Job Title: Cyber Security Risk Analytics & Metrics Oversight Consultant
Location: Dallas, TX -hybrid
Type: Contract to hire
Duration: 12 Months
Job DescriptionThis role supports the execution, coordination, and operational governance of the enterprise Cyber Security Risk Analytics & Metrics Oversight Program. The Senior Associate helps ensure metrics are accurate, complete, timely, traceable, and decision-ready for senior management, governance committees, and Board-level reporting, while supporting second-line oversight standards for data quality, evidence, and audit readiness.
Key Responsibilities- Support day-to-day execution of the cyber security risk metrics lifecycle, including metric intake, maintenance, enhancement, validation, and retirement activities.
- Maintain the enterprise cyber risk metric inventory by updating metric objectives, scope, calculation methodology, thresholds, authoritative data sources, owners, and evidence references.
- Perform data quality checks, reconciliation, reasonableness reviews, variance analysis, and evidence validation to support accurate and consistent metric reporting.
- Prepare monthly, quarterly, and ad-hoc cyber risk reporting inputs for governance committees, Operational Risk Management (ORM), senior management, and Board-level audiences.
- Support review of executive and Board-level reporting materials to confirm completeness, consistency, data traceability, and alignment to approved risk appetite and tolerance expectations.
- Assist with Out-of-Tolerance (OOT) metric analysis by gathering supporting data, drafting narrative inputs, validating root cause information, and tracking remediation commitments.
- Maintain documentation of metric definitions, calculation logic, data lineage, validation activities, approval decisions, and supporting evidence to ensure audit and regulatory readiness.
- Support metric proposal reviews by collecting required artifacts, assessing data availability, documenting review outcomes, and tracking follow-up actions.
- Coordinate metric-related escalations, action items, and follow-ups from governance forums, ensuring status updates are timely and accurately reflected in reporting materials.
- Support updates to Risk Tolerance Dashboards, Risk Tolerance Statements, and related enterprise metric repositories through data preparation, quality review, and narrative support.
- Assist with reporting platform and dashboard maintenance, including IBM BPM workflows, Power BI dashboards, standardized templates, CLAW integration, and future SmartSuite reporting capabilities.
- Partner with metric owners and managers to reinforce consistent data submission, interpretation, evidence standards, and reporting timelines.
- Identify recurring data quality issues, reporting gaps, control weaknesses, or thematic trends and escalate insights to program leadership for review and credible challenge.
- Support automation, process improvement, and modernization efforts that improve reporting timeliness, reduce manual rework, and strengthen traceability across the metrics lifecycle.
Required Qualifications- 4–6 years of experience in Cybersecurity Risk, Technology Risk, Governance, Risk & Compliance (GRC), Risk Analytics, Metrics Reporting, or Data Governance.
- Strong analytical, documentation, and quality review skills with exceptional attention to detail and evidence standards.
- Experience supporting risk metrics, KRIs/KPIs, dashboards, executive reporting, or governance committee materials in a regulated environment is preferred.
- Experience with data visualization tools, reporting platforms, or data warehouses such as:
- Power BI
- Snowflake
- IBM BPM
- SmartSuite
- CLAW
- Similar reporting and analytics tools