IT Audit, Risk & Cybersecurity Consultant
Job Description
Join Precelsus Consulting as an IT Audit, Risk & Cybersecurity Consultant supporting client engagements across IT audits, risk, cybersecurity assessments, and business continuity/disaster recovery.
- IT audits and assessments: participate in IT audits, ITGC assessments, control testing, and cybersecurity reviews
- Evidence-driven analysis: conduct walkthroughs, analyze evidence, and document processes, risks, controls, findings, and recommendations
- Risk coverage: support technology, cybersecurity, third-party, and operational risk assessments
- vCISO-related support: help with security assessments, policies and procedures, risk and vulnerability tracking, security metrics, awareness initiatives, and compliance activities
- Continuity and recovery: participate in Business Impact Analysis, business continuity, and disaster recovery engagements
- Gap remediation support: assist clients in addressing control and security gaps and act as a liaison among management, IT, cybersecurity, auditors, and vendors
- Data and tooling: analyze information using Excel, Power BI, and other relevant tools
- Client deliverables: prepare professional workpapers, reports, and executive presentations
- Consulting execution: manage multiple clients, assignments, and deadlines effectively
Requirements
- Exposure to or working knowledge of one or more technologies, such as Microsoft Azure, Microsoft 365, Entra ID, AWS, Power BI, Power Query, SQL, SIEM, EDR/XDR, vulnerability management, penetration testing, or GRC platforms
- Familiarity with one or more frameworks, standards, or regulatory requirements including NIST CSF, COBIT, CIS Controls, ISO 27001, SOC 2, PCI DSS, GLBA, HIPAA, or SOX
- Familiarity with emerging technologies, including AI and generative AI, with an interest in building knowledge of AI governance, security, privacy, and risk
- Professional certifications in IT audit, cybersecurity, risk, cloud, or related areas are desirable (examples: CISA, Security+, CySA+, PenTest+, CEH, eJPT, SSCP, Microsoft Azure, AWS, or similar)
- Previous consulting experience or experience supporting organizations in regulated industries is a plus
- English (Required)
- San Juan, PR 00917 (Required)
- Relocation: relocate before starting work (Preferred)
Tools and technologies
- Microsoft Azure, Microsoft 365, Entra ID
- AWS
- Power BI, Power Query
- SQL
- SIEM, EDR/XDR
- Vulnerability management, penetration testing
- GRC platforms
- NIST CSF, COBIT, CIS Controls, ISO 27001, SOC 2, PCI DSS, GLBA, HIPAA, SOX
- AI, generative AI
- Excel
Benefits
- Exposure to IT audit, cybersecurity, risk management, GRC, and vCISO engagements
- Experience working with diverse clients, regulated industries, and technologies
- Mentoring from experienced and certified professionals
- Training, certification, and professional growth opportunities
- Competitive salary and benefits package
Preferred qualifications
- Organized, analytical, motivated, flexible, dynamic
- Detail-oriented and solutions-driven
- Demonstrates initiative, adaptability, willingness to learn
- Strong teamwork and ability to perform in a fast-paced consulting environment
Pay and experience
- Salary: USD 50,000 per year
- IT auditing: 3 years (Preferred)
- Risk management: 1 year (Preferred)
- Regulatory compliance: 3 years (Preferred)
- Business continuity: 3 years (Preferred)
- ITGC assessments: 3 years (Preferred)
- Disaster recovery: 3 years (Preferred)
- Control assessments: 3 years (Preferred)
Education: Bachelor's (Preferred)
Work location: In person