Security Consulting
Summary of the Course
This course provided a practical insight into the core responsibilities carried out by a Security Consulting firm. Specifically focused on risk assessments, mitigation advice and executive reporting. The module took a deep dive into Risk Reports involving the use of common compliance frameworks such as SOX & NIST, while actively testing the professional communication skills needed to present findings directly to corporate stakeholders.
Learning Objectives
The primary focus of this course was split into many different activities and goals to help gain a deeper understanding of Risk Consulting and Communication, Those were:
- To gain an understanding on risk identification and constructing risk reports alongside the ability to offer mitigation advice.
- Align identified vulnerabilities and mitigation strategies with standard regulatory and compliance frameworks.
- To strengthen communication and presentation skills in order to easily convey ideas & risk to other stakeholders
- Deepen knowledge of concepts such as the SDLC and the critical role of IT auditing in maintaining security baselines.
Work Produced & Problems Overcome
In this course I assumed the role of a junior security consultant, My first task was to help facilitate a clients request for a procure-to-pay system. It was my responsibility to review the outlined plan and perform a risk assessment to ensure it met the compliance of the SOX framework. I was responsible for identifying security risks and composing a professional email outlining my findings and remediation strategies to senior leadership.
My next task was centered around communication specifically focused on a meeting environment, I was tasked with conducting a product walkthrough with the client, asking strategic questions to uncover operational gaps. The primary goal being to convey a better understanding of the changes and adjustments needed so the project can move forward with SOX compliance baselines. I had to be clear and concise, while also being polite and understanding with my questioning and responses.
The introduction of Task 3 showed a pivot from the client-facing side of security consulting and saw a deeper focus on IT auditing. I was responsible for reviewing documentation related to the Software Development Life Cycle (SDLC) and change management procedures. My role was to evaluate these records and ensure they adhered to strict compliance protocols and maintained system integrity. Additionally ,I provided strategic recommendations on how to optimize their SDLC processes to ensure the final product consistently meets its security and operational requirements.
Lastly Task 4 represented the culmination of both the IT audit and client communication phases through the creation of comprehensive audit documentation. This final package detailed proposed remediation strategies and highlighted previously resolved technical issues. I was tasked with creating a professional high-impact presentation designed to convey complex audit changes in a clear and scannable format. This presentation provided a different perspective, ensuring the documentation could be easily understood by all corporate stakeholders.
Tools Used
To complete this course it involved critical thinking, interview skills and deep research into security frameworks and IT auditing, The tools I used:
Learning Outcomes
Throughout this course, I developed a strong understanding of the specialized workflows within a cybersecurity consulting firm. I gained deep insights into industry-led frameworks such as SOX and NIST, alongside mastering the skills of risk identification and strategic mitigation reporting. The simulation focused heavily on client-facing communication in an interview-style setting, which strengthened both my critical thinking and stakeholder engagement skills. Furthermore, it sharpened my capability to translate complex technical concepts into clear insights for non-technical corporate leaders. Lastly, constructing the final deliverable advanced my ability to design high-impact, industry-standard visual content, balancing creativity and strategic decision-making to appeal to a wider executive audience.