Senior Information Security (Analyst – Consultant) Strategic Services Fairfax, VA or Irvine, CA If you haven't heard of Tevora, it's because we've done our job! Tevora is a tight-knit community of professionals with a shared passion for our craft. Every day, we combine in-depth knowledge of cybersecurity, technology, and compliance to help create more secure digital environments. To Tevorans, every problem is a puzzle in need of solving. We strongly believe that if we put smart, driven people in a room together, they will accomplish great things. We maintain a supportive culture that celebrates continuous learning, diverse perspectives, and sharing the wins. That's why we have our eyes on you. What's the role? The Senior Information Security Analyst is a pivotal client-facing role responsible for delivering expert assessment and solution implementation services to external organizations. This position involves evaluating client environments across operational IT, information security, privacy, and IT service management disciplines. The Senior Analyst identifies critical gaps, develops strategic roadmaps, and designs programs for enhanced maturity, resilience, and efficient service delivery. Acting as a trusted advisor, the Senior Analyst guides Tevora clients through complex challenges, facilitating the adoption of industry best practices and solutions aligned with industry-recognized frameworks for IT Service Delivery and Management, Information Security, and Privacy. A day in the life could include Client Engagements and Program Development: Lead and support various client engagements, including Enterprise Risk Assessments, Privacy Impact Assessments, and Risk /Privacy / Program Buildouts. Facilitate collaborative assessment processes such as scoping, leading client interviews/workshops, and ensuring open dialogue and understanding of client-specific challenges Manage client expectations and ensure project deliverables align with their business objectives and regulatory requirements Risk and Privacy Expertise: Perform comprehensive point-in-time assessments of client cybersecurity posture against industry standards and frameworks (e.g., NIST CSF 2.0, CIS Critical Security Controls) Conduct maturity assessments across various domains, including IT Risk Management, IT Service Management, and specific security controls Evaluate critical platforms and tool use cases, assessing their effectiveness and alignment with client needs and best practices Identify security gaps, vulnerabilities, and control weaknesses through documentation review, interviews with key personnel, and observation of operational processes Assess client compliance with relevant laws, regulations, and contractual obligations, including PII, PHI, and IP considerations, specifically HIPAA and PCI DSS Design and implement enterprise-wide IT risk management programs based on NIST principles, integrating cybersecurity risk with overall enterprise risk management (ERM) Establish risk governance structures, define roles and responsibilities, and develop risk management strategies for clients Develop and implement policies and procedures related to application security, data protection, and privacy Create roadmaps for program implementation, such as Technical Impact Analysis (TIA) programs, including stakeholder engagement, data collection, and continuous improvement Collaboration & Leadership: Prepare comprehensive assessment reports, compliance narratives, and strategic roadmaps for executive and technical client stakeholders Present complex technical and risk information clearly and concisely to diverse client audiences, supporting informed decision-making Ensure all findings, recommendations, and program documentation are auditable and support client compliance requirements Engage effectively with both internal and external stakeholders, including client project managers, client leadership, internal managers, and junior team members, to ensure alignment and successful project outcomes. Facilitate cross-functional communications with other team members and departments, fostering collaboration and knowledge sharing.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Mid Level