Experience conducting security and risk assessments. * Experience with incident response, threat monitoring, IAM, and vulnerability management. Education and Certifications * Bachelor's degree in ...
Quick apply
Experience conducting security and risk assessments. * Experience with incident response, threat monitoring, IAM, and vulnerability management. Education and Certifications * Bachelor's degree in ...
Quick apply
Experience conducting security and risk assessments. * Experience with incident response, threat monitoring, IAM, and vulnerability management. Education and Certifications * Bachelor's degree in ...
The role requires hands-on experience in IT ITAC, and Information Security control testing, risk assessments, audit support, and regulatory compliance activities. The successful candidate will act as ...
The role requires hands-on experience in IT ITAC, and Information Security control testing, risk assessments, audit support, and regulatory compliance activities. The successful candidate will act as ...
Directs ongoing risk assessment programs for all new and existing systems, understands organizational goals and processes to develop effective controls for a strong security posture. * Oversees all ...
Directs ongoing risk assessment programs for all new and existing systems, understands organizational goals and processes to develop effective controls for a strong security posture. * Oversees all ...
Phoenix, AZ · On-site
Assess control gaps and residual risk exposure. Draft concise, actionable, and well-defined issue ... Security and other regulations as applicable to this . * May be asked to coach, mentor, or train ...
Phoenix, AZ · On-site
Assess control gaps and residual risk exposure. Draft concise, actionable, and well-defined issue ... Security and other regulations as applicable to this . * May be asked to coach, mentor, or train ...
Knowledge of Selection/Approval, Implementation, and Assessment/Audit of Security and Privacy Controls. * Knowledge of Risk Management Framework (RMF) requirements. * Knowledge of Authorization ...
Quick apply
Knowledge of Selection/Approval, Implementation, and Assessment/Audit of Security and Privacy Controls. * Knowledge of Risk Management Framework (RMF) requirements. * Knowledge of Authorization ...
Chandler, AZ · On-site
Perform remediation of security assessment review issues, complex ad hoc data, and reporting to support information security risk management * Provide guidance and direction in reviewing assessment ...
Quick apply
Chandler, AZ · On-site
Perform remediation of security assessment review issues, complex ad hoc data, and reporting to support information security risk management * Provide guidance and direction in reviewing assessment ...
Paradise Valley, AZ · On-site
Conduct security risk assessments, vulnerability reviews, and threat analyses to identify potential risks and vulnerabilities. * Develop and implement mitigation strategies aligned with regulatory ...
Paradise Valley, AZ · On-site
Conduct security risk assessments, vulnerability reviews, and threat analyses to identify potential risks and vulnerabilities. * Develop and implement mitigation strategies aligned with regulatory ...
Scottsdale, AZ · Hybrid
$99K/yr
... security, data management, technology risk, third-party risk, or a related discipline. * Experience conducting or supporting risk assessments, control testing, due diligence, audit activities, issue ...
Scottsdale, AZ · Hybrid
$99K/yr
... security, data management, technology risk, third-party risk, or a related discipline. * Experience conducting or supporting risk assessments, control testing, due diligence, audit activities, issue ...
Chandler, AZ · Hybrid
$40 - $45/hr
Perform remediation of security assessment review issues, complex ad hoc data, and reporting to support information security risk management. Provide guidance and direction in reviewing assessment ...
Chandler, AZ · Hybrid
$40 - $45/hr
Perform remediation of security assessment review issues, complex ad hoc data, and reporting to support information security risk management. Provide guidance and direction in reviewing assessment ...
Liaise with risk assessment team and other stakeholders to ensure control testing is in alignment ... Certified Information Systems Auditor (CISA), Certified Information Security Manager (CISM) or ...
Liaise with risk assessment team and other stakeholders to ensure control testing is in alignment ... Certified Information Systems Auditor (CISA), Certified Information Security Manager (CISM) or ...
Scottsdale, AZ · On-site
$150 - $250/hr
Own the enterprise IT risk management framework, including risk appetite, risk assessments, and ... Align security and risk strategies with enterprise objectives to support innovation, operational ...
Scottsdale, AZ · On-site
$150 - $250/hr
Own the enterprise IT risk management framework, including risk appetite, risk assessments, and ... Align security and risk strategies with enterprise objectives to support innovation, operational ...
Preferred Skills Access Control (AC), Building Architecture, Customer Solutions, Disaster Recovery Planning, Information Security, Network Security, Physical Security, Risk Assessments, Security ...
Preferred Skills Access Control (AC), Building Architecture, Customer Solutions, Disaster Recovery Planning, Information Security, Network Security, Physical Security, Risk Assessments, Security ...
Scottsdale, AZ · On-site
$99K/yr
... security, data management, technology risk, third-party risk, or a related discipline. * Experience conducting or supporting risk assessments, control testing, due diligence, audit activities, issue ...
Scottsdale, AZ · On-site
$99K/yr
... security, data management, technology risk, third-party risk, or a related discipline. * Experience conducting or supporting risk assessments, control testing, due diligence, audit activities, issue ...
Oversee product risk assessments, control design, monitoring, testing, reporting, and remediation efforts. * Guide remediation of security and compliance findings through collaborative leadership ...
Oversee product risk assessments, control design, monitoring, testing, reporting, and remediation efforts. * Guide remediation of security and compliance findings through collaborative leadership ...
Scottsdale, AZ · On-site
$99K/yr
... security, data management, technology risk, third-party risk, or a related discipline. * Experience conducting or supporting risk assessments, control testing, due diligence, audit activities, issue ...
Scottsdale, AZ · On-site
$99K/yr
... security, data management, technology risk, third-party risk, or a related discipline. * Experience conducting or supporting risk assessments, control testing, due diligence, audit activities, issue ...
$58.25 - $78/hr
The Application Security Engineer is responsible for supporting the security and privacy of the ... Conduct regular application risk assessments to identify vulnerabilities and emerging threats.
$58.25 - $78/hr
The Application Security Engineer is responsible for supporting the security and privacy of the ... Conduct regular application risk assessments to identify vulnerabilities and emerging threats.
Phoenix, AZ · On-site +1
$112K - $143K/yr
... focus on risk assessment and service work, providing leadership in division/branch-level ... Programs designed to support the employee well-being and financial security. This pay range ...
Phoenix, AZ · On-site +1
$112K - $143K/yr
... focus on risk assessment and service work, providing leadership in division/branch-level ... Programs designed to support the employee well-being and financial security. This pay range ...
Tucson, AZ · On-site
Risk Management Integration * Facilitate the information security risk assessment and risk treatment process working with technical and business stakeholders to identify, evaluate, and treat ...
Tucson, AZ · On-site
Risk Management Integration * Facilitate the information security risk assessment and risk treatment process working with technical and business stakeholders to identify, evaluate, and treat ...
Phoenix, AZ · On-site
... Prepare assessment reports, risk documentation, and executive summaries. • Support internal and external security audits. Required Qualifications • Bachelor's degree in computer science ...
Phoenix, AZ · On-site
... Prepare assessment reports, risk documentation, and executive summaries. • Support internal and external security audits. Required Qualifications • Bachelor's degree in computer science ...
Support the execution of risk assessments in alignment with the Enterprise Risk Identification and ... Security and other regulations as applicable to this . * May be asked to coach, mentor, or train ...
Support the execution of risk assessments in alignment with the Enterprise Risk Identification and ... Security and other regulations as applicable to this . * May be asked to coach, mentor, or train ...
| Aspect | Freelance Security Risk Assessment | Security Consultant |
|---|---|---|
| Credentials | Certifications like CISSP, CISA, or CEH often required | Similar certifications, often with additional experience requirements |
| Work Environment | Independent, project-based, often remote or on-site at client locations | Typically employed by firms or consulting agencies, may work on multiple projects |
| Industry Usage | Used by organizations seeking independent risk assessments | Engaged for broader security strategy, policy development, and consulting |
While both roles involve assessing security risks, Freelance Security Risk Assessments focus on independent, project-specific evaluations, whereas Security Consultants often provide ongoing security advice and strategy within organizations or consulting firms.

About NovaSource
NovaSource Power Services is the world’s #1-ranked solar operations and maintenance (O&M) provider and insight-driven total asset optimization partner for renewables asset owners ready to fuel smart growth. With over 20 years of operating experience and a presence on 5 continents, NovaSource has the global reach and strategic capabilities to achieve our clients’ renewables goals around the world.
NovaSource’s comprehensive approach to total asset optimization in addition to O&M services includes value engineering, performance analysis, strategic supply chain management, and advanced monitoring systems. The company operates in key global markets managing over 30GW of solar power plants. NovaSource’s expertise extends beyond solar and includes battery energy storage systems (BESS), offering a complete suite of services for the evolving renewable energy landscape.
Job Summary
The Manager, Information Security is responsible for managing the day-to-day operations of the Information Security function, supporting the implementation of cybersecurity programs, maintaining security controls, and ensuring compliance with applicable regulatory and company security requirements. This role partners closely with Information Technology, Engineering, and Operations to protect corporate and operational technology environments while supporting the organization's overall cybersecurity strategy.
Experience
• 5+ years of experience in Information Security, Infrastructure Services, OT Security, or related fields.
• 2+ years leading technical teams.
• Experience implementing cybersecurity policies, procedures, and controls.
• Experience supporting regulatory compliance programs, preferably NERC CIP.
• Experience conducting security and risk assessments.
• Experience with incident response, threat monitoring, IAM, and vulnerability management.
Education and Certifications
• Bachelor’s degree in Cybersecurity, Computer Science, Engineering, Information Systems, or related discipline.
• Relevant certifications preferred (CISSP, CISM, GIAC, Security+, PMP).
• Advanced degree preferred but not required.
Technical Qualifications
• Experience managing cybersecurity vendors and security technologies.
• Experience implementing and administering information security policies, technologies, controls, and management processes.
• Knowledge of NERC CIP standards and data privacy requirements.
• Experience with ITIL processes.
• Strong analytical, problem-solving, and project management skills.
• Experience with SIEM, endpoint security, vulnerability management, and identity governance platforms.
• Knowledge of NIST CSF, CIS Controls, and ISO 27001 preferred.
Essential Functions & Responsibilities
• Manage the day-to-day activities of the Information Security team, providing coaching, guidance, and performance management.
• Build, develop, and retain a high-performing information security organization.
• Establish clear performance expectations, career-development plans, and succession strategies.
• Foster a culture of accountability, continuous improvement, and cybersecurity awareness.
• Promote business partnership and consultative engagement across the enterprise.
• Support the execution of cybersecurity programs and initiatives that align with business objectives and regulatory requirements.
• Manage security operations across corporate, cloud, and operational technology (OT) environments, including monitoring, incident response, identity and access management, and vulnerability management.
• Implement and maintain security controls, standards, and procedures to protect company information systems and assets.
• Coordinate cybersecurity activities supporting NERC CIP compliance, regulatory audits, and security assessments.
• Conduct security risk assessments, identify vulnerabilities, and partner with stakeholders to implement remediation plans.
• Support security architecture reviews, technology implementations, and system changes to ensure compliance with established security standards.
• Partner with IT, Engineering, Operations, and business teams to address cybersecurity risks and support secure business operations.
• Review and approve security requirements for infrastructure, cloud, application, and enterprise architecture initiatives.
• Provide cybersecurity oversight for major technology projects and system changes.
• Evaluate security technologies and recommend investments supporting risk reduction.
• Lead the implementation and lifecycle management of enterprise security tools.
• Manage cybersecurity vendors and technologies to ensure effective service delivery and continuous improvement of security operations.
• Prepare operational security metrics, reports, and documentation to support leadership decision-making.
• Promote cybersecurity awareness by supporting employee training and security awareness initiatives.
• Maintain knowledge of emerging cybersecurity threats, technologies, and industry best practices to support continuous improvement.
• Partner with Legal, HR, Compliance, and IT leadership on cybersecurity investigations and evidence preservation activities.
• Coordinate litigation hold requirements involving cybersecurity incidents, employee investigations, electronic discovery, and regulatory inquiries.
• Support forensic collection, chain-of-custody processes, and evidence management activities.
• Ensure appropriate preservation and protection of security-related records and audit evidence.
• Promote a culture of cybersecurity awareness, accountability, and continuous improvement.
Work Environment
• Excellent communication and presentation skills.
• Strong analytical and problem-solving abilities.
• Experience managing distributed teams and collaborating with global stakeholders.
Office Physical Requirements:
All positions in our office require interaction with people and technology while either standing or sitting. In order to best serve our customers, internal and external, all associates must be able to communicate face-to-face and on the phone with or without reasonable accommodation. NovaSource is committed to compliance with its obligations under all applicable state and federal laws prohibiting employment discrimination. In keeping with this commitment, it attempts to reasonably accommodate applicants and employees in accordance with the requirements of the disability discrimination laws. It also invites individuals with disabilities to participate in a good faith, interactive process to identify reasonable accommodations that can be made without imposing an undue hardship.
Potential candidates will meet the education and experience requirements provided on the above job description and excel in completing the listed responsibilities for this role.
US: Diversity Statement – Equal Employment Opportunity
It is NovaSource’s policy to provide equal employment opportunities to all applicants and employees. NovaSource disapproves of, and will not tolerate, unlawful discrimination against any applicant or employee because of race, color, national origin or ancestry, gender (including pregnancy, childbirth, or related medical conditions), gender identity, age, religion, disability, family care status, veteran status, marital status, sexual orientation, or any other basis protected by local, state or federal laws.
Sourced by ZipRecruiter
Clean energy semiconductors manufacturing
1,001 - 5,000 Employees
Austin, TX, US
2020