Fermi Inc. Logo

Fermi Inc.

Interim Cybersecurity & IT Risk Lead Consultant

Posted 8 Days Ago
Be an Early Applicant
In-Office
Dallas, TX
Expert/Leader
In-Office
Dallas, TX
Expert/Leader
Lead the development and maturation of an enterprise cybersecurity, IT risk, and compliance program. Responsibilities include governance, risk assessments, security policies, IAM/PAM, Microsoft Entra, cloud and endpoint security, incident response, vulnerability management, MSSP oversight, vendor risk, legal and data governance support, and OT/physical security coordination. The role partners with executives, legal, operations, compliance, and technical teams in a primarily Dallas-based hybrid environment with limited site travel.
The summary above was generated by AI

Description

We are seeking an experienced Cybersecurity & IT Risk Lead Consultant to help establish and mature the cybersecurity, risk, and compliance function for a rapidly growing infrastructure organization. This individual will serve as the senior internal cybersecurity leader, responsible for strengthening security governance, reducing enterprise risk, overseeing managed security providers, and building the foundation for a scalable security program. The ideal candidate brings a combination of hands-on technical expertise and strategic leadership, with experience operating in highly regulated, capital-intensive environments such as energy, industrial infrastructure, construction, utilities, critical infrastructure, or data center organizations. This role will partner closely with executive leadership, legal, compliance, operations, and external service providers to ensure cybersecurity, IT risk, and governance programs evolve alongside the organization's growth.
 

Cybersecurity Program Leadership

  • Assess, design, and implement cybersecurity governance, policies, standards, and risk management frameworks.
  • Develop and execute a strategic cybersecurity roadmap aligned with business objectives and growth plans.
  • Establish security metrics, reporting, and executive-level risk visibility.
  • Build scalable cybersecurity processes suitable for a growing organization.

IT Risk & Compliance

  • Lead enterprise cybersecurity risk assessments and remediation initiatives.
  • Support regulatory, governance, and compliance requirements, including SOX controls and public-company cybersecurity expectations.
  • Assist with cybersecurity governance activities, risk reporting, and documentation aligned with SEC disclosure requirements.
  • Develop and maintain security policies, standards, and control frameworks.

Identity & Access Management

  • Oversee and enhance Identity and Access Management (IAM) and Privileged Access Management (PAM/PIM) programs.
  • Drive security best practices within Microsoft Entra and related identity platforms.
  • Improve access governance, authentication controls, and privileged account management.

Security Operations & Incident Response

  • Provide oversight of vulnerability management, endpoint security, cloud security, threat detection, and incident response programs.
  • Lead investigations, root cause analyses, and remediation efforts following security incidents or data-loss events.
  • Coordinate incident response activities across internal stakeholders and third-party providers.
  • Establish and refine security monitoring and response procedures.

Security Vendor & MSSP Management

  • Evaluate, select, and manage Managed Security Service Providers (MSSPs) and cybersecurity partners.
  • Hold external providers accountable for service delivery, performance metrics, and security outcomes.
  • Guide the long-term transition from outsourced services toward an internally developed security capability.

Legal, eDiscovery & Data Governance

  • Partner with Legal and external counsel regarding cybersecurity matters, investigations, and risk management.
  • Support eDiscovery, legal hold, records retention, and data governance initiatives.
  • Provide cybersecurity guidance related to information retention and protection policies.

Operational Technology & Physical Security

  • Collaborate with Facilities, Operations, and infrastructure teams to address cybersecurity risks associated with operational and physical environments.
  • Support governance surrounding access control systems, surveillance technologies, visitor management, and site security solutions.
  • Contribute to the development of OT/ICS security practices as operational infrastructure expands.

Requirements

Required Qualifications

  • 10+ years of progressive experience in cybersecurity, information security, IT risk, or security consulting.
  • Proven track record building or maturing cybersecurity programs within growing organizations.
  • Strong experience across:
    • IAM, PAM/PIM, and Microsoft Entra
    • Endpoint security
    • Cloud security
    • Vulnerability management
    • Security operations
    • Incident response
    • Third-party/vendor risk management
  • Experience managing MSSPs, security consultants, and external service providers.
  • Strong knowledge of cybersecurity governance, risk management, and control frameworks.
  • Experience supporting SOX controls and public-company cybersecurity requirements.
  • Hands-on experience with policy development, risk assessments, remediation programs, and security program implementation.
  • Ability to operate effectively as both a strategic leader and hands-on contributor.
  • Excellent communication skills with the ability to engage executives, business stakeholders, legal teams, and technical teams.

Preferred Qualifications

  • Experience within energy, utilities, industrial infrastructure, construction, critical infrastructure, data center, or other capital-intensive environments.
  • Knowledge of OT/ICS cybersecurity principles and industrial control environments.
  • Experience supporting cyber-physical security programs.
  • Familiarity with SEC cybersecurity governance and disclosure requirements.
  • Certifications such as CISSP, CISM, CRISC, GIAC, or similar credentials.

Ideal Candidate Profile

  • Builder mindset with experience creating structure in rapidly growing organizations.
  • Comfortable working in ambiguity and establishing processes from the ground up.
  • Capable of balancing strategy, governance, and hands-on execution.
  • Strong vendor management and stakeholder influence skills.
  • Collaborative leader who can partner across technology, operations, legal, compliance, and executive leadership teams.

Travel

  • Primarily Dallas-based hybrid role.
  • Limited travel required to operational sites.

Third-Party Submissions

We are not accepting unsolicited résumés from staffing agencies, recruiters, or other third parties for this position. Résumés submitted without a signed agreement will be considered our property, and no placement fee will be paid.

Similar Jobs

7 Minutes Ago
Remote or Hybrid
5 Locations
87K-120K Annually
Mid level
87K-120K Annually
Mid level
Big Data • Food • Hardware • Machine Learning • Retail • Automation • Manufacturing
Analyzes consumer, shopper, customer, and market data to identify category trends and develop actionable recommendations. The role supports assortment, planogram, pricing, promotion, product placement, and omnichannel strategies while creating reports, presentations, and data-backed narratives for retailer partners. It collaborates with sales, trade marketing, category leadership, and customer teams, and serves as a consultative category expert in buyer meetings and joint business planning.
Top Skills: CrispIriExcelMicrosoft PowerpointNielsenNumeratorPower BI
58 Minutes Ago
Hybrid
83K-135K Annually
Senior level
83K-135K Annually
Senior level
Cloud • Information Technology • Software • Cybersecurity
Own strategic relationships with Lansweeper’s largest enterprise customers from onboarding through renewal and expansion. Build outcome-based success plans, lead executive QBRs and EBRs, quantify ROI, monitor health and usage signals, manage escalations, and identify expansion opportunities. The role partners closely with Sales, Account Management, Product, Support, and Engineering while using AI and customer success tools to improve account planning, risk detection, and customer outcomes.
Top Skills: ChatgptCloudConfluenceCrm PlatformsCybersecurityGainsightGainsight AiIt OperationsJIRAMicrosoft CopilotSaaS
59 Minutes Ago
Hybrid
55K-89K Annually
Mid level
55K-89K Annually
Mid level
Cloud • Information Technology • Software • Cybersecurity
Build and deploy AI agents and integrations across the go-to-market application stack. Responsibilities include configuring GTM systems, developing Salesforce data pipelines, identifying automation opportunities, engineering prompts, monitoring agent performance, implementing human-in-the-loop controls, troubleshooting workflows, and evaluating new AI tools. The role partners with Revenue Operations, Sales, Customer Success, and Salesforce teams to deliver scalable AI-augmented solutions.
Top Skills: Claude Managed AgentsDocusignGainsightGongLangchainN8NSalesforceSalesforce AgentforceSnowflakeWorkatoZapierZoominfoZoomphone

What you need to know about the Los Angeles Tech Scene

Los Angeles is a global leader in entertainment, so it’s no surprise that many of the biggest players in streaming, digital media and game development call the city home. But the city boasts plenty of non-entertainment innovation as well, with tech companies spanning verticals like AI, fintech, e-commerce and biotech. With major universities like Caltech, UCLA, USC and the nearby UC Irvine, the city has a steady supply of top-flight tech and engineering talent — not counting the graduates flocking to Los Angeles from across the world to enjoy its beaches, culture and year-round temperate climate.

Key Facts About Los Angeles Tech

  • Number of Tech Workers: 375,800; 5.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Snap, Netflix, SpaceX, Disney, Google
  • Key Industries: Artificial intelligence, adtech, media, software, game development
  • Funding Landscape: $11.6 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Strong Ventures, Fifth Wall, Upfront Ventures, Mucker Capital, Kittyhawk Ventures
  • Research Centers and Universities: California Institute of Technology, UCLA, University of Southern California, UC Irvine, Pepperdine, California Institute for Immunology and Immunotherapy, Center for Quantum Science and Engineering

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account