Pivot Point Solutions
Pivot Point Solutions is a California-based technology consulting firm that specializes in delivering IT solutions and support for the construction and utility industries. We partner with organizations across the state to provide reliable technology services that improve operational efficiency, enhance project delivery, and support critical business systems.
Our team understands the unique technology challenges facing construction and utility organizations, from field operations and infrastructure projects to enterprise applications and cybersecurity. By combining industry expertise with responsive service, we help clients modernize their technology environments, streamline workflows, and maintain secure, reliable IT systems that support long-term growth.
Job Overview
Title: Senior Cybersecurity Risk & Governance Consultant
Sector: Cybersecurity
Seniority: Senior Level
Location: Oakland, CA
Job Type: Contract
Contract Length: 18 months
Compensation: $121,181 – $178,422
As a Senior Cybersecurity Risk & Governance Consultant, you will help shape and oversee cybersecurity strategy, risk management, regulatory compliance, and security governance across a complex enterprise environment. This role works closely with cybersecurity leadership, business stakeholders, regulatory partners, and technical teams to evaluate risk and strengthen security practices across both information technology (IT) and operational technology (OT) environments.
The position also supports emerging areas of cybersecurity risk, including artificial intelligence governance and security. You'll provide senior-level guidance on cybersecurity frameworks, critical infrastructure protection, regulatory requirements, and enterprise risk while helping translate complex technical risks into actionable recommendations for leadership.
Your Day-to-Day Activities
Lead and support enterprise cybersecurity governance, risk management, and compliance initiatives
Develop cybersecurity strategies, roadmaps, operating plans, and risk reduction priorities
Maintain and evaluate cybersecurity risk portfolios across multiple business and technology environments
Serve as a cybersecurity liaison with regulatory organizations and key internal stakeholders
Lead or participate in security governance committees, steering groups, and executive discussions
Perform cybersecurity and compliance assessments using established industry frameworks
Evaluate cybersecurity risks associated with AI and machine learning technologies, including data exposure, model misuse, adversarial attacks, and emerging threats
Support development of AI security policies, governance practices, and responsible-use standards
Assess Industrial Control Systems (ICS), SCADA environments, PLCs, and other operational technology for cybersecurity risk
Develop and recommend OT security controls aligned with critical infrastructure security practices
Evaluate security architecture, applications, systems, networks, and business processes to identify vulnerabilities and control gaps
Partner with legal, compliance, technology, and business teams to address regulatory and cybersecurity requirements
Translate complex cybersecurity findings into clear risk recommendations for technical and executive stakeholders
Monitor evolving cybersecurity regulations, frameworks, threats, and technology trends
The Job Requirements
Bachelor's degree in Computer Science, Information Systems, Cybersecurity, Engineering, or a related discipline, or equivalent professional experience
8+ years of combined cybersecurity, information security, IT, critical infrastructure, intelligence, or related experience
Advanced experience with cybersecurity risk management, governance, and compliance
Experience conducting cybersecurity risk assessments and evaluating security controls
Knowledge of enterprise IT security across applications, systems, networks, and infrastructure
Experience working with cybersecurity standards and frameworks such as NIST and ISO
Understanding of regulatory and compliance requirements within complex or highly regulated organizations
Current cybersecurity certification such as Security+, GIAC, SANS, Cisco Security, Microsoft Security, or equivalent
Strong executive communication, analytical, and decision-making capabilities
Ability to influence stakeholders and lead cybersecurity initiatives across multiple teams
You'll Stand Out If You Have
CISSP, CISM, CRISC, CISA, or comparable advanced cybersecurity certification
Master's degree in Cybersecurity, Computer Science, Information Systems, or a related discipline
Cybersecurity experience within utilities, energy, critical infrastructure, or another regulated industry
Experience securing Operational Technology (OT), Industrial Control Systems (ICS), SCADA, or PLC environments
Knowledge of NIST 800-82 and industrial control system security practices
Experience with NERC CIP or other critical infrastructure regulatory requirements
Experience with AI/ML security, AI governance, model risk, or the NIST AI Risk Management Framework
Knowledge of SOX, CCPA/CPRA, HIPAA, or other security and privacy regulations
Experience presenting cybersecurity risk and strategy recommendations to senior or executive leadership