Cybersecurity Risk & Technical Advisory Consultant - Remote
Washington, District of Columbia, 20022, USA
Listed on 2026-08-28
-
IT/Tech
Cybersecurity, IT Consultant
About us: At Echelon Risk + Cyber, we believe in defending basic human rights to security and privacy. We seek a highly skilled and experienced Cybersecurity Risk & Technical Advisory Consultant to join our dynamic team at Echelon Risk + Cyber, a leading cybersecurity consulting firm. Our next team member will be ready to roll up their sleeves and identify opportunities for our clients and for Echelon internally with unquestioned integrity.
This team member will be passionate about cybersecurity and ready to use their knowledge to be an Entrepreneurial Problem Solver and work alongside their Echelon team members to build creative solutions.
As a Cybersecurity Risk & Technical Advisory Consultant your work will include a variety of technical engagements, including cloud and Microsoft 365 security assessments, network and endpoint assessments, threat modeling, threat hunting, purple team exercises, tabletop exercises (TTXs), incident response advisory, detection engineering, and BIA/BC/DR planning.
At Echelon, you will have the opportunity to engage with clients, business partners, and systems that are at the cutting edge of technology. We allow our employees to build from the ground up and make an impact across the organization. We look for driven and proactive people that are eager to contribute to a distinct and thriving Cybersecurity services organization, that can adapt to a rapid and changing environment.
WhatYou Will Do
- Assist in the execution, development, and reporting of Technology Risk, Compliance, and Cybersecurity engagements.
- Conduct technical security assessments across cloud environments (AWS, Azure, and GCP), Microsoft 365, network infrastructure, endpoints, and SOC operations to identify control gaps and misconfigurations.
- Perform threat modeling and threat hunting engagements to proactively surface adversary behavior and gaps in detection coverage.
- Apply MITRE ATT&CK tactics, techniques, and procedures (TTPs) throughout assessments, threat modeling, and purple team engagements to map client environments against real-world adversary behavior and validate detection and response coverage.
- Support purple team exercises and technical tabletop exercises (TTXs), working alongside client blue teams to test and strengthen detection, response, and escalation processes.
- Provide incident response advisory support to clients actively managing security incidents, and develop incident response playbooks, plans, and post-incident remediation roadmaps.
- Contribute to detection engineering efforts, helping clients build, tune, and validate detection logic aligned to observed and anticipated threats.
- Support business continuity and disaster recovery (BC/DR) planning, including developing business impact analyses (BIA), to help clients prepare for and recover from disruptive events.
- Document results, create client reports, and communicate results to client management and other stakeholders.
- Work collaboratively with our clients and other team members to identify security risks and provide actionable recommendations and solutions.
- Demonstrate consistency, versatility, and adaptability while managing simultaneous client engagements and priorities and delivering quality results in a timely fashion.
- Work with the internal team to develop and plan engagement strategies, define objectives, identify and provide recommendations to address client risks.
- Handle and evaluate data and information responsibly.
- Create and deliver client-facing presentations, reports, and analytics.
- Establish exceptional internal and client relationships using strong written and verbal communication skills.
- Stay up to date with industry trends, emerging threats, and related laws and regulations within cybersecurity.
- Collaborate with members of the team to resolve new or complex cybersecurity risks and project challenges.
- Demonstrate thought leadership through the creation of content for the organization's website blog and involvement in the cybersecurity community.
- 3+ years of experience in a cybersecurity environment, with hands‑on exposure to technical security assessments, testing, or advisory work.
- 1+…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).