Haystack
← Back to Jobs
Finance

Cyber Risk Consultant - Financial Services / BISO / AI Governance

Compunnel Inc.Charlotte, NC🇺🇸United StatesPosted 24 Jul 2026

Why This Role Stands Out

This hybrid role offers a fantastic opportunity to shape cybersecurity risk management and AI governance within a respected financial services firm, allowing you to grow your expertise in cutting-edge areas. You'll thrive here if you're a seasoned professional passionate about evaluating complex technology solutions and ensuring robust risk frameworks. Apply today to make a significant impact and advance your career in a dynamic environment.

Quick Overview

Work Type
Hybrid
Level
Mid Senior

Job Description

Job Summary We are seeking a Cyber Risk Consultant to support cybersecurity risk management, technology governance, and Business Information Security Officer (BISO) functions within a regulated financial services environment. This role is responsible for conducting cyber risk assessments, evaluating technology and AI initiatives, supporting cybersecurity governance processes, and collaborating with business and technology stakeholders to ensure effective risk management. The ideal candidate will have extensive experience in cybersecurity risk, financial services, AI governance, and cybersecurity control frameworks. Key Responsibilities Conduct cybersecurity risk assessments and technology reviews for new and existing technology initiatives. Perform technology intake and toll gate reviews to identify, document, and address cybersecurity and technology risks before project implementation. Partner with business stakeholders, technology teams, Cyber SMEs, and cross-functional teams to evaluate technology solutions and recommend appropriate security controls. Support AI Center of Excellence (CoE) initiatives by performing cybersecurity risk assessments for Artificial Intelligence (AI), Machine Learning (ML), Generative AI, and emerging technologies. Evaluate AI architectures, data flows, technology solutions, and associated cybersecurity risk vectors to support governance and risk management decisions. Represent the BISO team by managing technology evaluation requests, clearing intake backlogs, supporting operational processes, and contributing to governance initiatives. Assess cybersecurity risks across Identity and Access Management (IAM), Vulnerability Management, Cloud Security, Cybersecurity Architecture, Network Security, Compliance, Metrics, and related security domains. Evaluate cybersecurity controls against industry frameworks including NIST, ISO 27001, and equivalent standards. Conduct third-party and vendor cybersecurity risk assessments and recommend appropriate security requirements. Identify control gaps, recommend remediation strategies, and support risk acceptance and issue management processes. Develop and maintain cybersecurity dashboards, metrics, reporting, and executive-level presentations for technology evaluations, AI governance, and BISO activities. Facilitate workshops and working sessions with technical and business stakeholders to communicate cybersecurity risks and recommendations. Build and maintain collaborative relationships with Cyber SMEs, business leaders, technology partners, and cross-functional teams. Maintain documentation related to cybersecurity assessments, governance activities, risk evaluations, and operational procedures. Required Qualifications Bachelor's degree in Computer Science, Information Systems, Cybersecurity, Engineering, Risk Management, or a related field, or equivalent professional experience. Minimum of 7 years of experience in Cybersecurity Risk Management, Information Security, Technology Risk, or Cybersecurity Governance. Minimum of 7 years of experience working within Financial Services, Banking, Insurance, Brokerage, or another highly regulated industry. Minimum of 5 years of experience identifying technology risks, evaluating cybersecurity controls, identifying control gaps, and recommending risk mitigation strategies. Minimum of 5 years of experience conducting cybersecurity risk assessments, technology reviews, and control assessments. Minimum of 5 years of experience across cybersecurity domains including IAM, Vulnerability Management, Cloud Security, Cybersecurity Architecture, Network Security, Metrics, and Compliance. Minimum of 5 years of experience working with cybersecurity control frameworks such as NIST, ISO 27001, or equivalent industry standards. Minimum of 3 years of experience assessing cybersecurity risks associated with Artificial Intelligence (AI), Machine Learning (ML), Generative AI, or emerging technologies. Minimum of 3 years of experience evaluating AI and Machine Learning architectures, cybersecurity risk vectors, data protection risks, and evaluation methodologies. Minimum of 3 years of experience performing third-party or vendor cybersecurity risk assessments and due diligence. Minimum of 3 years of experience supporting BISO, Cyber Risk, Technology Risk, Information Security Governance, or Enterprise Risk Management functions. Minimum of 3 years of experience managing technology evaluations, cyber risk intake processes, BISO intake requests, or similar governance workflows. Strong understanding of cybersecurity risk identification, control assessments, remediation planning, risk acceptance, issue management, and risk reporting. Strong communication, stakeholder management, analytical, and problem-solving skills. Experience facilitating workshops and collaborating with business leaders, Cyber SMEs, and technical teams. Ability to manage multiple priorities independently while meeting project deadlines. Preferred Qualifications Experience supporting a Business Information Security Officer (BISO) function within a financial institution. Experience supporting an AI Center of Excellence (CoE) or enterprise AI governance program. Knowledge of AI governance frameworks, AI risk management, model risk management, and Responsible AI practices. Experience supporting enterprise risk management programs within regulated financial services organizations. Experience developing cybersecurity dashboards, executive reporting, and operational metrics. Familiarity with Agile, Scrum, and enterprise governance methodologies. Certifications Certified Information Systems Security Professional (CISSP) (Preferred). Certified Information Security Manager (CISM) (Preferred). Certified in Risk and Information Systems Control (CRISC) (Preferred). Certified Information Systems Auditor (CISA) (Preferred). Education: Bachelors Degree Certification: Certified Information Systems Security Professional (CISSP) , Certified Information Security Manager (CISM) , Certified in Risk and Information Systems Control (CRISC) , Certified Information Systems Auditor (CISA)

Skills

Scrum
Agile
Due Diligence
Risk Management
Stakeholder Management

Similar jobs