Cyber Security Coach - Seattle, United States - Bluehawk Consulting

    Default job background
    Technology / Internet
    Description

    Cyber Security Specialist/Coach

    Work can be done fully remote via conferencing.

    2 workstreams, Repeatable and Tabletop Exercises

    1. Repeatable: take 40-50 client products/services through an internal demonstration/review and identify gaps where not compliant with current policies or best practices. Many of these product pre date the policies and may have been on target then and are not now. Each of the products runs independently, which is somewhat a problem. The work for each involves:
    2. Conduct session
    3. Readout document, next steps to get on policy
    4. Follow up to roadmap/fix each over time.
    5. Document program effort for visibility

    Move through many products, so somewhat high level. Leverage consistency to level up all products to same standard. Mark mentioned focusing on the fixes required, this may be more of solve the big problems and not the small/granular but need to circle back on that.

    May be of interest to develop policy guidelines scoring for each project, at a minimum a green/yellow/red for program dashboard.

    1. Executive Table Top Exercise. This is an exercise for senior leadership to run through many different security dilemma (visible high concern issues) to answer the question: "Who to get if "X" happens due to an event, data leak of customer data, internal data leak, or similar."
    2. About 20-30 scenarios to discuss, will want a follow up report/recap, with 5 y's (who, what, when, where, how), gaps in response today, other suggestions
    3. Similar to above but different case
    4. New product launches from a competitor that is very similar to client's product
    5. What to do? What questions to ask, what discovery?
    6. Validate IP theft
    7. Y
    8. N
    9. Next Steps