersecurity governance, policies, standards, and risk management frameworks.
  • Develop and execute a strategic cybersecurity roadmap aligned with business objectives and growth plans.
  • Establish security metrics, reporting, and executive-level risk visibility.
  • Build scalable cybersecurity processes suitable for a growing organization.
IT Risk & Compliance
  • Lead enterprise cybersecurity risk assessments and remediation initiatives.
  • Support regulatory, governance, and compliance requirements, including SOX controls and public-company cybersecurity expectations.
  • Assist with cybersecurity governance activities, risk reporting, and documentation aligned with SEC disclosure requirements.
  • Develop and maintain security policies, standards, and control frameworks.
Identity & Access Management
  • Oversee and enhance Identity and Access Management (IAM) and Privileged Access Management (PAM/PIM) programs.
  • Drive security best practices within Microsoft Entra and related identity platforms.
  • Improve access governance, authentication controls, and privileged account management.
Security Operations & Incident Response
  • Provide oversight of vulnerability management, endpoint security, cloud security, threat detection, and incident response programs.
  • Lead investigations, root cause analyses, and remediation efforts following security incidents or data-loss events.
  • Coordinate incident response activities across internal stakeholders and third-party providers.
  • Establish and refine security monitoring and response procedures.
Security Vendor & MSSP Management
  • Evaluate, select, and manage Managed Security Service Providers (MSSPs) and cybersecurity partners.
  • Hold external providers accountable for service delivery, performance metrics, and security outcomes.
  • Guide the long-term transition from outsourced services toward an internally developed security capability.
Legal, eDiscovery & Data Governance
  • Partner with Legal and external counsel regarding cybersecurity matters, investigations, and risk management.
  • Support eDiscovery, legal hold, records retention, and data governance initiatives.
  • Provide cybersecurity guidance related to information retention and protection policies.
Operational Technology & Physical Security
  • Collaborate with Facilities, Operations, and infrastructure teams to address cybersecurity risks associated with operational and physical environments.
  • Support governance surrounding access control systems, surveillance technologies, visitor management, and site security solutions.
  • Contribute to the development of OT/ICS security practices as operational infrastructure expands.
Requirements
  • 10+ years of progressive experience in cybersecurity, information security, IT risk, or security consulting.
  • Proven track record building or maturing cybersecurity programs within growing organizations.
  • Strong experience across:
    • IAM, PAM/PIM, and Microsoft Entra
    • Endpoint security
    • Cloud security
    • Vulnerability management
    • Security operations
    • Incident response
    • Third-party/vendor risk management
  • Experience managing MSSPs, security consultants, and external service providers.
  • Strong knowledge of cybersecurity governance, risk management, and control frameworks.
  • Experience supporting SOX controls and public-company cybersecurity requirements.
  • Hands-on experience with policy development, risk assessments, remediation programs, and security program implementation.
  • Ability to operate effectively as both a strategic leader and hands-on contributor.
  • Excellent communication skills with the ability to engage executives, business stakeholders, legal teams, and technical teams.
Preferred Qualifications
  • Experience within energy, utilities, industrial infrastructure, construction, critical infrastructure, data center, or other capital-intensive environments.
  • Knowledge of OT/ICS cybersecurity principles and industrial control environments.
  • Experience supporting cyber-physical security programs.
  • Familiarity with SEC cybersecurity governance and disclosure requirements.
  • Certifications such as CISSP, CISM, CRISC, GIAC, or similar credentials.
Ideal Candidate Profile
  • Builder mindset with experience creating structure in rapidly growing organizations.
  • Comfortable working in ambiguity and establishing processes from the ground up.
  • Capable of balancing strategy, governance, and hands-on execution.
  • Strong vendor management and stakeholder influence skills.
  • Collaborative leader who can partner across technology, operations, legal, compliance, and executive leadership teams.
Travel
  • Primarily Dallas-based hybrid role.
  • Limited travel required to operational sites.
Third-Party Submissions

We are not accepting unsolicited résumés from staffing agencies, recruiters, or other third parties for this position. Résumés submitted without a signed agreement will be considered our property, and no placement fee will be paid.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Interim Cybersecurity & IT Risk Lead Consultant
Interim Cybersecurity & IT Risk Lead Consultant

Fermi Inc • Dallas (TX)

Hybrid
USD 170,000 - 250,000
Interim Cybersecurity and IT Risk Lead Consultant
Interim Cybersecurity and IT Risk Lead Consultant

Ports North • Dallas (TX)

Hybrid
USD 140,000 - 200,000
Director of Cybersecurity
Director of Cybersecurity

WSP • Houston (TX)

On-site
USD 180,000 - 260,000
Director of Cybersecurity
Director of Cybersecurity

Kinect • Los Angeles (CA), California (MO)

On-site
USD 180,000 - 270,000
Compliance Lead / SOC2 / ISO 27001 / hybrid onsite in Herndon, VA
Compliance Lead / SOC2 / ISO 27001 / hybrid onsite in Herndon, VA

Motion Recruitment Partners LLC • Herndon (VA)

Hybrid
USD 140,000 - 190,000
Medical, dental, and vision coverage
401(k) with company match
Paid vacation and holidays
+1
Senior Cybersecurity Risk & Governance Analyst
Senior Cybersecurity Risk & Governance Analyst

Mortgage-Trade-Holding-Company,-LL • Oxford (MS)

On-site
USD 110,000 - 150,000
Senior Cybersecurity Risk & Governance Analyst
Senior Cybersecurity Risk & Governance Analyst

mTrade, LLC. • Oxford (MS)

On-site
USD 110,000 - 160,000
Cybersecurity Engagement Director
Cybersecurity Engagement Director

XCUTIVES INC. • United States

On-site
USD 130,000 - 160,000
Senior Manager of Risk and Compliance
Senior Manager of Risk and Compliance

PTR Global • United States

On-site
USD 100,000 - 130,000
Senior Director, Cybersecurity Operations & Compliance
Senior Director, Cybersecurity Operations & Compliance

Ddn • Santa Clara (CA)

On-site
USD 150,000 - 210,000