Principal Risk Advisor
- Lead cybersecurity and data privacy risk scoping and planning for mergers, acquisitions, divestitures, joint ventures, and other strategic transactions.
- Coordinate MA&D cybersecurity and privacy readiness assessments with external providers, including but not limited to maturity assessments, compromise assessments, software composition analysis, application security testing (SAST/DAST), Office 365 security reviews, network security assessments, red team exercises, executive background research, and integration support.
- Review and synthesize provider assessment outputs, translating technical findings into clear, business-focused risk summaries that highlight significant business impacts, likelihood and severity, and prioritization of remediation activities.
- Develop and present structured recommendations to support deal decisions, including risk acceptance, mitigation strategies, deal term adjustments, and conditions for close (e.g., remediation milestones and required controls).
- Partner with Corporate Development, Cybersecurity, Privacy, Legal, IT, and business leaders to integrate cybersecurity and privacy risk considerations into deal evaluation, negotiation, and integration planning.
- Coordinate Day 1 cyber readiness activities and support the design and implementation of future-state cyber operating models for acquired or divested entities, ensuring alignment with enterprise security standards and control frameworks.
- Convert assessment findings into actionable remediation plans with clear owners, timelines, and tracking mechanisms; monitor progress, escalate delays or critical risks, and provide options and trade-offs to stakeholders.
- Contribute to the development, maintenance, and continuous improvement of MA&D risk management standards, procedures, and playbooks, ensuring alignment with enterprise cybersecurity and privacy policies and standard control frameworks (such as NIST, CIS, ISACA, or ISO).
- Collaborate with security awareness and training program owners to ensure MA&D-related requirements, patterns, and lessons learned are incorporated into training, guidance, and communications for key stakeholder groups.
- Oversee the repository of MA&D projects, assessments, risks, and compliance issues in the governance, risk, and compliance (GRC) tool, working with operations and GRC teams to ensure workflows are in place to trigger security reviews based on data risk ratings and to track findings through remediation and closure.
- Manage MA&D-related cybersecurity and privacy policy exceptions, ensuring that exceptions are documented, approved, monitored, and reviewed or closed prior to expiration; ensure that automated alerts are issued to the SOC or relevant teams as needed.
- Support high-risk third-party risk assessments and onboarding/offboarding activities, applying MA&D-style rigor for critical suppliers or engagements as bandwidth permits.
- Contribute to the design and implementation of third-party risk operating model enhancements, ensuring alignment between MA&D risk practices and enterprise TPRM processes, standards, and risk scoring approaches.
- Develop and track key performance indicators (KPIs) for MA&D risk activities (such as volume of deals assessed, assessment cycle time, number and severity of findings, and remediation cycle time), and contribute MA&D-related insights to broader TPRM and cybersecurity reporting.
- Bachelor's degree from accredited university or college with minimum of 10 years of professional experience OR Associates degree with minimum of 13 years of professional experience OR High School Diploma with minimum of 15 years of professional experience
- Minimum 7 years of professional experience in Risk Management
- Note: Military experience is equivalent to professional experience
- Legal authorization to work in the U.S. is required. We will not sponsor individuals for employment visas, now or in the future, for this job.
- Lead cross-functional teams and MA&D-focused workstreams, leveraging strong influencing skills to guide risk-based decision-making across deal teams, corporate functions, and external providers.
- Demonstrate strong experience in cybersecurity and data privacy risk assessment, compliance, and regulatory standards, with the ability to interpret assessment outputs (e.g., SAST/DAST, SCA, red team, network assessments, O365 security reviews) and convert them into actionable business risk insights.
- Provide subject matter expertise within the MA&D cyber and privacy risk domain, ensuring alignment with secure supply chain and third-party risk best practices, emerging regulations, and organizational requirements.
- Exhibit strong analytical and strategic problem-solving abilities, using data and structured thinking to assess complex risk scenarios, develop pragmatic remediation plans, and define metrics for monitoring risk and performance.
- Act as a change agent for MA&D risk management, contributing to improvements in standards, processes, and tools, while demonstrating comfort in ambiguity and the ability to make informed, balanced decisions under time pressure.
- Foster collaboration and communication across Corporate Development, Cybersecurity, Privacy, Legal, IT, business teams, and external partners, establishing trust and credibility while continuously seeking opportunities to improve MA&D and third-party risk processes and solutions.
Recommended Jobs
Maintenance Assistant
Job Details Description Come join our team as a Maintenance Assistant at our state of the art, skilled nursing facility. The position works with the maintenance director to assist with organizin…
CDCA II Counselor (Toledo)
Description Looking for a new opportunity? New Season offers exciting benefits! Take a look at this opportunity to join us in making a powerful impact in your local community! Full benefits avai…
Internal Recruiter
Find. Engage. Build the Team. We’re looking for a Recruiter (Pipeline Builder) who knows how to hunt. This role is about building a strong, consistent pipeline of experienced construction tal…
US Tax Manager (Insurance Tax)
Bermuda, a British Overseas Territory in the North Atlantic, is one of the world’s leading insurance and reinsurance hubs – home to many of the largest global carriers and captive structures. Our …
Director of Rehabilitation
Aventura at Oakwood Village is seeking an experienced and motivated Director of Rehabilitation to lead our therapy team. The ideal candidate is a Physical Therapist Assistant (PTA) or Certified Occ…
Group Fitness Instructor
Benefits: ~Fun Energy Environment ~Employee discounts ~Training & development Crunch Fitness is looking for a Group Fitness Instructor to join our growing team! Crunch, known for its innova…
Quality Manager
Sensical Inc. is a successful custom manufacturing company specializing in custom materials and automotive services. We are ISO 9001:2015 certified and committed to delivering high-quality, precision…
3rd shift Skilled Machine Operator (K&M), M-F (11pm -7am), *Starting at $24.07/hour*
All Posting Locations: Mason, OH, US Job Functions: Manufacturing Date Published: February 5, 2026 Ref#: R-99991 ABOUT THE ROLE Job Description Description & Requiremen…
Private Client Advisor II
At Bank of America, we are guided by a common purpose to help make financial lives better through the power of every connection. We do this by driving Responsible Growth and delivering for our …
Cosmetic Merchandiser
As a cosmetic merchandiser, you’ll take on project-based work to ensure cosmetic products, graphics, and displays are visually appealing to attract and engage shoppers, build strong relationships wit…