Senior Information Security (Analyst Consultant) Strategic Services

Tevora
Fairfax, VA

Senior Information Security (Analyst – Consultant) Strategic Services

Fairfax, VA or Irvine, CA

If you haven't heard of Tevora, it's because we've done our job!

Tevora is a tight-knit community of professionals with a shared passion for our craft. Every day, we combine in-depth knowledge of cybersecurity, technology, and compliance to help create more secure digital environments. To Tevorans, every problem is a puzzle in need of solving. We strongly believe that if we put smart, driven people in a room together, they will accomplish great things. We maintain a supportive culture that celebrates continuous learning, diverse perspectives, and sharing the wins. That's why we have our eyes on you.

What's the role?

The Senior Information Security Analyst is a pivotal client-facing role responsible for delivering expert assessment and solution implementation services to external organizations. This position involves evaluating client environments across operational IT, information security, privacy, and IT service management disciplines.

The Senior Analyst identifies critical gaps, develops strategic roadmaps, and designs programs for enhanced maturity, resilience, and efficient service delivery. Acting as a trusted advisor, the Senior Analyst guides Tevora clients through complex challenges, facilitating the adoption of industry best practices and solutions aligned with industry-recognized frameworks for IT Service Delivery and Management, Information Security, and Privacy.

A day in the life could include

Client Engagements and Program Development:

  • Lead and support various client engagements, including Enterprise Risk Assessments, Privacy Impact Assessments, and Risk /Privacy / Program Buildouts.
  • Facilitate collaborative assessment processes such as scoping, leading client interviews/workshops, and ensuring open dialogue and understanding of client-specific challenges
  • Manage client expectations and ensure project deliverables align with their business objectives and regulatory requirements

Risk and Privacy Expertise:

  • Perform comprehensive point-in-time assessments of client cybersecurity posture against industry standards and frameworks (e.g., NIST CSF 2.0, CIS Critical Security Controls)
  • Conduct maturity assessments across various domains, including IT Risk Management, IT Service Management, and specific security controls
  • Evaluate critical platforms and tool use cases, assessing their effectiveness and alignment with client needs and best practices
  • Identify security gaps, vulnerabilities, and control weaknesses through documentation review, interviews with key personnel, and observation of operational processes
  • Assess client compliance with relevant laws, regulations, and contractual obligations, including PII, PHI, and IP considerations, specifically HIPAA and PCI DSS
  • Design and implement enterprise-wide IT risk management programs based on NIST principles, integrating cybersecurity risk with overall enterprise risk management (ERM)
  • Establish risk governance structures, define roles and responsibilities, and develop risk management strategies for clients
  • Develop and implement policies and procedures related to application security, data protection, and privacy
  • Create roadmaps for program implementation, such as Technical Impact Analysis (TIA) programs, including stakeholder engagement, data collection, and continuous improvement

Collaboration & Leadership:

  • Prepare comprehensive assessment reports, compliance narratives, and strategic roadmaps for executive and technical client stakeholders
  • Present complex technical and risk information clearly and concisely to diverse client audiences, supporting informed decision-making
  • Ensure all findings, recommendations, and program documentation are auditable and support client compliance requirements
  • Engage effectively with both internal and external stakeholders, including client project managers, client leadership, internal managers, and junior team members, to ensure alignment and successful project outcomes.
  • Facilitate cross-functional communications with other team members and departments, fostering collaboration and knowledge sharing.

Necessary skills and qualifications:

  • Bachelor's degree in information security or related discipline
  • Technical Expertise:
  • Proficiency In IT Risk Management frameworks (e.g., NIST RMF, NIST CSF 2.0) and knowledge of up to two of the following industry frameworks and regulations CCPA/CPRA, GDPR, NIST Privacy, NIST RMF, PCI, ISO, HIPAA
  • Strong knowledge of cybersecurity controls, vulnerability management, identity and access management, detection and response, product security, and security operations, including CIS Critical Security Controls
  • Ability to synthesize complex technical and business information, identify patterns, and develop actionable recommendations
  • Excellent written and verbal communication skills, with the ability to present detailed technical and analytical findings clearly and concisely to both technical and non-technical audiences, including executive leadership, project managers, and technical teams.
  • Proven ability to tailor communication style and content to different audiences, from junior staff to senior management, both internally and externally.
  • Advanced capability in performing various types of assessments (point-in-time, maturity, risk, technical) and integrating findings from multiple sources
  • Hold current standing with at least one industry relevant certifications, such as CISM, CISA, CRISC, CISSP
  • Ability to coordinate and manage multiple priorities in a fast-paced environment, working both independently and collaboratively
  • Ability to travel up to 10% for client-related or internal-related activities as needed

Bonus Points:

  • At least 2 years’ experience in a client-facing role (e.g., consulting or external auditor)
  • Experience operating industry-relevant tools (e.g., GRC platforms, and other privacy and risk management solutions such as BigID, OneTrust, etc.)
  • Familiarity with Artificial Intelligence (AI) Risk Management (AI RMF), AI Governance, and AI Security

We've got you covered!

  • Comprehensive benefits including: Medical, Dental, Vision & Basic Life Insurance
  • Paid Vacations, Sick Time, & Holidays
  • 401 (k) with discretionary company match
  • Vibrant work culture

Additional requirements:

  • Eligibility to work in the United States.

$105,000 - $140,000 a year

Depending on Experince

EEOC Statement

Tevora is proud to be an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, gender identity or expression, pregnancy, sexual orientation, gender identity, national origin, age, protected veteran status, disability status, or other applicable legally protected characteristics.

We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

Posted 2026-03-16

Recommended Jobs

Lead Receptionist

Northwest Center
Arlington, VA

Description The Northwest Center @ Amazon team operates in a fast-paced and demanding corporate environment where we provide professional 5-star customer service across several program divisions. T…

View Details
Posted 2026-03-11

Emergency Veterinarian - Winchester, VA

Valley Veterinary Emergency and Referral Center
Winchester, VA

&##128680; Emergency Veterinarians – Let’s Talk Flexibility, Culture & Mountains of Perks! &##128062; Valley Veterinary Emergency Hospital (VVERC) is on the lookout for experienced and …

View Details
Posted 2026-03-03

Miembro del Equipo de Restaurante - Cocinero

Noodles & Company
Alexandria, VA

Resumen: En Noodles & Company , nuestra misión es nutrir e inspirar a cada miembro del equipo, cada cliente y cada comunidad a la que servimos. Estamos contratando Miembros del Equipo para unir…

View Details
Posted 2025-12-19

Technician

N-Hance
Portsmouth, VA

Wood Refinishing Technician N-Hance is an innovative and affordable cabinet and floor renewal service that renews wood cabinets and floors without the dust, inconvenience, and noxious fumes associ…

View Details
Posted 2026-03-15

Processing Technician, OB/Demin, Weekday ON

LifeNet Health
Virginia Beach, VA

AT LIFENET HEALTH, YOU ARE THE ADVANTAGE   Every day, YOUhelp us to save lives, restore health, and bring hope to patients and families around the world. At LifeNet Health, we cultivate growth, in…

View Details
Posted 2026-03-12

Travel Occupational Therapist Job in Woodstock, VA - $9,370 per Month (2 Years Experience Needed)

Vetted Health
Woodstock, VA

Vetted is seeking a Occupational Therapist for a travel job in Woodstock, Virginia . Must have 2+ years of experience. This contract pays approximately $9,370/month gross. Assignment deta…

View Details
Posted 2026-03-09

Manager

Hibbett Sports
Emporia, VA

Manager In Training Hourly: $13.41 - $16.00 The Manager In Training is responsible for assisting the Store Manager and Assistant Store Manager regarding overall operations and administrative dut…

View Details
Posted 2026-03-15

Development Coordinator

Boys & Girls Club of the Mountain Empire
Bristol, Washington County, VA

Summary Title: Development Coordinator Location: Bristol, VA Help Power the Mission That Changes Kids’ Lives The Boys & Girls Club of the Mountain Empire serves youth across our commu…

View Details
Posted 2026-02-20

Retail Sales Associate

Elements Massage
Vienna, VA

Overview If you're looking for a retail sales associate / customer service job where you can positively change the lives of clients in a meaningful way, then look no further! Retail Sales Associ…

View Details
Posted 2026-03-15

Warehouse Operations/Driver (M-F 7a-4p)

DSV - Global Transport and Logistics
Manassas, VA

DSV - Global transport and logistics In 1976, ten independent hauliers joined forces and founded DSV in Denmark. Since then, DSV has evolved to become the world's 3rd largest supplier of global so…

View Details
Posted 2026-02-17