Job Opportunities API

The Public Ledger of Openings

← Back to the ledger

Senior Consultant - Cyber Security

electricmind
Companyelectricmind
CategorySecurity
LocationNew York City
RemoteOn-site (inferred)
EmploymentNot stated
LevelSenior
SalaryNot stated by the employer
Posted19 Jun 2026
Last verified12 Aug 2026
SourceThe employer's own careers page (company_site)
Applications are handled by the employer, not by us.Apply on the employer's site →
Description
Electric Mind's Technology Practice is a consulting firm helping large financial institutions navigate complex cyber security regulatory remediation. As a Senior Consultant on the Cyber & Regulatory Remediation team, you will lead client-facing engagements translating regulator findings (MRAs, MRIAs, Consent Orders) into defensible remediation plans, while driving technical execution across incident response, vulnerability management, and identity governance. What You'll Do • Lead regulatory remediation programs by translating regulator findings into prioritized remediation plans with defensible milestones, evidence requirements, and validation criteria • Drive technical remediation workstreams in partnership with client CISO, IT Risk, Infrastructure, and IAM teams to close findings on incident response, vulnerability and patch management, and identity access management • Lead or co-lead client-side incident response engagements for material cyber events, including containment strategy, forensic coordination, regulator notification, and post-incident remediation • Design and operationalize vulnerability and patch management programs, assessing current state, designing risk-based SLAs, building exception governance, and implementing tooling such as Qualys, Tenable, Rapid7, Wiz, and ServiceNow • Drive identity and access management remediation workstreams including privileged access management, joiner-mover-leaver processes, access certification, and segregation-of-duties improvements • Mentor junior analysts and consultants, review deliverables, and contribute to proposals and thought leadership assets What You Need • Hands-on experience leading or coordinating incident response for ransomware, business email compromise, third-party breach, insider, and nation-state events • Demonstrated experience designing or remediating enterprise vulnerability management programs with familiarity with Qualys, Tenable, Rapid7 InsightVM, Wiz, Microsoft Defender for Cloud, and ServiceNow Vulnerability Response • Strong understanding of identity and access management domains including identity governance and administration, privileged access management, authentication and federation, and practical experience with at least two platforms such as SailPoint, Saviynt, Okta, Azure AD, Ping, CyberArk, BeyondTrust, or Delinea • Deep knowledge of at least three regulatory frameworks and regimes such as Federal Reserve Board SR guidance, OCC Heightened Standards, NY DFS Part 500, FFIEC Cybersecurity Assessment Tool, SEC Cybersecurity Disclosure Rules, or NIST CSF • Proven ability to communicate technical findings to regulators and executive leadership, with experience drafting incident notifications and regulator communications Nice to Have • Experience with SOX ITGC, PCI DSS 4.0, GLBA Safeguards Rule, and SOC 1/SOC 2 attestation work • Familiarity with forensics coordination across external firms such as Mandiant, CrowdStrike, Kroll, or Unit 42 • Experience with patch management at scale across Windows, Linux, network, container, and cloud workloads