| Location | Milwaukee, WI |
At Cream City Cyber , we understand the convergence of physical and digital risks and how they impact businesses and governments alike. Our battle-tested experts have been trusted advisors for decades, offering tailored security solutions to help clients navigate evolving landscapes. We strive to mitigate risks with confidence, enabling our partners to thrive in a connected world.Technology Risk Management ArchitectOverviewWe are looking for a proactive and experienced Technology Risk Management Architect to join our Risk & Compliance consulting team. In this role, you will lead cybersecurity risk assessments, ensure regulatory compliance, and manage governance activities across business functions and technology initiatives. This is a highly collaborative and strategic role, ideal for candidates with a strong technical background, excellent problem‑solving capabilities, and the ability to guide junior team members.Key ResponsibilitiesIndependently identify and assess cybersecurity risks across projects and operationsDevelop and implement risk treatment plansManage and maintain risk registers, ensuring alignment with risk management processesCollaborate with stakeholders to design effective mitigation strategiesControls ManagementAssess the effectiveness of security controls, identify gaps, and recommend enhancementsRefine testing procedures and support compliance assessmentsAdvise stakeholders on best practices for risk, security, and privacy controlsVulnerability ManagementLead assessments to identify, prioritize, and remediate vulnerabilitiesDeliver detailed reports with analysis and recommendationsPartner with stakeholders to align remediation with business objectives and risk toleranceMetrics and ReportingDevelop and deliver risk and compliance reports for mid-level managementCreate and refine KPIs and metrics to communicate trends and emerging issuesEnsure alignment of reporting with business objectivesGRC Program ManagementManage governance, risk, and compliance (GRC) elements in assigned areasWork with stakeholders to update and enforce policies and proceduresProvide practical guidance on GRC implementation within projectsRegulatory ComplianceIndependently assess compliance status and identify gapsCreate comprehensive compliance reports with improvement recommendationsSupport internal and external audit processesPolicy Development and EnforcementLead updates to cybersecurity policies and standardsPromote adherence through training and stakeholder engagementMonitor compliance and address concerns as neededCross-Functional CollaborationLead cross-department projects, ensuring integration of security requirementsServe as a liaison between security and business teams to align goalsPromote secure practices and advise on risk integration into processesLeadership and Team DevelopmentProvide mentorship to junior team membersLead small projects and workstreams with accountabilityFoster a collaborative and supportive team cultureProblem SolvingUse structured methodologies to diagnose root causes and develop creative solutionsTailor communication of solutions to technical and business audiencesAlign problem‑solving with organizational goalsPursue advanced training and certificationsStay updated on risk, compliance, and cybersecurity best practicesShare knowledge through mentoring and team discussionsRequired QualificationsBachelor's degree in Cybersecurity, Computer Science, Information Systems, or a related field5+ years of experience in information security or cybersecurity risk managementStrong understanding of risk principles, frameworks, and assessment methodologiesExperience managing enterprise GRC programs and mitigation strategiesHands‑on experience with compliance frameworks (e.g., NIST CSF, PCI‑DSS, ISO/IEC 27001, SOC 2, GDPR, HIPAA)Excellent communication skills for technical and non-technical audiencesProven ability to work independently and lead project initiativesStrategic mindset with a focus on aligning security with business objectivesPreferred QualificationsDegree in Information Security or Business Administration (or commiserate experience)Certifications such as CISSP, CISM, CRISC, CISA, or similarExperience in consulting or highly regulated industries (e.g., finance, healthcare)Familiarity with cloud security, vendor risk, and incident responseAudit and regulatory engagement experienceDemonstrated involvement in security awareness programsApplicationThis full‑time role offers significant impact and leadership opportunities within a forward‑thinking risk team. If you're passionate about cybersecurity, GRC, and driving cross‑functional risk initiatives, we encourage you to apply.#J-18808-Ljbffr