IT Risk Consultant, Cloud/SaaS Adoption

Infinitive
Ashburn, VA


About Infinitive

Infinitive is a data & AI consultancy that enables global brands to deliver results through insights, innovation, and efficiency. We possess deep industry and technology expertise to drive and sustain adoption of new capabilities. We match our people and personalities to our clients' culture while bringing the right mix of talent and skills to enable high return on investment.

Infinitive has been named “Best Small Firms to Work For” by Consulting Magazine eight times, and has also been named a Washington Post Top Workplace, Washington Business Journal Best Places to Work, and Virginia Business Best Places to Work.

About the Role

We are seeking a Cloud / SaaS Service Adoption Risk Consultant to support clients in evaluating the security, compliance, operational, and business risks associated with onboarding and scaling new cloud and SaaS services. In this role, you will assess vendor capabilities, review service and architecture designs, recommend governance controls, and guide organizations through risk-informed adoption decisions that balance innovation with regulatory, security, and operational guardrails.

You will work closely with cyber security, procurement, legal, risk management, architecture, and product teams to shape standards, streamline review processes, and ensure rapid—but safe—enablement of new SaaS and cloud capabilities.


Key Responsibilities

Risk Assessment & Advisory

  • Conduct end-to-end assessments of new SaaS and cloud vendors, including security posture, compliance certifications, architecture, data flows, SLAs, and operational reliability.

  • Evaluate vendor SOC 1/SOC 2 reports, penetration testing summaries, data privacy practices, and business continuity/disaster recovery controls.

  • Recommend remediation actions, compensating controls, or risk acceptance decisions.

Governance & Policy Alignment

  • Develop or refine cloud/SaaS adoption frameworks, intake workflows, risk scoring models, and tiering methodologies.

  • Ensure adoption decisions align with enterprise policies (e.g., authentication standards, encryption requirements, data retention, vendor onboarding).

  • Partner with enterprise architecture to confirm alignment with security patterns and integration standards.

Stakeholder Engagement

  • Facilitate risk review meetings across InfoSec, Legal, Procurement, Privacy, Architecture, and business stakeholders.

  • Translate technical and compliance findings into clear business impact and decision options.

  • Present recommendations to leadership and risk committees as needed.

Enablement & Process Improvement

  • Create playbooks, intake checklists, vendor assessment templates, and decision dashboards.

  • Identify opportunities to streamline review timelines and improve cross-team collaboration.

  • Track adoption outcomes, continuous monitoring results, and vendor performance over time.


Required Qualifications

  • 3+ years in one or more areas: cloud security, third-party risk, SaaS vendor evaluations, cybersecurity consulting, or enterprise technology risk management.

  • Experience reviewing vendor security documentation (SOC reports, CAIQ/CSA, ISO 27001, FedRAMP packages, etc.).

  • Familiarity with cloud concepts including identity and access management, data residency, integrations, audit logging, and API-driven workflows.

  • Strong communication and stakeholder facilitation skills—able to synthesize and present risk recommendations clearly.

  • Ability to manage multiple vendor/service assessments in parallel.


Preferred Qualifications

  • Experience working within regulated industries (financial services, healthcare, public sector, etc.).

  • Understanding of frameworks such as NIST CSF, ISO 27001, SOC, CSA CCM/STAR.

  • Certifications such as CISA, CCSK/CCSP, Security+, CISM, CRISC, AWS/Azure/GCP Foundations, or Prosci Change Management.

  • Prior consulting or cross-functional advisory experience.

Posted 2025-11-28

Recommended Jobs

DIR, CONTAINER MAINTENANCE & REPAIR

CMA CGM
Norfolk, VA

Led by Rodolphe Saadé, the CMA CGM Group, a global leader in shipping and logistics, serves more than 420 ports around the world on five continents. With its subsidiary CEVA Logistics, a world leader…

View Details
Posted 2025-10-16

Program Manager 4-ProdDev

Oracle
Richmond, VA

**Job Description** Join Oracle's Platform Software Team as a Technical Program Manager, driving complex, cross-functional software projects for Oracle Cloud Infrastructure and Exadata. You will manag…

View Details
Posted 2025-11-14

Primary Care LPN

Bayview Physicians Group
Suffolk, VA

Primary Care Licensed Practical Nurse (LPN) Bayview Physicians Group – Hampton Roads, VA About Us Bayview Physicians Group is a dynamic and growing outpatient multi-specialty medical group co…

View Details
Posted 2025-07-25

Logistics Coordinator - NOT a remote position

Perfect Placement Group, LLC
Mechanicsville, VA

Logistics Coordinator Location: Mechanicsville, VA - IN PERSON - not a remote position! Schedule: Monday–Friday, 8:00 AM – 5:00 PM Compensation: $28–$30 per hour Reports To: Logistic…

View Details
Posted 2025-11-14

Structural Engineer - Ship/Dry dock

RedBeard Solutions
Newport News, VA

Location: Newport News VA, fully onsite (No relocation assistance) Number of openings: 1 Experience: 5 Years with Bachelors in Science; 3 Years with Masters; 0 Years with PhD.- Newport Ne…

View Details
Posted 2025-11-13

American Girl Tysons Corner Retail Associate- Holiday Seasonal

Mattel
McLean, VA

The Opportunity:  The American Girl Washington DC retail store (McLean VA) is looking for dynamic individuals as  Summer Seasonal   Sales Department Associates  who have the interpersonal skills to p…

View Details
Posted 2025-11-26

Occupational Therapist - Outpatient/Hand Therapy

Bonsai Rehab
Blacksburg, VA

We are now hiring a full-time Occupational Therapist to work in an Outpatient Orthopedic setting in Blacksburg, VA, focusing on hand therapy/upper extremities. 40 hours per week are available. All ca…

View Details
Posted 2025-11-21

Outreach & Engagement Specialist - Senior

KBR
Chantilly, Loudoun County, VA

Title: Outreach & Engagement Specialist - Senior Belong. Connect. Grow. with KBR! KBR's National Security Solutions team provides high-end engineering and advanced technology solutions to ou…

View Details
Posted 2025-11-26

Requirements Engineer TS/SCI CI poly

Tenica and Associates
Chantilly, Loudoun County, VA

TENICA is looking to hire a Ground Engineering Requirements Engineer. This position is responsible for establishing/maintaining the requirements repository. Monitoring/controlling the project require…

View Details
Posted 2025-11-27

Satellite Systems Engineer

SAIC
Chantilly, Fairfax County, VA

**Description** Join a winning team!! SAIC's Space and Intelligence Business Group is currently hiring to advance space capabilities supporting our Department of Defense (DOD) and Intelligence Communi…

View Details
Posted 2025-11-19