Principal Consultant, GRC

Palo Alto Networks
Summary
Join Palo Alto Networks as a Principal Consultant, Cyber Risk Management Advisory, leading the Governance, Risk, and Compliance team. Assess security risks across multiple frameworks, act as a technical key team member in client engagements, and advocate for cybersecurity risk management. Lead advisory engagements, including Tabletop Exercises, Cyber Risk Assessments, and Incident Response Plan development. Manage teams, monitor progress, and ensure stakeholder communication. Proactively identify security risks and vulnerabilities, ensuring client controls meet legal and regulatory requirements. Effectively communicate findings and recommendations to stakeholders and scope new opportunities with prospective clients. Travel is required (approximately 30%).
Requirements
- 6+ years of experience performing information security and risk assessments based upon industry-accepted standards
- Experience managing a team of consultants
- Experience with GRC tools, technology, and implementation
- Experience with security assessments/audits, drafting findings and recommendations, and prioritizing recommendations via quantitative risk scoring
- Demonstrate a track record in strengthening existing and developing new client relationships
- Knowledge of computer forensic tools, technologies and methods
- Bachelorโs Degree in Information Security, Computer Science, Digital Forensics, Cyber Security or equivalent years of professional experience or equivalent military experience to meet job requirements and expectations
Responsibilities
- Lead and support Advisory engagements such as Tabletop Exercises, Cyber Risk Assessments, Incident Response Plan development, Ransomware Readiness Reviews & Breach Readiness Reviews
- Manage team, monitor progress, track budget, manage risk and ensure key stakeholders are kept informed about progress and expected outcomes while defining potential impacts and creating an effective mitigation strategy for multiple projects at a given time
- Skilled at proactively identifying security risks and vulnerabilities while eliminating cybersecurity threats via stakeholder interviews, documentation review, and deep-dive testing and control validation
- Ensure client controls meet legal, regulatory, privacy, policy, standards and security requirements
- Effectively write and communicate audit, assessment, or compliance results, findings, and recommendations to stakeholders
- Effectively and efficiently communicate to external stakeholders in a professional manner
- Ability to scope new opportunities with prospective clients, including drafting statements of work and proposals
- Ability to perform travel requirements as needed to meet business demands (on average ~30%)
Preferred Qualifications
Former professional services and consulting experience
Benefits
The offered compensation may also include restricted stock units and a bonus