Cyber Security Assurance Analyst
Core
Define and maintain security requirements for technology procurement and projects; conduct cyber assurance assessments of vendors and solutions; validate security controls and manage remediation prior to deployment.
Role type
GRC Cyber Security Assurance Analyst
Builds
Security assurance register and evidence for ISO 27001 certification and governance audits
Domain
Cyber Security / Governance, Risk, and Compliance (GRC)
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
vendor and third-party risk assessment (TPRM), security clause negotiation, ISO 27001 Annex A controls knowledge, Essential 8 understanding, solution architecture review, GRC tooling proficiency
Preferred skills
ISO 27001 Lead Implementer/Auditor certification, CISSP, CISM, CRISC
Technologies
Jira, ServiceNow GRC, Archer
Responsibilities
Define security requirements for technology procurement and projects; Conduct cyber assurance assessments of vendors and proposed solutions; Review and negotiate security requirements in commercial contracts; Partner with Architecture and Procurement to embed security in delivery lifecycles; Validate security controls and manage remediation activities; Own and maintain the Cyber Security Assurance Register; Lead third-party security assurance and risk assessment activities; Support ISO 27001 certification and compliance reporting.
Seniority
Mid-level, hands-on IC