Cyber Risk Analyst
Core
Implement cyber risk operational strategy, manage GRC programs, and perform internal and third-party security risk assessments.
Role type
Cyber Risk Analyst (GRC)
Builds
Risk management processes, control mappings, and security exception tracking aligned to ISO 27005, NIST, and CIS frameworks.
Domain
Cybersecurity / Risk Management / Governance
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Risk assessment and management, Regulatory compliance, GRC tool management, Policy lifecycle management, Risk mitigation planning, Control mapping, Vendor risk assessment, Security exception tracking, Business case development, Data metrics presentation
Preferred skills
CISSP, CISM, CRISC certifications, Experience with OneTrust or ServiceNow, Knowledge of MITRE ATT&CK
Technologies
GRC tools (OneTrust, ServiceNow), ISO 27005, NIST Cybersecurity Framework, CIS Top 18 Controls, MITRE ATT&CK
Responsibilities
Implement cyber risk strategy and advise on critical improvement areas; Lead process improvement and present outcomes to senior management; Manage day-to-day exception processes within the GRC tool; Support risk mitigation or acceptance efforts with stakeholders; Manage risk remediation plans and follow up on progress; Document and communicate corrective action plans based on risk findings; Partner with regional BISOs to understand local compliance requirements.
Seniority
Mid-level, hands-on IC
