Find Jobs
Find Jobs Near You – Available Work in Your Location
Skip to job details
2S
2001 SSB&T
Business Information Security Officer-AVP
Career Insights for Business / Management Consultant
See where this job fits in the broader career landscape. Knowing your career path helps you see what's possible from here.
Scorecard
Based on Massachusetts data
Review key factors to help you decide if this role fits your goals. How is this calculated?
What they do
A Business or Management Consultant provides strategic management consulting to companies and businesses. Advises on ways to improve operations, increase efficiency, reduce costs and increase revenues; may recommend systems or organizational change. Works with business management analysts; frames problems for business clients, and develops plans to address inefficiencies.
$115,173 / year median in Massachusetts
-7% projected decline
Job Description
AVP, Cyber Risk Advisor The AVP , Cyber Risk Advisor provides cyber risk advisory services focused on strengthening the firm's defensive cybersecurity posture through proactive risk management, cyber control oversight, vulnerability reduction, and security-by-design practices. The role serves as a trusted advisor to technology, infrastructure, application, and business teams, ensuring cybersecurity risks are identified, assessed, and managed in alignment with enterprise standards, regulatory expectations, and risk appetite. As a member of the Business Information Security organization, the AVP Cyber Security Advisor partners closely with Security Operations, Vulnerability Management, Threat Intelligence, Engineering, Architecture, and AI Security teams to drive risk-informed decisions and measurable reductions in cyber exposure. The successful candidate combines strong technical cybersecurity knowledge with the ability to influence stakeholders and translate complex cyber risks into actionable business guidance. Cyber Risk Advisory & Oversight Assess cyber risks associated with infrastructure, applications, cloud services, third party supply chain, and emerging technologies. Assess network designs, material changes, and new initiatives for security risk; review architecture artifacts and control implementations. Provide expert guidance on risk acceptance decisions, exception handling, and residual risk posture related to network controls. Support execution of enterprise cyber risk management objectives and control improvement initiatives across Saas platforms in support of client deliverables. Security Architecture & Design Influence Partner with network and cloud engineering teams to embed security ‑ by ‑ design and resilience principles across on ‑ prem, cloud, and hybrid networks. Review and influence network segmentation, trust boundaries, ingress/egress controls, and monitoring strategies . Influence the alignment with security patterns with enterprise standards, zero trust principles, and regulatory obligations while working with cyber threat intel to build models. Partner with GCS Security Guardians to ensure current network security principals and guidance are updated and documented . Vulnerability and Exposure Management Partner with vulnerability management teams to prioritize remediation activities based on risk. Analyze vulnerability trends, systemic control weaknesses, and emerging threat exposures. Provide advisory support on patch management, configuration management, and security hardening efforts . Assist business and technology teams in developing sustainable remediation strategies. Risk Assessment & Control Governance Lead or support network security risk assessments, control gap analysis, and prioritization aligned to enterprise risk frameworks. Track remediation of identified control gaps and provide transparent risk reporting and escalation as needed. Support internal audits, regulatory reviews, and risk committees by articulating network security posture and key risks. Threat and Incident Advisory Provide advisory support during cyber incidents and events , including impact analysis, containment strategy guidance, and participate in playbook refinement . Partner with threat intelligence teams , cyber defense center , and vulnerability management teams to interpret emerging threats , model exposure, and appropriate remediation . Qualifications and Experience Strong technical understanding of enterprise networking concepts and security controls. Strong experience with network security technologies , secure cloud, Secure SDLC practices Experience in securing S oftware-as-a- S ervice delivery models (Identity, Data Protection, Monitoring, and Governance) Ability to assess architecture diagrams and design documents for security risk. Experience in cyber risk assessment, control evaluation, and remediation tracking. Strong written and verbal communication skills; able to influence without direct authority. Experience in regulated financial services or similarly complex environments. Exposure to regulatory expectations (e.g., FFIEC, NIST, ISO, SOC, or equivalent frameworks). Experience supporting audits, regulators, or executive risk forums.