Cybersecurity Risk & Technical Advisory Consultant - Remote (USA)
Boost your chances before you apply.
Echelon Risk + Cyber
Washington, DC, US
Summary
The consultant will conduct technical security assessments, threat modeling, and purple team exercises across cloud and network environments. They will also provide incident response advisory, develop security playbooks, and assist clients with business continuity and disaster recovery planning.
Job Description
About us: At Echelon Risk + Cyber, we believe in defending basic human rights to security and privacy. We seek a highly skilled and experienced Cybersecurity Risk & Technical Advisory Consultant to join our dynamic team at Echelon Risk + Cyber, a leading cybersecurity consulting firm. Our next team member will be ready to roll up their sleeves and identify opportunities for our clients and for Echelon internally with unquestioned integrity. This team member will be passionate about cybersecurity and ready to use their knowledge to be an Entrepreneurial Problem Solver and work alongside their Echelon team members to build creative solutions.
As a Cybersecurity Risk & Technical Advisory Consultant your work will include a variety of technical engagements, including cloud and Microsoft 365 security assessments, network and endpoint assessments, threat modeling, threat hunting, purple team exercises, tabletop exercises (TTXs), incident response advisory, detection engineering, and BIA/BC/DR planning.
At Echelon, you will have the opportunity to engage with clients, business partners, and systems that are at the cutting edge of technology. We allow our employees to build from the ground up and make an impact across the organization. We look for driven and proactive people that are eager to contribute to a distinct and thriving Cybersecurity services organization, that can adapt to a rapid and changing environment
What You Will Do:
- Assist in the execution, development, and reporting of Technology Risk, Compliance, and Cybersecurity engagements.
- Conduct technical security assessments across cloud environments (AWS, Azure, and GCP), Microsoft 365, network infrastructure, endpoints, and SOC operations to identify control gaps and misconfigurations.
- Perform threat modeling and threat hunting engagements to proactively surface adversary behavior and gaps in detection coverage.
- Apply MITRE ATT&CK tactics, techniques, and procedures (TTPs) throughout assessments, threat modeling, and purple team engagements to map client environments against real-world adversary behavior and validate detection and response coverage.
- Support purple team exercises and technical tabletop exercises (TTXs), working alongside client blue teams to test and strengthen detection, response, and escalation processes.
- Provide incident response advisory support to clients actively managing security incidents, and develop incident response playbooks, plans, and post-incident remediation roadmaps.
- Contribute to detection engineering efforts, helping clients build, tune, and validate detection logic aligned to observed and anticipated threats.
- Support business continuity and disaster recovery (BC/DR) planning, including developing business impact analyses (BIA), to help clients prepare for and recover from disruptive events.
- Document results, create client reports, and communicate results to client management and other stakeholders.
- Work collaboratively with our clients and other team members to identify security risks and provide actionable recommendations and solutions.
- Demonstrate consistency, versatility, and adaptability while managing simultaneous client engagements and priorities and delivering quality results in a timely fashion.
- Work with the internal team to develop and plan engagement strategies, define objectives, identify and provide recommendations to address client risks.
- Handle and evaluate data and information responsibly.
- Create and deliver client-facing presentations, reports, and analytics.
- Establish exceptional internal and client relationships using strong written and verbal communication skills.
- Stay up to date with industry trends, emerging threats, and related laws and regulations within cybersecurity.
- Collaborate with members of the team to resolve new or complex cybersecurity risks and project challenges.
- Demonstrate thought leadership through the creation of content for the organization's website blog and involvement in the cybersecurity community.
Your knowledge, skills, and abilities:
- 3+ years of experience in a cybersecurity environment, with hands-on exposure to technical security assessments, testing, or advisory work.
- 1+ years of related experience in a client-facing role.
- Technical experience evaluating cloud environments (AWS, Azure, GCP), Microsoft 365, network infrastructure, endpoints, or SOC operations.
- Working knowledge of MITRE ATT&CK tactics, techniques, and procedures (TTPs), and the ability to apply them across assessments, threat modeling, and purple team engagements.
- Experience with, or working knowledge of, threat modeling, threat hunting, and detection engineering.
- Exposure to purple team exercises, technical tabletop exercises (TTXs), or other collaborative adversary-emulation formats.
- Understanding of the incident response lifecycle, including playbook/plan development and post-incident remediation.
- Familiarity with business continuity and disaster recovery (BCDR) planning and business impact analysis (BIA).
- Scripting or automation experience with Python and/or PowerShell to support assessment, testing, and reporting workflows.
- Experience with a variety of information security frameworks and best practices (e.g., NIST, CMMC, ISO, GLBA, FFIEC, SOX, SOC, HIPAA, HITRUST, MITRE ATT&CK, etc.).
- Risk management experience, including performing assessments and audits, designing information security processes, managing enterprise control frameworks, and evaluating and prioritizing risk.
- Excellent verbal and written communication skills, with experience crafting professional messages, client reports, and presentations for both technical and non-technical audiences.
- Ability to manage and prioritize multiple simultaneous client engagements, adapting in a demanding and fast-changing environment.
- Strong attention to detail and excellent analytical, technical, and problem-solving skills.
- Actively pursues opportunities to develop professionally and demonstrates a willingness to learn.
- Applicants must have authorization to work in the United States without current or future visa sponsorship.
Preferred Qualifications:
- Certified in, or currently in pursuit of, one or more industry standard certifications: Security+, CySA+, GCIH, OSCP, or a cloud security certification.
- Experience and / or familiarity with Digital Forensics and Incident Response (DFIR) techniques and solutions
- Experience developing scripts and automation for data collection and sanitization using Python and PowerShell.
Why Echelon?
We are committed to creating an inclusive environment for our team with unquestioned integrity. If you have a special need that requires accommodation, please let your recruiter know. One of our core values is "People with Personality," and we want to allow you the space to bring your full self to work.
We currently offer the following benefits:
- Access to medical, dental, and vision insurance through Cigna, with the majority of the employee cost covered by the employer
- Employer funding to HSA accounts and FSA access
- Access to a 401(k) through Vanguard with a guaranteed employer contribution
- Flexible vacation policy that allows you to manage your schedule and rest and recharge when you need to
- 11 holidays with flexibility based on what is important for you and those you love
- Family-friendly benefits, including weeks off for Maternity leave, weeks off for non-birthing parent leave, employer-paid short-term and long-term disability, employer-paid life insurance, and access to additional life insurance, hospital coverage, accidental coverage, discounted mental health support, and more
- Support for individual development through certifications, continued learning, conferences, and more
We value a diverse workforce and a culture of inclusivity and belonging. All employment decisions shall be made without regard to age, race, creed, color, religion, gender, national origin, ancestry, disability status, veteran status, sexual orientation, gender identity or expression, genetic information, marital status, citizenship status, or any other basis as protected by federal, state, or local law. Echelon Risk + Cyber is an Equal Opportunity Employer.
Echelon was born with a purpose; the belief that security and privacy are basic human rights.
We partner with organizations to design, build, operate, and mature cybersecurity and compliance programs aligned to business goals, regulatory requirements, and real-world risk. We take the time to understand each organization’s environment, constraints, and risk tolerance, then deliver practical solutions that drive measurable improvement. We do not believe trust is built through fear or complexity. It is built through transparency, accountability, and consistent execution.
We offer a suite of services including:
- Managed Security Services
- vCISO-Led Security Team as a Service (STaaS)
- Offensive Security + Adversary Simulation
- Defensive Security + Hardening
- Risk Advisory + GRC
How We Work:
ASSESS: Custom risk assessments tailored to your specific business needs, designed by our experts to reflect your organization's unique environment and risk posture.
STRATEGIZE: Practical security roadmaps that align with your long-term goals, helping your organization cut through complexity and build a defensible path forward.
IMPLEMENT: Hands-on execution that turns strategy into reality by engineering solutions, building sustainable processes, and enhancing your overall cybersecurity maturity.
LEVEL UP: Continuous improvement and proactive threat mitigation to keep your program ahead of an evolving threat landscape.
Founded
2021
Company size
51-200 employees
Industry
Computer and Network Security
Org type
Partnership
Headquarters
Pittsburgh, PA
Echelon was born with a purpose; the belief that security and privacy are basic human rights.
We partner with organizations to design, build, operate, and mature cybersecurity and compliance programs aligned to business goals, regulatory requirements, and real-world risk. We take the time to understand each organization’s environment, constraints, and risk tolerance, then deliver practical solutions that drive measurable improvement. We do not believe trust is built through fear or complexity. It is built through transparency, accountability, and consistent execution.
We offer a suite of services including:
- Managed Security Services
- vCISO-Led Security Team as a Service (STaaS)
- Offensive Security + Adversary Simulation
- Defensive Security + Hardening
- Risk Advisory + GRC
How We Work:
ASSESS: Custom risk assessments tailored to your specific business needs, designed by our experts to reflect your organization's unique environment and risk posture.
STRATEGIZE: Practical security roadmaps that align with your long-term goals, helping your organization cut through complexity and build a defensible path forward.
IMPLEMENT: Hands-on execution that turns strategy into reality by engineering solutions, building sustainable processes, and enhancing your overall cybersecurity maturity.
LEVEL UP: Continuous improvement and proactive threat mitigation to keep your program ahead of an evolving threat landscape.
Founded
2021
Company size
51-200 employees
Industry
Computer and Network Security
Org type
Partnership
Headquarters
Pittsburgh, PA