ECI Logo

ECI

Principal Cybersecurity Risk Advisor

Posted 2 Days Ago
Be an Early Applicant
Hybrid
Boston, MA, USA
Senior level
Hybrid
Boston, MA, USA
Senior level
The Principal Cybersecurity Risk Advisor leads client security initiatives, manages compliance programs, conducts audits, and provides strategic guidance to executive leadership in cybersecurity risk management.
The summary above was generated by AI

ECI is the leading global provider of managed services, cybersecurity, and business transformation for mid-market financial services organizations across the globe.  From its unmatched range of services, ECI provides stability, security and improved business performance, freeing clients from technology concerns and enabling them to focus on running their businesses.  More than 1,000 customers worldwide with over $3 trillion of assets under management put their trust in ECI.  

At ECI, we believe success is driven by passion and purpose. Our passion for technology is only surpassed by our commitment to empowering our employees around the world.  

Position Summary

As a Principal Cybersecurity Risk Advisor, you will work alongside industry leaders across verticals to strengthen client security postures, drive compliance programs, and act as a trusted strategic partner to executive leadership. This is not a delegation role — you will own the work: writing policies, conducting assessments, leading audits, and advising boards. This is not your typical consulting role. Since ECI is the primary third party to our clients, you will be working with internal teams to own workflows.

You will serve as a senior technical and advisory resource across a portfolio of complex client engagements, leading multi-framework compliance programs (CMMC, TISAX, NIST, ISO 27001, SOC 2, SEC) and helping clients translate evolving regulatory obligations into prioritized, actionable programs. If you can't get your hands dirty, this role isn't for you.

Responsibilities

Client Advisory & Program Leadership

  • Serve as a named senior advisor to client CTO, CISO, and executive leadership — owning strategic direction and day-to-day program execution across multiple engagements
  • Lead steering sessions, quarterly program reviews, and board-level risk briefings — preparing and delivering materials directly
  • Develop and maintain rolling GRC roadmaps aligned to client business priorities, regulatory calendars, and risk appetite
  • Translate complex regulatory and technical requirements into actionable, prioritized guidance for operational, technical, and executive stakeholders
  • Address ad hoc client security queries with timely, well-reasoned guidance, and build deep institutional knowledge of client environments, systems, and supply chains

Risk Management & Compliance

  • Develop and implement risk management strategies, maintaining enterprise GRC risk registers with hands-on identification, scoring, treatment, and reporting
  • Conduct thorough security architecture analyses, identifying vulnerabilities and proposing robust countermeasures; facilitate risk workshops and annual Security Program Reviews
  • Manage multi-framework compliance programs concurrently — CMMC Level 2 (including SSP, POA&M, SRM, SPRS scoring, and C3PAO coordination), TISAX (ISA self-assessment, ISMS), ISO 27001 (SoA, Annex A mapping), and others as client needs dictate
  • Own and drive full audit lifecycle management — pre-audit readiness, evidence collection, auditor liaison, post-audit remediation — across up to four certification engagements per year
  • Develop, review, and maintain client information security policy suites and procedures; update policies against SEC, NIST, CMMC, FTSE, ISO 27001, and other applicable standards

 

Vendor Risk & M&A Due Diligence

  • Own vendor due diligence programs including SOC 2 Type II analysis, security questionnaire reviews, risk scoring, and contractual flow-down verification
  • Lead GRC due diligence workstreams on M&A acquisition targets — assessing security posture, compliance gaps, and integration risk; produce diligence reports and post-acquisition integration roadmaps

Mentorship & Practice Development

  • Mentor team members, contributing to their professional growth and overall GRC practice capability
  • Contribute to internal practice development — maintaining and improving compliance playbooks, templates, and methodologies informed by client engagement learnings
  • Participate in internal QA and peer review processes to ensure quality and consistency across all client deliverables

Qualifications (Knowledge, Skills, Abilities)

  • 7–10+ years of experience in information security, GRC, or IT risk, with a track record of continuous growth in a consulting or advisory environment
  • At least 3 years in a client-facing advisory, vCISO, or principal consultant capacity — comfortable owning named client relationships at the C-suite level
  • Demonstrated, hands-on experience managing multi-framework compliance programs (CMMC, NIST, SOC 2, ISO 27001, TISAX, or similar) — not just familiarity in isolation
  • Experience supporting M&A transactions from a GRC/security perspective — due diligence, gap analysis, or integration planning
  • Previous consulting experience in financial services, healthcare, government, manufacturing, or DIB sectors preferred
  • Bachelor's degree in Computer Science, Information Systems, or related field required; advanced degree preferred

Preferred Qualifications

Certifications (two preferred)

  • CISSP — Certified Information Systems Security Professional
  • CISM — Certified Information Security Manager
  • CMMC Registered Practitioner (RP) or Certified Professional (CCP), or ability to obtain within 6 months
  • ISO/IEC 27001 Lead Implementer or Lead Auditor
  • CRISC or CISA advantageous

Technical & Framework Knowledge

  • Deep working knowledge of CMMC 2.0 (NIST SP 800-171 / 800-172), DFARS 252.204-7012, NIST CSF/RMF/SP 800-53, HITRUST, and SEC cybersecurity rules
  • TISAX requirements — ISA categories, maturity levels, VDA ISA control catalogue, and ENX assessment process
  • Strong understanding of security controls and best practices: MFA, Conditional Access, Least Privilege, Defense in Depth
  • Experience with endpoint and cloud security platforms (CrowdStrike, SentinelOne, Microsoft 365, Cisco); familiarity with GRC tooling (Vanta, Cynomi, Drata, Archer, ServiceNow GRC, or similar)
  • Constantly aware of evolving threat landscape and real-world events impacting client security posture

ECI’s culture is all about connection - connection with our clients, our technology and most importantly with each other.  In addition to working with an amazing team around the world, ECI offers a competitive compensation package and includes flexible PTO, benefit eligibility the first of the month, 401K with employer match and so much more!  If you believe you’d be a great fit and are ready for your best job ever, we’d like to hear from you!

Love Your Job, Share Your Technology Passion, Create Your Future Here!


#LI-Hybrid


Equal Opportunity Employer
This employer is required to notify all applicants of their rights pursuant to federal employment laws. For further information, please review the Know Your Rights notice from the Department of Labor.

Top Skills

Archer
Cisco
Cmmc
Crowdstrike
Cynomi
Drata
Iso 27001
Microsoft 365
Nist
Sentinelone
Servicenow Grc
Soc 2
Tisax
Vanta
HQ

ECI Boston, Massachusetts, USA Office

100 High Street, 16th Floor, Boston, MA, United States, 02110

Similar Jobs

An Hour Ago
Easy Apply
Remote or Hybrid
United States
Easy Apply
1K-1K Annually
Entry level
1K-1K Annually
Entry level
eCommerce • Food • Pet
Veterinary Student Ambassadors mentor peers, advocate for The Farmer's Dog products, participate in campus events related to nutrition, and provide feedback to enhance veterinary education.
An Hour Ago
Hybrid
15-20 Hourly
Junior
15-20 Hourly
Junior
eCommerce • Fashion • Other • Retail • Sales • Wearables • Design
The Sales Support Associate is responsible for enhancing customer experiences, managing stock levels, operating the POS system, and maintaining sales floor standards in a luxury retail environment. Key duties include assisting clients, processing shipments, and promoting products.
Top Skills: InternetIpadLaptopMobile PosPos Systems
An Hour Ago
In-Office
Senior level
Senior level
Information Technology • Internet of Things • Mobile • On-Demand • Software
Manage a sales team in the hospitality sector, driving sales growth, coaching personnel, and overseeing daily activities to exceed targets in telecommunications.
Top Skills: Cloud ServicesEthernetFiber ServicesHigh Speed DataMS OfficeNetworking TechnologiesSalesforceTelecommunications Technologies

What you need to know about the Boston Tech Scene

Boston is a powerhouse for technology innovation thanks to world-class research universities like MIT and Harvard and a robust pipeline of venture capital investment. Host to the first telephone call and one of the first general-purpose computers ever put into use, Boston is now a hub for biotechnology, robotics and artificial intelligence — though it’s also home to several B2B software giants. So it’s no surprise that the city consistently ranks among the greatest startup ecosystems in the world.

Key Facts About Boston Tech

  • Number of Tech Workers: 269,000; 9.4% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Thermo Fisher Scientific, Toast, Klaviyo, HubSpot, DraftKings
  • Key Industries: Artificial intelligence, biotechnology, robotics, software, aerospace
  • Funding Landscape: $15.7 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Summit Partners, Volition Capital, Bain Capital Ventures, MassVentures, Highland Capital Partners
  • Research Centers and Universities: MIT, Harvard University, Boston College, Tufts University, Boston University, Northeastern University, Smithsonian Astrophysical Observatory, National Bureau of Economic Research, Broad Institute, Lowell Center for Space Science & Technology, National Emerging Infectious Diseases Laboratories

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account