Senior Cybersecurity & Disaster Recovery Auditor - USA
Zazz Tredyffrin Township, Pennsylvania, United States
IT Services and IT Consulting · 501-1,000 employees
About the role
Lead and facilitate disaster recovery and incident response tabletop exercises while conducting cybersecurity audits against recognized frameworks. Provide executive-level advisory services, including risk governance, policy development, and board-level reporting.
What they look for
Requirements
Requires 10+ years of experience in cybersecurity, IT risk, or audit roles with a background in top-tier advisory firms. Candidates must possess relevant certifications such as CISSP, CISM, CISA, or CRISC and demonstrate strong executive communication skills.
Full description
Fractional / Consulting Engagement — Financial Services Client
Position Summary
We are engaging a Senior Cybersecurity and Disaster Recovery Auditor to lead governance, risk, and resilience assessments for a financial-sector client. This role sits at the intersection of cybersecurity compliance, business continuity, and executive advisory work, and is best suited to a principal-level consultant or fractional CISO with a track record of directing tabletop exercises and presenting findings to senior leadership and boards. Candidates who have held Big 4 or comparable top-tier advisory roles (e.g., Deloitte, PwC, EY, KPMG, or equivalent boutique cybersecurity/risk consultancies) are strongly preferred.
Engagement Details
- Location: On-site availability required in Radnor, PA 19087 for client tabletop exercise facilitation
- Engagement type: Fractional / consulting (1099)
- Level: Senior Architect minimum; Associate CIO/CTO-level experience preferred
Key Responsibilities
- Design, lead, and facilitate disaster recovery and incident response tabletop exercises for large financial-sector clients, including scenario development, injects, and after-action reporting
- Conduct cybersecurity and disaster recovery audits against recognized frameworks (NIST 800-53, NIST CSF, ISO 27001, FFIEC, SOC 2) and produce gap assessments with prioritized remediation roadmaps
- Evaluate and advise on business continuity plans (BCP), disaster recovery plans (DRP), and risk governance structures, including RTO/RPO validation
- Serve as a fractional CISO or governance advisor where needed — setting risk appetite, policy frameworks, and audit cadence
- Prepare and deliver executive-level presentations and board briefings on audit findings, risk posture, and remediation status
- Act as primary stakeholder liaison between the client's executive team, IT/security staff, and third-party auditors or regulators
- Develop governance documentation: risk registers, audit charters, control matrices, and compliance attestations
- Mentor client-side security and IT staff on maintaining audit readiness and resilience posture post-engagement
Required Qualifications
- 10+ years in cybersecurity, IT risk, or audit roles, with demonstrated progression into senior/principal or fractional executive engagements
- Direct experience designing and running disaster recovery/incident response tabletop exercises for enterprise or financial-sector clients
- Deep working knowledge of business continuity planning (BCP/DRP), risk governance frameworks, and regulatory compliance in financial services (FFIEC, GLBA, SOX, FINRA as applicable)
- Proven executive presentation and stakeholder communication skills — comfortable presenting directly to C-suite and boards
- Prior experience at a Big 4 firm, national cybersecurity/risk consultancy, or as principal of an independent advisory practice
- One or more relevant certifications: CISSP, CISM, CISA, CRISC, or equivalent
- Available for on-site work in Radnor, PA 19087 for scheduled tabletop exercises
Preferred Qualifications
- Prior title or equivalent standing at Associate CIO, CTO, VP of Risk/Security, or Principal Consultant level
- Experience serving as fractional CISO for mid-market or enterprise clients
- Background in M&A security due diligence or pre-IPO compliance readiness
- Familiarity with CMMC, HITRUST, or FedRAMP in addition to financial-sector frameworks
Similar roles
-
Staff Software Security Engineer
Anthropic London, England, United Kingdom · £255K–£325K/yr
-
Security Engineer - Blue Team
Incognia Confidential Brazil
-
Information Security Engineer | Corporate Technology
Red Ventures Charlotte, North Carolina, United States · $100K–$150K/yr
-
Application Security Engineer - Assistant Vice President
iCapital Salt Lake City, Utah, United States · $100K–$130K/yr
-
Consultant Cloud Security Engineer [CloudSec] - F/H/N
OCTO Technology Paris, Ile-de-France, France · €60K–€75K/yr
-
Cybersecurity Detection Engineer
Spektrum Mons, Wallonia, Belgium