Cyber Specialist
Core
Perform technical security assessments of web apps, mobile apps, APIs, systems, cloud services, and third-party solutions to detect risks and control gaps.
Role type
Senior IC cybersecurity specialist (security assessments & GRC)
Builds
Risk-based security recommendations, assessment summaries, and remediation plans for enterprise systems and vendors
Domain
Cybersecurity, IT risk, compliance, and third-party risk management
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
technical security assessments, application security controls evaluation, risk-based recommendations, vendor security reviews, audit support, regulatory compliance knowledge, executive reporting, stakeholder collaboration
Preferred skills
cloud security, identity and access management, data protection controls, GRC platform usage
Technologies
GRC platforms, workflow tools, ticketing systems, evidence management platforms
Responsibilities
Perform technical security assessments of web apps, mobile apps, APIs, applications, systems, cloud services, technology platforms, business processes, and third-party solutions; Evaluate application security controls including authentication, authorization, session management, encryption, secrets management, logging, and secure configuration practices; Develop practical, risk-based recommendations that balance security, operational requirements, and business objectives; Document findings, conclusions, and risk decisions in a clear and professional manner; Review evidence supporting security controls and evaluate control efficiency; Produce executive-ready assessment summaries, threat analysis, and remediation recommendations; Present findings to both technical and non-technical audiences; Review vendor security questionnaires, SOC reports, certifications, penetration testing reports, and supporting security documentation; Evaluate the security measures of potential and current vendors, SaaS providers, cloud service providers, and technology partners; Partner with Procurement, Legal, business teams, and vendors to resolve security concerns and detail residual risk; Assist with internal audits, external audits, client assurance requests, and regulatory examinations; Contribute to the ongoing improvement of security assessment processes, templates, standards, and reporting practices
Seniority
Senior, hands-on IC