Pyramid Consulting - Atlanta, GA
posted 4 months ago
The Cyber Security Government Risk and Compliance Lead position is a critical role within the organization, focusing on ensuring compliance with applicable regulatory and legal requirements while implementing leading industry practices in cybersecurity. This position is a contract opportunity with a duration of over six months, located in Atlanta, GA, and requires onsite presence on Thursdays, with flexibility for other days after an initial period. The role involves maturing the Cybersecurity Risk Management Program, managing the cybersecurity risk register, and ensuring that appropriate risk management strategies are in place and effectively followed up on. The successful candidate will be responsible for updating Business Impact Analysis (BIAs) plans to assess key cybersecurity systems, overseeing the organization-wide Security Awareness Program, and conducting cybersecurity risk assessments in accordance with the NIST Cybersecurity Framework (CSF). This includes performing control assessments to ensure compliance with client policies and regulatory requirements, as well as leading initiatives to promote a security mindset throughout the organization. The role also involves active participation in incident response tabletop exercises and collaborating with the Cybersecurity GRC team to build programs that enhance security awareness and training across the organization. Additionally, the Cyber Security Government Risk and Compliance Lead will track incidents related to SEC cybersecurity disclosure compliance, maintain the SEC Materiality Checklist, and update workflows and incident response plans based on new SEC mandates. The position requires a strong understanding of the EU Artificial Intelligence (AI) Act Compliance Activities, including AI inventory and risk assessment, as well as governance and risk compliance activities related to AI. This role is essential for ensuring that the organization meets its cybersecurity obligations while fostering a culture of security awareness and compliance.