Riveron · Remote

Cyber Security - Strategy Lead at Riveron — Remote

Full-timeRemote$117,500–$166,250/yearPosted 2026-07-23Apply on Ashby

Full job description

Security risk is a business problem. At Riveron, our Cybersecurity practice helps organizations understand their risk, make confident decisions, and build security programs that hold up under real pressure. We partner with business leaders, boards, and technical teams to deliver advisory and execution that is practical, credible, and tied to what matters to the organization.

Our work spans the full security lifecycle, from program strategy and risk advisory to compliance readiness and hands-on remediation. We serve startups, mid-market companies, and PE-backed portfolios at any stage of their security journey, across a wide range of industries and regulatory environments.

The Cybersecurity Strategy Lead is a key delivery role within the practice. This person leads project execution across client engagements, serves as the primary day-to-day client contact, and represents the firm with professionalism while leading conversations at any level of the organization.

You will work closely with senior practice leadership, mentor junior team members, and contribute across our cybersecurity strategy, GRC, and security engineering teams as engagement needs evolve. This is a role for someone who enjoys variety, takes ownership naturally, and wants to grow in a client-facing advisory environment.

What You Have

  • Bachelor's degree in Cybersecurity, Computer Information Systems, or a related field.
  • 5+ years of experience in cybersecurity consulting, advisory services, or a client-facing security role.
  • Hands-on experience delivering security assessments, risk advisory, or program development engagements.
  • Familiarity with common cybersecurity frameworks including NIST CSF, ISO 27001, HIPAA, SOC 2, and PCI-DSS.
  • Strong written and verbal communication skills with experience presenting to senior business and technical stakeholders.
  • Technical familiarity with one or more security domains such as cloud security, identity and access management, security operations, or data protection is a plus.
  • Relevant certification preferred, such as CISSP, CISM, CISA, or equivalent.
  • Bonus experience: Hands-on tooling experience in either Cloud Security, DevSecOps, Vulnerability Management, End Point Security, or Log Management.

Who You Are

  • You take ownership of your work and your client relationships. You bring people along rather than waiting to be told what to do.
  • You communicate well across audiences. You are as comfortable in a working session with an engineer as you are presenting to a CISO or CFO.
  • You think about security in terms of business impact, not just technical controls.
  • You are adaptable. You can move between a strategy, compliance, and a technical architecture conversation without losing your footing.
  • You are a natural collaborator. You work well across teams, and you make the people around you better.
  • You are curious and motivated to keep growing. The security landscape moves fast, and you stay with it.
  • You enjoy being part of something bigger, including recruiting, training, firm events, and building a practice that stands out in the market.

What You'll Do

  • Lead day-to-day project execution across cybersecurity strategy and advisory engagements, keeping work on track and clients well informed.
  • Serve as the primary client contact throughout engagements, managing expectations, communicating progress, and building trust with stakeholder teams.
  • Facilitate workshops, discovery sessions, and working meetings with client teams including senior technical and business leadership.
  • Deliver high-quality work product including assessment reports, risk analyses, program roadmaps, and executive presentations.
  • Support security maturity assessments, gap analyses, vCISO advisory engagements, and bespoke security program projects.
  • Contribute to scoping discussions and proposal development under the guidance of practice leadership.
  • Collaborate with Riveron's GRC and Security Engineering teams to support engagements that require a broader set of capabilities.
  • Lead client status updates and reporting to keep stakeholders aligned between engagements.
  • Support business development by identifying expansion opportunities within existing client relationships.
  • Review and provide feedback on the work of Senior Associates and Associates, supporting their professional development.
  • Contribute to internal practice development such as methodology, templates, and delivery frameworks.
  • Stay current on the evolving threat landscape, emerging frameworks, and security tooling relevant to our clients.
  • Participate in recruiting, internal training, and thought leadership initiatives that contribute to the growth of the practice.

About Riveron:

Check us out on social media:

LinkedIn Glassdoor Instagram Facebook

### Fraud Alert

### Artificial intelligence (AI) tools are used to support the hiring process in screening, assessing, and/or selecting applicants for this position. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

Required skills

  • teamwork
  • delivery
  • hipaa
  • artificial intelligence
  • communication