AA

Cyber Security Consultant

Awaken Arrow
Posted 4 hours ago
NigeriaRemoteEngineering & Development
Is this job info correct?

About Awaken Arrow

Awaken Arrow is a cybersecurity consulting and advisory firm helping organizations strengthen security, manage risk, and meet compliance obligations. We take a practical, business-focused approach, combining technical insight, effective processes, and automation to build security programs that support sustainable growth.


Position Summary

The Cybersecurity Risk Advisor partners with clients to establish, assess, and improve their cybersecurity programs. This role combines risk and compliance expertise with the technical understanding needed to evaluate controls and turn findings into practical recommendations.

You will manage ongoing client engagements, work with business and technology leaders, and guide organizations with varying levels of security maturity. The ideal candidate brings approximately eight years of relevant experience, sound judgment, and the ability to help clients make informed decisions and follow through on improvements.


Key Responsibilities

  • Serve as the primary cybersecurity advisor for assigned clients, building lasting relationships and understanding their business priorities, risk exposure, and contractual commitments.
  • Establish and improve security programs, including policies, risk registers, incident response plans, and business continuity documentation.
  • Conduct risk assessments and gap analyses against frameworks such as NIST CSF 2.0, ISO 27001, and CIS Controls, translating findings into prioritized improvement plans.
  • Validate security controls through configuration reviews, system reports, and supporting evidence, including Microsoft 365 and identity management environments.
  • Explain findings, tradeoffs, and recommended actions in language suited to technical teams, business leaders, and executive stakeholders.
  • Coordinate with engineering and operations teams to advance remediation, address implementation concerns, and track agreed actions.
  • Perform third-party risk reviews and help clients prioritize vulnerabilities based on business impact, exposure, and existing safeguards.
  • Advise on applicable regulatory obligations and support audit preparation, evidence gathering, and remediation within the agreed engagement scope.
  • Lead recurring client reviews, respond to advisory requests, and manage priorities, timelines, and requests for additional services.
  • Improve delivery methods through reusable resources, knowledge sharing, and responsible use of AI and automation, validating outputs for accuracy and client relevance.


Required Qualifications

  • Approximately eight years of experience in cybersecurity, IT risk, governance, compliance, or a related discipline.
  • Demonstrated ability to build or strengthen security programs and conduct assessments that produce actionable recommendations.
  • Working knowledge of NIST CSF, ISO 27001, CIS Controls, and related governance frameworks.
  • Understanding of regulatory requirements relevant to client environments, such as GDPR, the UK Data Protection Act 2018, or CMMC.
  • Ability to examine technical evidence and assess the effectiveness of identity, endpoint, cloud, and other security controls.
  • Strong communication, presentation, and stakeholder management skills, including the ability to explain unfamiliar concepts, address resistance, and influence decisions.
  • Effective organization and judgment when managing multiple engagements, setting expectations, and determining when to seek support or escalate concerns.
  • Bachelor’s degree in cybersecurity, information technology, computer science, or a related field, or equivalent professional experience.


Preferred Qualifications

  • Experience supporting financial services or other regulated organizations.
  • Previous cybersecurity consulting, advisory, MSP, or MSSP experience.
  • Certifications such as CISSP, CISM, CRISC, CISA, or CCSP.
  • Practical familiarity with Microsoft 365 administration, Entra ID, endpoint protection, and security reporting.
  • Experience improving GRC workflows through automation, integrations, or AI-assisted processes.


Working Conditions

  • Remote work with independent ownership of assigned engagements and regular coordination with colleagues and clients.
  • Occasional business travel and work outside standard hours may be required to support client needs or project deadlines.
  • Flexibility to manage changing priorities while maintaining quality and timely delivery.

Similar jobs