Cybersecurity Risk Analyst
Core
Ensure consistent, measurable end-to-end delivery of security services, focusing on threat detection, risk mitigation, and response for enterprise systems and data.
Role type
Cybersecurity Risk Analyst
Builds
Defensible environment with integrated security controls, vendor risk assessments, and security metrics.
Domain
Entertainment & Sports Agency / Information Security / Third-Party Risk Management
Deliverable
production ML models | product features | dashboards & analysis | client delivery | infrastructure
Required skills
Vendor risk assessment, NIST CSF and ISO 27001 framework knowledge, security integration coordination, security analytics, cloud architecture understanding, server/OS operations, Third-Party Risk Management (TPRM) processes, Single Sign-on (SSO) concepts, Identity and Access Administration, Event Management
Preferred skills
Experience with GRC platforms (One Trust, SIG), Azure and AWS cloud environments, security tooling implementation
Technologies
NIST CSF, CIS, ITIL, ISO 27001, GDPR, CCPA, SOC, ISO, PCIDSS, FedRAMP, One Trust, SIG, Azure, AWS, PingFed, SAML, Active Directory, Azure AD, AWS IAM, Splunk, JIRA
Responsibilities
Support Technology Vendor Management program and conduct risk reviews; Participate in IT control framework reviews; Conduct vendor, product, and application security assessments; Partner with business groups to enhance security workflows; Coordinate implementation of core security integrations (SSO, Event Logs, Secrets, Alerting, Threat Model, Backup/Recovery); Ensure secure configuration of solutions; Develop and deliver key security metrics.
Seniority
Mid-level, hands-on IC