
201 - 500 employees
đź Consulting
Consulting
UMS is a company that focuses on enhancing utility performance through innovative solutions tailored for water and energy management. They specialize in areas such as advanced metering, water conservation, and smart metering, providing services that include meter installation, testing, and data management. UMS is dedicated to addressing the challenges faced by utility providers, including outdated infrastructure and non-revenue water loss, with expertise that supports both utilities and the communities they serve.
đĽ 3 minutes ago
đşđ¸ United States â Remote
đľ $65k - $75k / year
â° Full Time
đĄ Mid-level
đ Senior
đ˛ Risk
đť Ghost score 3%
Improve your chances of getting an interview by checking your resume score before you apply.

201 - 500 employees
đź Consulting
Consulting
UMS is a company that focuses on enhancing utility performance through innovative solutions tailored for water and energy management. They specialize in areas such as advanced metering, water conservation, and smart metering, providing services that include meter installation, testing, and data management. UMS is dedicated to addressing the challenges faced by utility providers, including outdated infrastructure and non-revenue water loss, with expertise that supports both utilities and the communities they serve.
⢠Manage and support the institutional cybersecurity risk program ⢠Maintain the risk register and document risks ⢠Develop and track Plans of Action and Milestones (POA&Ms) ⢠Coordinate corrective actions with systems and data owners ⢠Manage cybersecurity risk reviews for new solutions, services, and technology acquisitions ⢠Intake and triage risk review requests ⢠Conduct or coordinate security risk assessments, including third-party and vendor reviews ⢠Use HECVAT, SOC 2 reports, and similar assurance documentation for vendor reviews ⢠Document findings and recommendations ⢠Route risk acceptance and approval decisions to the appropriate authority ⢠Map and maintain cybersecurity controls against NIST SP 800-171, CIS Controls, FERPA, HIPAA, CJIS, PCI, GLBA Safeguards Rule, and other standards ⢠Develop, review, and maintain cybersecurity policies, standards, procedures, and guidelines ⢠Monitor compliance and coordinate audit readiness, evidence collection, and documentation ⢠Liaise with internal and external auditors and regulatory entities ⢠Manage cybersecurity exception and risk acceptance processes ⢠Facilitate periodic risk reviews and escalate overdue items ⢠Coordinate remediation of audit, risk assessment, and compliance findings ⢠Develop cybersecurity metrics, dashboards, and reports ⢠Lead cybersecurity awareness and training initiatives, including phishing simulations, campaigns, onboarding, annual education, and role-based training ⢠Support cybersecurity engagement and outreach, including a cybersecurity champions network ⢠Prepare reports, briefings, and presentations for executive leadership and governance bodies ⢠Leverage artificial intelligence and automation to improve analysis, reporting, workflows, and cybersecurity program operations
⢠Bachelor's degree in Cybersecurity, Information Systems, Information Technology, Risk Management, or a related field, or an equivalent combination of education and experience ⢠Five years of professional experience in cybersecurity, IT risk management, compliance, or information security program support ⢠Experience with audit preparation and evidence documentation practices ⢠Knowledge of cybersecurity frameworks and standards, including NIST, CIS Controls, ISO standards, and applicable regulatory requirements ⢠Knowledge of cybersecurity risk assessment methodologies and security control frameworks ⢠Experience maintaining risk registers, POA&Ms, or corrective action tracking, and supporting risk acceptance or exception processes ⢠Ability to analyze cybersecurity risks and develop practical mitigation recommendations ⢠Ability to develop policies, procedures, and governance documentation ⢠Ability to develop reports, dashboards, and metrics for leadership and governance audiences ⢠Strong written communication skills, including policy documentation and executive-level reporting ⢠Ability to collaborate effectively with both technical and nontechnical stakeholders ⢠Demonstrated use of AI-assisted tools or automation to improve security workflows, processes, or reporting ⢠Familiarity with the responsible use of artificial intelligence and automation in professional environments, including appropriate data protection considerations ⢠U.S. work authorization that does not require employer sponsorship now or in the future ⢠Must not require visa sponsorship or OPT extensions at any point ⢠Successful applicant subject to appropriate background screenings ⢠Cover letter and resume or curriculum vitae required ⢠Three professional references may be requested for finalists
⢠Comprehensive health benefits, including medical, dental, vision, flexible spending accounts (FSA), and Health Savings Account (HSA) options ⢠Employer-paid basic life insurance and long-term disability coverage, with additional voluntary coverage options ⢠Retirement plan through TIAA with 10% employer contribution and opportunities for additional tax-deferred retirement savings ⢠Generous paid time off, including vacation and sick leave ⢠13 paid holidays each year ⢠Tuition waiver program for employees, including graduate courses and Maine Law ⢠Substantial tuition discounts for eligible spouses and dependent children ⢠Employee Assistance Program (EAP) ⢠Wellness programs ⢠Professional development opportunities and career growth within Maine's public university system ⢠Pet insurance ⢠Home and auto insurance discounts ⢠Supplemental disability and life insurance options
Apply NowđĽ 41 minutes ago
Senior Security GRC Analyst scaling compliance, risk, and customer assurance for Monarchâs all-in-one personal finance platform. Automating GRC workflows across security and business teams.
đĽ 2 hours ago
Senior P2P governance specialist optimizing outsourced invoice and payment operations for Activision Blizzardâs global gaming business. Driving controls, process improvement, stakeholder alignment, and transformation initiatives.
đĽ 4 hours ago
Climate risk consultant helping Ramboll, a global architecture, engineering, and consultancy company, assess climate and sustainability opportunities. Delivering analytics, financial models, client presentations, and proposals.
đşđ¸ United States â Remote
đľ $69.2k - $100.2k / year
â° Full Time
đ˘ Junior
đĄ Mid-level
đ˛ Risk
đŚ H1B Visa Sponsor
đĽ 9 hours ago
Senior P2P governance specialist optimizing outsourced invoice and payment operations for Activision Blizzard. Driving controls, process improvement, stakeholder alignment, and transformation across a global gaming company.
đĽ 10 hours ago
Senior GRC Analyst automating enterprise compliance for Aya Healthcareâs tech-enabled healthcare workforce solutions. Managing SOC 2, ISO 27001, ServiceNow GRC, risk, and audit operations.
đşđ¸ United States â Remote
đľ $105k - $135k / year
â° Full Time
đ Senior
đ˛ Risk
đŚ H1B Visa Sponsor