Interim Cybersecurity & IT Risk Lead Consultant
Job Description
Fermi Inc is seeking an interim Cybersecurity & IT Risk Lead Consultant to help a rapidly growing infrastructure organization establish and mature its cybersecurity, risk, and compliance capabilities. This role will function as a senior internal cybersecurity leader across governance, IT risk, identity, security operations, vendor oversight, legal and data governance, and OT or physical security considerations. Based in Dallas, TX with a hybrid schedule, the consultant will blend strategic leadership with hands-on execution to build scalable processes as the organization expands.
Key Responsibilities
- Assess, design, and implement cybersecurity governance, policies, standards, and risk management frameworks.
- Develop and execute a strategic cybersecurity roadmap aligned to business objectives and growth plans.
- Create security metrics, reporting, and executive-level visibility into risk.
- Build and scale cybersecurity processes suitable for a growing organization.
- Lead enterprise cybersecurity risk assessments and remediation initiatives.
- Support regulatory, governance, and compliance requirements, including SOX controls and public-company cybersecurity expectations.
- Contribute to cybersecurity governance activities, risk reporting, and documentation aligned with SEC disclosure requirements.
- Develop and maintain security policies, standards, and control frameworks.
- Oversee and enhance Identity and Access Management (IAM) and Privileged Access Management (PAM/PIM) programs.
- Drive security best practices within Microsoft Entra and related identity platforms.
- Improve access governance, authentication controls, and privileged account management.
- Provide oversight for vulnerability management, endpoint security, cloud security, threat detection, and incident response.
- Lead investigations, perform root cause analyses, and manage remediation after security incidents or data-loss events.
- Coordinate incident response across internal stakeholders and third-party providers.
- Establish and refine security monitoring and response procedures.
- Evaluate, select, and manage Managed Security Service Providers (MSSPs) and other cybersecurity partners, including holding external providers accountable for performance metrics and security outcomes.
- Guide the long-term transition from outsourced security services toward an internally developed security capability.
- Partner with Legal and external counsel on cybersecurity matters, investigations, and risk management.
- Support eDiscovery, legal hold, records retention, and data governance initiatives, including guidance on information retention and protection policies.
- Collaborate with Facilities, Operations, and infrastructure teams to address cybersecurity risks tied to operational and physical environments.
- Support governance for access control systems, surveillance technologies, visitor management, and site security solutions.
- Contribute to development of OT/ICS security practices as operational infrastructure expands.
Requirements
- 10+ years of progressive experience in cybersecurity, information security, IT risk, or security consulting.
- Proven track record building or maturing cybersecurity programs within growing organizations.
- Strong experience across IAM, PAM/PIM, and Microsoft Entra; endpoint security; cloud security; vulnerability management; security operations; incident response; and third-party or vendor risk management.
- Experience managing MSSPs, security consultants, and external service providers.
- Strong knowledge of cybersecurity governance, risk management, and control frameworks.
- Experience supporting SOX controls and public-company cybersecurity requirements.
- Hands-on experience with policy development, risk assessments, remediation programs, and security program implementation.
- Ability to operate effectively as both a strategic leader and hands-on contributor.
- Excellent communication skills, with the ability to engage executives, business stakeholders, legal teams, and technical teams.
Technologies
- Microsoft Entra
- IAM
- PAM/PIM
- SOX
- SEC
- OT/ICS
Preferred Qualifications
- Experience in energy, utilities, industrial infrastructure, construction, critical infrastructure, data center, or other capital-intensive environments.
- Knowledge of OT/ICS cybersecurity principles and industrial control environments.
- Experience supporting cyber-physical security programs.
- Familiarity with SEC cybersecurity governance and disclosure requirements.
- Certifications such as CISSP, CISM, CRISC, GIAC, or similar credentials.
Role Location and Travel
- Dallas, TX (hybrid)
- Limited travel required to operational sites
Third-Party Submissions: Fermi Inc is not accepting unsolicited resumes from staffing agencies, recruiters, or other third parties. Resumes submitted without a signed agreement will be considered the company’s property, and no placement fee will be paid.