Cyber Strategy PRISM Analytics and Governance Senior Consultant

Cyber | Cyber & Strategic Risk
Same job available in 12 locations

Atlanta, Georgia, United States

Boston, Massachusetts, United States

Chicago, Illinois, United States

Costa Mesa, California, United States

Dallas, Texas, United States

Detroit, Michigan, United States

Jersey City, New Jersey, United States

Los Angeles, California, United States

New York, New York, United States

Parsippany, New Jersey, United States

Philadelphia, Pennsylvania, United States

San Jose, California, United States

Position Summary

Cyber Strategy PRISM Analytics and Governance Senior Consultant

The Cyber Strategy - Analytics & Reporting – PRISM – Governance Senior Consultant is a newly created role within the Cyber Risk practice to assist client with establishing and scaling cyber risk analytics and reporting program. The program provides risk-based insights for varied global audiences ranging from operational leaders to Board of Directors. Key expectations from the candidate involve:

  • Assist in building a global cyber risk analytics program to enable executive decision making and prioritized risk mitigation through reporting of meaningful insights
  • Drive the buildout and maturing of the cyber risk analytics program - including people, process and technology components
  • Work with executive and senior management stakeholders for solution requirements gathering and socialization
  • Work with cyber data source owners to establish sustainable processes and technical architecture for data acquisition
  • Manage a team of cyber risk and data analysts to support development of cyber risk analytics solution
  • Develop program level governance and operating processes and run book for the ongoing management of the solution

Work you’ll do

  • Assist in client engagements for Cyber Risk Analytics and reporting program development and implementation
  • Must be able to collaborate internally and externally with the clients to ensure collection and distribution of complete, accurate, and timely information to stakeholders
  • Ensure a standard process is used throughout the enterprise for metrics development, creation, and analysis
  • Ensure that metrics data is consistently collected, analyzed, and reported to leadership and stakeholders
  • Actively solicit input from stakeholders and provide feedback to the leadership and program manager at every step of program development and operation
  • Assist with periodic refinement of standards-based and best practices compliant security metrics
  • Enable design and deployment of the mechanisms and tools for data harvesting and determine key risk indicators



  • Bachelor's degree in Statistics, Mathematics, Computer Science, or related discipline
  • 3+ years of experience developing Key Risk Indicators / Key Performance Indicators related to Information Security or IT Risk Management
  • 3+ years of experience and proven leadership in developing, reporting, and communicating analytic results
  • 3+ year of cyber risk experience with good understanding of overall cyber security program and expertise in at least three cyber domains e.g. vulnerability management, threat intelligence, GRC, incident management, Security operations managements, data protection etc.
  • Working knowledge of information security industry frameworks (e.g. ISO 27K, NIST Cyber Security Framework)
  • Knowledge of regulatory environment as it applies to information security
  • Drive meaningful risk-based insights from data and report across different stakeholders
  • Knowledge of different cyber risk data types and experience in guiding programmatic collection of cyber and technical data from IT data sources using programs such as Python, R, C#, PowerShell etc.
  • Working knowledge of business intelligence tools such as tableau, Power BI, QuickSight, Looker etc. to model and communicate analytic results
  • Ability to travel 35%, on average, based on the work you do and the clients and industries/sectors you serve
  • Limited immigration sponsorship may be available


An ideal candidate is

  • Is a self-driven and motivated individual with proven ability to lead development of security programs involving multitude of areas and stakeholders
  • Is a great communicator (must have)
  • Is a great presenter and adept at several reporting and presentation tools (via Microsoft PowerPoint, Excel AND more advanced reporting solutions like Tableau, QlikView)
  • Is experienced in managing a team of in-house or contracted resources
  • Is experienced in collaborating with client management and technical stakeholders

Our people and culture

Our diverse, equitable, and inclusive culture empowers our people to be who they are, contribute their unique perspectives, and make a difference individually and collectively. It enables us to leverage different ideas and perspectives, and bring more creativity and innovation to help solve our client most complex challenges. This makes Deloitte one of the most rewarding places to work. Learn more about our inclusive culture.

Professional development

From entry-level employees to senior leaders, we believe there’s always room to learn. We offer opportunities to build new skills, take on leadership opportunities and connect and grow through mentorship. From on-the-job learning experiences to formal development programs, our professionals have a variety of opportunities to continue to grow throughout their career.

As used in this posting, "Deloitte Advisory" means Deloitte & Touche LLP, which provides audit and enterprise risk services; Deloitte Financial Advisory Services LLP, which provides forensic, dispute, and other consulting services; and its affiliate, Deloitte Transactions and Business Analytics LLP, which provides a wide range of advisory and analytics services. Deloitte Transactions and Business Analytics LLP is not a certified public accounting firm. Please see for a detailed description of the legal structure of Deloitte LLP and its subsidiaries. These entities are separate subsidiaries of Deloitte LLP.

All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability or protected veteran status, or any other legally protected basis, in accordance with applicable law.

Requisition code: 32133


Caution against fraudulent job offers!

We have been informed of instances where jobseekers are led to believe of fictitious job opportunities with Deloitte US (“Deloitte”). In one or more such cases, false promises of actual or potential selection, or initiation or completion of the recruitment formalities appear to have been or are being made. Some jobseekers appear to have been asked to pay money to specified bank accounts of individuals or entities as a condition of their selection for a ‘job’ with Deloitte. These individuals or entities are in no way connected with Deloitte and do not represent or otherwise act on behalf of Deloitte.

We would like to clarify that:

  • At Deloitte, ethics and integrity are fundamental and not negotiable.
  • We are against corruption and neither offer bribes nor accept them, nor induce or permit any other party to make or receive bribes on our behalf.
  • We have not authorized any party or person to collect any money from jobseekers in any form whatsoever for promises of getting jobs in Deloitte.
  • We consider candidates on merit and that we provide an equal opportunity to eligible applicants.
  • No one other than designated Deloitte personnel (e.g., a Deloitte recruiter or Deloitte hiring partner) is permitted to extend any job offer from Deloitte.

Anyone who at any time has made or makes any payment to any party in exchange for promises of job or selection for a job with Deloitte or any matter related to this (including those for ‘registration’, ‘verification’ or ‘security deposit’) or otherwise engages with any such person who has made or makes fraudulent promises or offers, does so (or has done so) entirely at their own risk. Deloitte takes no responsibility or liability for any such unauthorized or fraudulent actions or engagements. We encourage jobseekers to exercise caution.