Cybersecurity Risk Analyst
Core
Ensure consistent delivery of security services, develop and deploy capabilities to protect enterprise systems and data, and manage technology vendor risk.
Role type
Cybersecurity Risk Analyst (Vendor Risk & Compliance)
Builds
Defensible security environment with measurable controls for enterprise systems and data
Domain
Entertainment & Sports Agency / Information Security / Vendor Risk Management
Deliverable
production ML models | product features | dashboards & analysis | client delivery | infrastructure
Required skills
Vendor risk assessment, IT control framework review (NIST CSF, CIS, ITIL, ISO 27001), security assessments, security integration coordination, security metrics reporting, cloud infrastructure understanding, security analytics tooling
Preferred skills
Third Party Risk Management (TPRM), GRC platforms (OneTrust, SIG), Azure/AWS cloud environments, Identity and Access Administration (SSO, Active Directory, Azure AD, AWS IAM), Event Management (Splunk)
Technologies
NIST CSF, CIS, ITIL, ISO 27001, OneTrust, SIG, Azure, AWS, Splunk, PingFed, SAML, Active Directory, JIRA
Responsibilities
Support Technology Vendor Management program and conduct risk reviews; Participate in risk reviews of IT control frameworks; Conduct vendor, product, and application security assessments; Partner with business groups to review workflows and enhance security processes; Coordinate implementation of core security integrations (SSO, Event Logs, Secrets, Alerting, Threat Model, Backup/Recovery); Ensure security solutions are configured securely; Coordinate with leadership to develop and deliver key security metrics.
Seniority
Mid-level, hands-on IC