ECI Logo

ECI

Principal Cybersecurity Risk Advisor

Posted 2 Days Ago
Be an Early Applicant
Hybrid
San Francisco, CA, USA
Senior level
Hybrid
San Francisco, CA, USA
Senior level
The Principal Cybersecurity Risk Advisor leads client security initiatives, manages compliance programs, conducts audits, and provides strategic guidance to executive leadership in cybersecurity risk management.
The summary above was generated by AI

ECI is the leading global provider of managed services, cybersecurity, and business transformation for mid-market financial services organizations across the globe.  From its unmatched range of services, ECI provides stability, security and improved business performance, freeing clients from technology concerns and enabling them to focus on running their businesses.  More than 1,000 customers worldwide with over $3 trillion of assets under management put their trust in ECI.  

At ECI, we believe success is driven by passion and purpose. Our passion for technology is only surpassed by our commitment to empowering our employees around the world.  

Position Summary

As a Principal Cybersecurity Risk Advisor, you will work alongside industry leaders across verticals to strengthen client security postures, drive compliance programs, and act as a trusted strategic partner to executive leadership. This is not a delegation role — you will own the work: writing policies, conducting assessments, leading audits, and advising boards. This is not your typical consulting role. Since ECI is the primary third party to our clients, you will be working with internal teams to own workflows.

You will serve as a senior technical and advisory resource across a portfolio of complex client engagements, leading multi-framework compliance programs (CMMC, TISAX, NIST, ISO 27001, SOC 2, SEC) and helping clients translate evolving regulatory obligations into prioritized, actionable programs. If you can't get your hands dirty, this role isn't for you.

Responsibilities

Client Advisory & Program Leadership

  • Serve as a named senior advisor to client CTO, CISO, and executive leadership — owning strategic direction and day-to-day program execution across multiple engagements
  • Lead steering sessions, quarterly program reviews, and board-level risk briefings — preparing and delivering materials directly
  • Develop and maintain rolling GRC roadmaps aligned to client business priorities, regulatory calendars, and risk appetite
  • Translate complex regulatory and technical requirements into actionable, prioritized guidance for operational, technical, and executive stakeholders
  • Address ad hoc client security queries with timely, well-reasoned guidance, and build deep institutional knowledge of client environments, systems, and supply chains

Risk Management & Compliance

  • Develop and implement risk management strategies, maintaining enterprise GRC risk registers with hands-on identification, scoring, treatment, and reporting
  • Conduct thorough security architecture analyses, identifying vulnerabilities and proposing robust countermeasures; facilitate risk workshops and annual Security Program Reviews
  • Manage multi-framework compliance programs concurrently — CMMC Level 2 (including SSP, POA&M, SRM, SPRS scoring, and C3PAO coordination), TISAX (ISA self-assessment, ISMS), ISO 27001 (SoA, Annex A mapping), and others as client needs dictate
  • Own and drive full audit lifecycle management — pre-audit readiness, evidence collection, auditor liaison, post-audit remediation — across up to four certification engagements per year
  • Develop, review, and maintain client information security policy suites and procedures; update policies against SEC, NIST, CMMC, FTSE, ISO 27001, and other applicable standards

 

Vendor Risk & M&A Due Diligence

  • Own vendor due diligence programs including SOC 2 Type II analysis, security questionnaire reviews, risk scoring, and contractual flow-down verification
  • Lead GRC due diligence workstreams on M&A acquisition targets — assessing security posture, compliance gaps, and integration risk; produce diligence reports and post-acquisition integration roadmaps

Mentorship & Practice Development

  • Mentor team members, contributing to their professional growth and overall GRC practice capability
  • Contribute to internal practice development — maintaining and improving compliance playbooks, templates, and methodologies informed by client engagement learnings
  • Participate in internal QA and peer review processes to ensure quality and consistency across all client deliverables

Qualifications (Knowledge, Skills, Abilities)

  • 7–10+ years of experience in information security, GRC, or IT risk, with a track record of continuous growth in a consulting or advisory environment
  • At least 3 years in a client-facing advisory, vCISO, or principal consultant capacity — comfortable owning named client relationships at the C-suite level
  • Demonstrated, hands-on experience managing multi-framework compliance programs (CMMC, NIST, SOC 2, ISO 27001, TISAX, or similar) — not just familiarity in isolation
  • Experience supporting M&A transactions from a GRC/security perspective — due diligence, gap analysis, or integration planning
  • Previous consulting experience in financial services, healthcare, government, manufacturing, or DIB sectors preferred
  • Bachelor's degree in Computer Science, Information Systems, or related field required; advanced degree preferred

Preferred Qualifications

Certifications (two preferred)

  • CISSP — Certified Information Systems Security Professional
  • CISM — Certified Information Security Manager
  • CMMC Registered Practitioner (RP) or Certified Professional (CCP), or ability to obtain within 6 months
  • ISO/IEC 27001 Lead Implementer or Lead Auditor
  • CRISC or CISA advantageous

Technical & Framework Knowledge

  • Deep working knowledge of CMMC 2.0 (NIST SP 800-171 / 800-172), DFARS 252.204-7012, NIST CSF/RMF/SP 800-53, HITRUST, and SEC cybersecurity rules
  • TISAX requirements — ISA categories, maturity levels, VDA ISA control catalogue, and ENX assessment process
  • Strong understanding of security controls and best practices: MFA, Conditional Access, Least Privilege, Defense in Depth
  • Experience with endpoint and cloud security platforms (CrowdStrike, SentinelOne, Microsoft 365, Cisco); familiarity with GRC tooling (Vanta, Cynomi, Drata, Archer, ServiceNow GRC, or similar)
  • Constantly aware of evolving threat landscape and real-world events impacting client security posture

ECI’s culture is all about connection - connection with our clients, our technology and most importantly with each other.  In addition to working with an amazing team around the world, ECI offers a competitive compensation package and includes flexible PTO, benefit eligibility the first of the month, 401K with employer match and so much more!  If you believe you’d be a great fit and are ready for your best job ever, we’d like to hear from you!

Love Your Job, Share Your Technology Passion, Create Your Future Here!


#LI-Hybrid


Equal Opportunity Employer
This employer is required to notify all applicants of their rights pursuant to federal employment laws. For further information, please review the Know Your Rights notice from the Department of Labor.

Top Skills

Archer
Cisco
Cmmc
Crowdstrike
Cynomi
Drata
Iso 27001
Microsoft 365
Nist
Sentinelone
Servicenow Grc
Soc 2
Tisax
Vanta

Similar Jobs

An Hour Ago
In-Office
66K-93K Annually
Mid level
66K-93K Annually
Mid level
Aerospace • Information Technology • Software • Cybersecurity • Design • Defense • Manufacturing
Responsible for managing order fulfillment, coordinating with teams and suppliers, monitoring supply chain metrics, and driving improvements in processes.
Top Skills: ExcelMS OfficePowerPoint
An Hour Ago
In-Office
60K-74K Annually
Entry level
60K-74K Annually
Entry level
Aerospace • Information Technology • Software • Cybersecurity • Design • Defense • Manufacturing
Assist in coordinating delivery of materials, analyzing inventory data, updating information systems, and communicating material management details internally.
Top Skills: GoldI-GoldMS Office
An Hour Ago
In-Office
71K-95K Annually
Junior
71K-95K Annually
Junior
Aerospace • Information Technology • Software • Cybersecurity • Design • Defense • Manufacturing
The Supply Chain Management Analyst collaborates with various teams to manage orders, analyze inventory, ensure compliance, and support operations, requiring critical customer service and data analysis skills.
Top Skills: ErplnExcelMicrosoft OutlookMicrosoft PowerpointMicrosoft WordOrder ManagerRedarsVelocity

What you need to know about the San Francisco Tech Scene

San Francisco and the surrounding Bay Area attracts more startup funding than any other region in the world. Home to Stanford University and UC Berkeley, leading VC firms and several of the world’s most valuable companies, the Bay Area is the place to go for anyone looking to make it big in the tech industry. That said, San Francisco has a lot to offer beyond technology thanks to a thriving art and music scene, excellent food and a short drive to several of the country’s most beautiful recreational areas.

Key Facts About San Francisco Tech

  • Number of Tech Workers: 365,500; 13.9% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Google, Apple, Salesforce, Meta
  • Key Industries: Artificial intelligence, cloud computing, fintech, consumer technology, software
  • Funding Landscape: $50.5 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Sequoia Capital, Andreessen Horowitz, Bessemer Venture Partners, Greylock Partners, Khosla Ventures, Kleiner Perkins
  • Research Centers and Universities: Stanford University; University of California, Berkeley; University of San Francisco; Santa Clara University; Ames Research Center; Center for AI Safety; California Institute for Regenerative Medicine

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account