Information Security Risk Management Specialist
Location: Reston, VA (Hybrid)
8 month contract
$60-75/hr W2. (No C2C at this time)
About the Opportunity
Our client, a global leader in technology and entertainment, is seeking a Information Security Risk Management Specialist to join its Information Security organization. This role will be responsible for identifying, assessing, and managing information security risks across business operations, technology environments, and third-party partnerships.
The ideal candidate combines strong information security knowledge with a consultative approach, helping business and technology teams understand risk, implement practical solutions, and strengthen overall security posture.
Key Responsibilities
Lead end-to-end information security risk assessments for systems, applications, networks, infrastructure, facilities, projects, and third-party vendors
Identify, evaluate, and communicate security risks while providing actionable recommendations for mitigation and remediation
Prepare and present risk assessment reports to support business decisions, risk acceptance processes, and executive-level discussions
Manage third-party and vendor security assessments, including contract and security control reviews
Analyze emerging threats and incorporate threat intelligence into risk evaluations to identify potential exposures
Support Information Security Management System (ISMS) activities through control reviews, testing, evidence validation, and maturity assessments
Partner with business, technology, and security stakeholders to provide guidance on security requirements, policies, and risk management practices
Deliver security risk consultation and education to various business units and project teams
Evaluate security controls and recommend improvements to reduce organizational risk
Assist in driving policy compliance, audit readiness, and continuous risk management program enhancements
Qualifications
Required
Bachelor's degree or equivalent combination of education and experience
5+ years of professional experience in information security, cybersecurity, risk management, governance, compliance, or related disciplines
Experience conducting information security risk assessments and communicating findings to business and technical stakeholders
Understanding of information security principles, controls, and industry best practices
Strong verbal and written communication skills with the ability to present complex topics to both technical and non-technical audiences
Experience building relationships across cross-functional teams and influencing risk-related decisions
Preferred
Experience in Governance, Risk & Compliance (GRC) programs
Knowledge of third-party risk management and vendor security assessments
Familiarity with security frameworks such as NIST, ISO 27001, CIS Controls, or similar standards
Experience with cloud security environments, including AWS
Understanding of networking, infrastructure security, operating systems, databases, and identity/access management concepts
Exposure to SaaS security assessments
Knowledge of emerging technologies and security considerations, including AI-related risk
What Makes a Strong Candidate
Demonstrated ability to perform comprehensive risk assessments and translate findings into business-focused recommendations
Experience balancing security requirements with operational and business objectives
Strong analytical and problem-solving skills
Ability to effectively prioritize competing initiatives in a fast-paced environment
Collaborative mindset with a customer-service approach to internal stakeholders
Confidence presenting risk concepts and recommendations to leadership teams
Why Apply
Opportunity to support security initiatives within a globally recognized organization
Exposure to enterprise-scale information security and risk management programs
Collaborative environment working closely with security, technology, and business leaders
Career growth within a mature and evolving cybersecurity organization
If you or someone you know is interested in this Information Security Risk Management Specialist role in Reston, VA, please apply today!
Benefit offerings for full-time employment include medical, dental, vision, term life and AD&D insurance, short-term and long-term disability, additional voluntary benefits, commuter benefits, wellness plans, and a 401k plan or a nonqualified deferred compensation plan. Available paid leave includes Personal Time Off (PTO) on an accrual basis. PTO and holiday hours are prorated based on hire date within the calendar year.
Equal Opportunity Employer/Veterans/Disabled To read our Candidate Privacy Information Statement, which explains how we will use your information, please navigate to https://www.lhh.com/us/en/candidate-privacy The Company will consider qualified applicants with arrest and conviction records in accordance with federal, state, and local laws and/or security clearance requirements, including, as applicable:
Pay Details: $60.00 to $75.00 per hour
Search managed by: Krysti Ellis
Benefit offerings available for our associates include medical, dental, vision, life insurance, short-term disability, additional voluntary benefits, EAP program, commuter benefits and a 401K plan. Our benefit offerings provide employees the flexibility to choose the type of coverage that meets their individual needs. In addition, our associates may be eligible for paid leave including Paid Sick Leave or any other paid leave required by Federal, State, or local law, as well as Holiday pay where applicable.
Equal Opportunity Employer/Veterans/Disabled
Military connected talent encouraged to apply
To read our Candidate Privacy Information Statement, which explains how we will use your information, please navigate to https://www.lhh.com/us/en/candidate-privacy
The Company will consider qualified applicants with arrest and conviction records in accordance with federal, state, and local laws and/or security clearance requirements, including, as applicable:
Massachusetts Candidates Only: It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.