Cyber Strategy - Senior - Consulting
Listed on 2026-09-10
-
IT/Tech
Cybersecurity, IT Consultant, Information Security & Data Protection
Location:
Anywhere in Country
At EY, we’re all in to shape your future with confidence.
We’ll help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go. Join EY and help to build a better working world.
The OpportunityOrganizations today face increasingly complex cybersecurity challenges driven by evolving threats, heightened regulatory expectations, cloud adoption, digital transformation, and emerging technologies. As a Senior Consultant within EY's Cyber Strategy practice, you will work with clients to evaluate cybersecurity programs, identify opportunities to strengthen risk management and governance, and develop practical strategies that support business objectives. This role offers the opportunity to work on complex engagements across multiple industries while developing deep expertise in cybersecurity strategy, governance, operating models, and transformation.
YourKey Responsibilities
As a Senior Consultant, you will play an active role in delivering cybersecurity strategy and transformation engagements while working closely with clients and EY engagement teams. You will support cybersecurity assessments, facilitate stakeholder interviews and workshops, analyze findings, and help translate insights into actionable recommendations. You will evaluate cybersecurity programs, governance structures, policies, operating models, and risk management capabilities against industry frameworks and leading practices.
You will assist clients in identifying capability gaps, emerging risks, and strategic improvement opportunities, helping them prioritize initiatives that strengthen security while supporting business objectives.
In addition, as a Senior Consultant, you will contribute to the development of cybersecurity strategies, target operating models, governance frameworks, maturity assessments, and transformation roadmaps. You will prepare client deliverables, executive presentations, and reports, communicating complex concepts to both technical and non-technical audiences. You will collaborate with multidisciplinary teams to deliver high-quality work products, support project planning and management activities, mentor junior team members, and contribute to business development initiatives, thought leadership, and practice-building efforts.
Skillsand Attributes for Success
Strong understanding of cybersecurity concepts, risk management principles, and industry trends.
Ability to analyze complex problems and develop practical, business-oriented recommendations.
Strong critical thinking, analytical, and problem-solving skills.
Ability to communicate effectively with both technical and business stakeholders.
Experience developing executive-level presentations, reports, and client-facing deliverables.
Strong verbal and written communication skills.
Ability to manage competing priorities in a fast-paced consulting environment.
Strong attention to detail and commitment to high-quality client service.
Ability to build relationships and collaborate effectively across teams and client organizations.
Demonstrated initiative, adaptability, and a commitment to continuous learning.
A bachelor's degree in Cybersecurity, Information Systems, Computer Science, Engineering, Business, Risk Management, or a related field, and approximately 3-5 years of relevant experience; or a graduate degree and 2-4 years of relevant experience.
Experience in one or more of the following areas:
Cybersecurity assessments and maturity evaluations
Cybersecurity governance, risk management, and compliance
Security strategy and roadmap development
Cybersecurity operating models and organizational design
Security policies, standards, procedures, and controls
Cybersecurity metrics, reporting, and program management
Regulatory and compliance assessments
Cybersecurity awareness and training programs
Knowledge of cybersecurity frameworks and standards such as NIST CSF, NIST 800-53, ISO 27001/27002, CIS Controls, and PCI DSS.
Experience conducting research, assessments, and analysis related to cybersecurity risks and controls.
Strong Microsoft PowerPoint, Excel, and Word skills.
Willingness to travel based on client and business needs; travel estimated at 25-50%.
Professional certifications such as CISSP, CISM, CRISC, CISA, Security+, or other relevant cybersecurity certifications.
Experience supporting NIST Cybersecurity Framework assessments, strategic transformation…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).