Interim Cybersecurity & IT Risk Lead Consultant
Fermi America · Dallas ·
- Seniority
- Lead
- Category
- Security
We are seeking an experienced Cybersecurity & IT Risk Lead Consultant to help establish and mature the cybersecurity, risk, and compliance function for a rapidly growing infrastructure organization. This individual will serve as the senior internal cybersecurity leader, responsible for strengthening security governance, reducing enterprise risk, overseeing managed security providers, and building the foundation for a scalable security program. The ideal candidate brings a combination of hands-on technical expertise and strategic leadership, with experience operating in highly regulated, capital-intensive environments such as energy, industrial infrastructure, construction, utilities, critical infrastructure, or data center organizations. This role will partner closely with executive leadership, legal, compliance, operations, and external service providers to ensure cybersecurity, IT risk, and governance programs evolve alongside the organization's growth.
Cybersecurity Program Leadership
- Assess, design, and implement cybersecurity governance, policies, standards, and risk management frameworks.
- Develop and execute a strategic cybersecurity roadmap aligned with business objectives and growth plans.
- Establish security metrics, reporting, and executive-level risk visibility.
- Build scalable cybersecurity processes suitable for a growing organization.
IT Risk & Compliance
- Lead enterprise cybersecurity risk assessments and remediation initiatives.
- Support regulatory, governance, and compliance requirements, including SOX controls and public-company cybersecurity expectations.
- Assist with cybersecurity governance activities, risk reporting, and documentation aligned with SEC disclosure requirements.
- Develop and maintain security policies, standards, and control frameworks.
Identity & Access Management
- Oversee and enhance Identity and Access Management (IAM) and Privileged Access Management (PAM/PIM) programs.
- Drive security best practices within Microsoft Entra and related identity platforms.
- Improve access governance, authentication controls, and privileged account management.
Security Operations & Incident Response
- Provide oversight of vulnerability management, endpoint security, cloud security, threat detection, and incident response programs.
- Lead investigations, root cause analyses, and remediation efforts following security incidents or data-loss events.
- Coordinate incident response activities across internal stakeholders and third-party providers.
- Establish and refine security monitoring and response procedures.
Security Vendor & MSSP Management
- Evaluate, select, and manage Managed Security Service Providers (MSSPs) and cybersecurity partners.
- Hold external providers accountable for service delivery, performance metrics, and security outcomes.
- Guide the long-term transition from outsourced services toward an internally developed security capability.
Legal, eDiscovery & Data Governance
- Partner with Legal and external counsel regarding cybersecurity matters, investigations, and risk management.
- Support eDiscovery, legal hold, records retention, and data governance initiatives.
- Provide cybersecurity guidance related to information retention and protection policies.
Operational Technology & Physical Security
- Collaborate with Facilities, Operations, and infrastructure teams to address cybersecurity risks associated with operational and physical environments.
- Support governance surrounding access control systems, surveillance technologies, visitor management, and site security solutions.
- Contribute to the development of OT/ICS security practices as operational infrastructure expands.